Home / Companies / Evervault / Blog / Post Details
Content Deep Dive

How We Built Cages: Networking for Secure Enclaves

Blog post from Evervault

Post Details
Company
Date Published
Author
Hannah Neary
Word Count
1,422
Company Posts That Month
8
Language
English
Hacker News Points
-
Post removed?
No
Summary

The blog post details the creation of an abstraction layer that facilitates the development of applications for Nitro Enclaves without requiring custom modifications, particularly addressing the challenges posed by default lack of networking and complex traffic management via VSOCK. The authors introduce a control and data plane layer that allows simple TCP applications to run in an enclave within 15 minutes, utilizing a Network Load Balancer and Server Name Indication for secure TLS traffic routing. They developed a data plane to abstract VSOCK complexities, enabling apps to interact over TCP/HTTP, and established a seamless egress networking system for secure external communication while maintaining enclave isolation. The system includes an internal DNS server and egress proxy for managing domain access, with a focus on security by ensuring all traffic is encrypted and restricted to allowlisted domains to mitigate risks like typosquatting. The post emphasizes the open-source nature of the solution, encouraging users to try it with a free 14-day trial of Cages, and highlights that the system is designed to seamlessly handle app deployment while maintaining security through attestable features and optional egress capabilities.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.