You can create a node pool that supports confidential computing in an Alibaba Cloud Container Service for Kubernetes (ACK) cluster. This creates trusted execution environments (TEEs) to store code and sensitive data in your clusters. This way, you can protect your code and data from being sniffed and compromised. This topic describes how to create a node pool that supports confidential computing.
- A managed ACK cluster is created. For more information, see Create a managed ACK cluster. The created cluster must meet the following requirements:
- The network plug-in is Flannel.
- The container runtime must be Docker.
- The cluster must be deployed in a region where ECS Bare Metal Instances of ecs.ebmhfg5.2xlarge are available for purchase.
- Log on to the ACK console.
- Create a node pool that supports confidential computing.
- In the left-side navigation pane, choose Node Pools in the Actions column. . Find the target cluster, click
- In the left-side navigation pane, choose Node Pools page, select the target cluster from the Cluster drop-down list. . On the
- In the upper-right corner of the Node Pools page, click Create Node Pool.
- On the Create Node Pool page, configure the node pool.For more information, see Create a managed ACK cluster. The following table lists the required parameters of a confidential computing node pool.
Parameter Description Confidential Computing Enable encrypted computing. Container Runtime You must select Docker. Auto Scaling Select whether to enable Auto Scaling (ESS). If you enable ESS, the node pool automatically scales based on the resource consumption. Instance Type Select ECS Bare Metal Instance and select ecs.ebmhfg5.2xlarge as the instance type.Note You can select multiple instance types. Only the ecs.ebmhfg5.2xlarge instance type supports confidential computing. If the stock of ecs.ebmhfg5.2xlarge instances is insufficient, you can select another instance type. However, the node pool will not support confidential computing. Quantity Specify the initial number of nodes in the node pool. If you do not need to create nodes in the node pool, set this parameter to 0. Operating System You can select only the Aliyun Linux operating system. Node Label You can add labels to nodes in the node pool. ECS Label You can attach labels to the selected ECS instances.
- Click OK.On the Node Pools page, if the status of the node pool displays Initializing, this indicates that the node pool creation is in progress.In the left-side navigation pane of the ACK console, choose View Logs in the Actions column. On the Log Information page of the target cluster, you can view the logs of the newly created node pool that supports confidential computing.After the cluster is scaled out, the . Find the target cluster and click status of the node pool changes to Active.