#freebsd
382 posts · Last used 27m

With host-side SEV support, multi-core virtualization, and networking now functional in bhyve, the team is working on upstreaming the code to the main FreeBSD repository.
Future milestones include upgrading to newer SEV generations like SEV-ES for encrypted CPU register states and SEV-SNP for hardware memory integrity protection as well as updating the FreeBSD kernel to run seamlessly as an encrypted guest OS using memory C-bit handling and bounce buffers.
And for you, mere mortal, what does all of this actually mean? It means true cloud privacy without having to blindly trust anyone. Whether you're hosting sensitive customer data, financial workloads, or proprietary algorithms, confidential computing ensures that not even your cloud provider or a rogue admin with full root access can peek into your running memory.
By bringing AMD SEV to FreeBSD, top-tier, silicon-enforced protection stops being an exclusive enterprise luxury and becomes part of the open-source toolkit.
Bottom line: your data is finally locked down in transit, at rest, and right down to the hardware while in use.


