1 comment

[ 559 ms ] story [ 216 ms ] thread
Secure enclaves like AWS Nitro Enclaves have some really cool properties that are used here:

- memory protection and isolation for Vault while it's running

- unsealing without the parent host getting the key (can't be observed)

- having an unseal key that can't be used unless inside the enclave via cryptographic attestation