Does Dstack support GCP / Azure
Dstack is open for PR to add that support. Currently it’s focusing on bare metal because it offers the most fine grained control and access to the vanilla TDX.How does KMS key generation work and how can it be modified?
The key generation logic is implemented in the onboard service:Reference: https://github.com/Dstack-TEE/dstack/blob/master/kms/src/onboard\_service.rs#L50
How does on-chain KMS work and how can I customize its governance?
The KMS contract allows for customizable ownership and governance:- During deployment, you can specify an owner
- After deployment, ownership can be transferred using transferOwnership function
Reference: https://github.com/Dstack-TEE/dstack/blob/master/kms/auth-eth/hardhat.config.ts#L96
Where can I find KMS deployment instructions?
Complete deployment documentation is available here: Reference: https://github.com/Dstack-TEE/dstack/blob/master/docs/deployment.mdHow does the current data encryption system work?
The system uses Linux’s built-in LUKS (Linux Unified Key Setup) for disk encryption:Reference: https://github.com/Dstack-TEE/dstack/blob/master/tdxctl/src/fde\_setup.rs#L437-L442