3 ms·
Another approach is to have to the DB run in a secure enclave (SGX, Nitro, etc.), the data encrypted in the enclave process during disk I/O and the querying cli
by maayank 3y ago
Another approach is to have to the DB run in a secure enclave (SGX, Nitro, etc.), the data encrypted in the enclave process during disk I/O and the querying clients also in their own enclaves with encrypted communication between the enclaves. While there are edge cases, this is a more general "treat the db as black box" approach.
- _nhynes 3y agoThis is really slow unless you figure out how to encrypt large batches of rows. It’s harder to do as a postgres plug-in. Do you have an example of enclaved today/transparent database encryption?
- robszumski 3y agoIf you're looking for the best way to take a container and run it with Nitro, I work on https://github.com/edgebitio/enclaver https://github.com/edgebitio/enclaver Works great with Kubernetes as a DaemonSet or straight on a VM. Like: protection and privacy for apps Love: using Nitro attestation and provenance like SLSA