> For the complete documentation index, see [llms.txt](https://docs.ionos.com/cloud/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.ionos.com/cloud/compute-services/compute-engine/confidential-computing-vm/how-tos/set-up-confidential-vm-dcd.md).

# Set Up a Confidential VM

Create a Confidential VM in the DCD using an uploaded CC image with hardware-enforced memory encryption.

Confidential VM is a hardware-isolated compute service provided by <code class="expression">space.vars.ionos\_cloud</code> that encrypts VM memory at the CPU level using AMD SEV-SNP. This guide shows how to create a Confidential VM in the Data Center Designer (DCD) using your uploaded Confidential VM image.

{% hint style="warning" %}
**Prerequisites:**

* Confidential VMs are currently available in the **Germany / Frankfurt am Main (de/fra/2)** data center. To deploy, ensure you have an active <code class="expression">space.vars.ionos\_cloud</code> account in this location.
* You have a Confidential VM image uploaded to <code class="expression">space.vars.ionos\_cloud</code>. For more information, see [<mark style="color:blue;">Prepare a Confidential VM Image</mark>](/cloud/compute-services/compute-engine/confidential-computing-vm/api-how-tos/prepare-confidential-vm-image.md).
* Only contract owners, administrators, or users with the **Create Data Center** privilege can provision changes.
  {% endhint %}

## Create a Confidential VM from the Workspace

To configure a Confidential VM, follow these steps:

{% stepper %}
{% step %}

### Open the Data Center Designer

1\. In the **DCD**, go to **Menu** > **Virtual Data Centers**.

2\. Select the data center in the **Germany / Frankfurt am Main (de/fra/2)** location to configure a Confidential VM within it.

{% hint style="warning" %}
**Important:**

* The procedure listed here applies only to the **Canvas** mode.
* If you do not have a data center, create one using the [<mark style="color:blue;">Canvas</mark>](/cloud/set-up-ionos-cloud/get-started/create-data-center/use-canvas.md) mode in the **Germany / Frankfurt am Main (de/fra/2)** location. Only data centers in this location support Confidential VMs.
* If you created a VM using **Xpress** mode, it will appear in your Workspace in a **Running** state. You can continue configuring it to optimize performance and settings.
  {% endhint %}

![A Confidential VM provisioned using the Xpress mode](https://1737632334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MifAzdGvKLDTtvJP8sm%2Fuploads%2Fgit-blob-d7003430eb8e58b8787afabca8c134b15d5dd64f%2Fcreate-confidential-vm.png?alt=media)
{% endstep %}

{% step %}

### Add a Confidential VM

1. Drag the **Confidential VM** element from the **Palette** into the **Workspace**. The **Add Confidential VM** dialog appears.

{% hint style="warning" %}
**Important:** If the dialog shows a "No confidential VM image found" warning, you must prepare and upload a Confidential VM image before continuing. Follow the steps shown in the dialog:

1. [<mark style="color:blue;">Prepare your image</mark>](/cloud/compute-services/compute-engine/confidential-computing-vm/api-how-tos/prepare-confidential-vm-image.md).

2. Follow the instructions to [<mark style="color:blue;">upload your image using FTP</mark>](/cloud/backup-and-storage/images-snapshots/private-images/how-tos/upload-image-via-ftp.md).

3. Reopen this dialog and select the image from the drop-down list.
   {% endhint %}

4. In the **Add Confidential VM** dialog, select your uploaded Confidential VM image from the drop-down list. Only images prepared with the Confidential VM flow appear here. **CPU Architecture** and **Cores** are automatically derived from the image and cannot be edited. You can set the RAM, but it cannot be modified later.

{% hint style="warning" %}
**Important:** Expand **Confidential VMs: Capabilities and constraints** to review the limitations before adding the VM. Key constraints include:

* **CPU Cores** and **RAM** cannot be changed after creation.
* Storage volume is cryptographically tied to the image and cannot be swapped.
* In-guest restart commands terminate the VM. They do not restart it. Use the DCD **Reset** action for a full restart.
  {% endhint %}

3. Click **Add**.
4. The Confidential VM appears in the Workspace. In the **Inspector** pane, review and configure the **Settings** tab:

* **Name:** Enter a name for the Confidential VM, unique within your VDC.
* **Hostname:** Enter the hostname the operating system uses to identify the VM.
* **CPU Architecture:** Read-only. Derived from the uploaded image; cannot be changed.
* **Cores:** Read-only. Derived from the uploaded image; cannot be changed.
* **RAM (GB):** Read-only. Set at provisioning; cannot be resized.
* **Network Security Groups:** Optionally assign the VM to one or more network security groups.
* **NIC Multi-Queue:** Enable to improve network throughput by distributing NIC interrupts across CPU cores.

![Confidential VM selected in the Workspace with the Inspector Settings tab](https://1737632334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MifAzdGvKLDTtvJP8sm%2Fuploads%2Fgit-blob-3b5635a38524fee8ad8c39b6eff496b098f7986d%2Fcreate-confidential-computing-vm.png?alt=media)
{% endstep %}

{% step %}

### Configure the network

1. Connect the Confidential VM to other elements in the Workspace, such as an internet access element, by dragging a line from the VM's **Autoport** to the element's NIC.
2. In the **Inspector** pane, configure the network interface in the **Network** tab:

* **Name:** Choose a name unique to this VDC.
* **MAC:** *(Optional)*. Leave blank to have the platform assign a MAC address automatically.
* **LAN:** Select the LAN to attach this NIC to. The LAN must exist in the same data center.
* **Primary IPv4:** Set to **Automatic** to use DHCP, or select a reserved IP from the drop-down.
* **DHCP:** Enabled by default. When checked, the platform assigns a gateway IP automatically.
* **Add IP:** Optionally assign additional static IP addresses to this NIC.
* **Firewall:** Configure firewall rules as required.
* **Flow Log:** Optionally enable flow logging to capture NIC traffic metadata for monitoring and auditing.
* **Network Security Groups:** Select one or more network security groups to associate with the VM.

![Configure network](https://1737632334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MifAzdGvKLDTtvJP8sm%2Fuploads%2Fgit-blob-17ee177e5c792680cb488b1acc6242d5762e97b1%2Fconfidential-vm-network.png?alt=media)
{% endstep %}

{% step %}

### Review the startup volume

The startup volume is attached automatically when you add the Confidential VM. Configure its name, zone, and size in the **Inspector** pane as mentioned in [<mark style="color:blue;">Configure Storage</mark>](#configure-storage).
{% endstep %}

{% step %}

### Configure Storage

1. Click the startup volume attached to the Confidential VM in the Workspace.
2. In the **Inspector** pane, enter a **Name** that is unique within your VDC.
3. Select an **Availability Zone** in which you want the storage device to be maintained. When you select **Auto**, our system assigns the optimal Zone. The **Availability Zone** cannot be changed after provisioning.
4. Specify the required **Storage Type**. You can increase the size after provisioning, even while the Confidential VM is running, if its operating system supports it. Reducing the storage size after provisioning is impossible.
5. Your associated **Image** is automatically listed.
6. Configure the SSH access within the image before you upload the image. For more information, see [<mark style="color:blue;">Prepare your image</mark>](/cloud/compute-services/compute-engine/confidential-computing-vm/api-how-tos/prepare-confidential-vm-image.md).
7. Provision your changes. The storage device is now provisioned and configured according to your settings.
   {% endstep %}

{% step %}

### Provision

1. Click **PROVISION CHANGES** in the Inspector pane.
2. In the **Provision Data Center** dialog, review your changes in the **Validation** tab.
3. Confirm changes by entering your password, then click **Provision Now**.

{% hint style="info" %}
**Note:** During provisioning, the platform performs a hardware-enforced startup. VM memory is encrypted by the CPU from the moment the VM starts. If you configured an attestation service, the `initrd` contacts it during startup to obtain the disk-unlock key. This process takes slightly longer than a standard VM start.
{% endhint %}
{% endstep %}
{% endstepper %}

{% hint style="success" %}
**Result:** Your Confidential VM is running. Memory is encrypted by the CPU from the moment the VM starts, with or without attestation. The DCD displays a **Provisioning Complete** notification when the VM is ready.
{% endhint %}

![A Confidential VM in a Running state after a successful provisioning](https://1737632334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MifAzdGvKLDTtvJP8sm%2Fuploads%2Fgit-blob-2b627eea4dfb5e1d40053ed83d4dcae8cdb3be1f%2Fconfidential-vm-running.png?alt=media)

## After creation

The following properties are **immutable** for Confidential VMs after creation and cannot be changed:

| **Property**          | **Reason**                                             |
| --------------------- | ------------------------------------------------------ |
| **Cores**             | Derived from the image; cannot be overridden           |
| **CPU Architecture**  | Derived from the image; cannot be overridden           |
| **RAM**               | Set at provisioning; cannot be resized                 |
| **Availability Zone** | Hardware placement is fixed at creation                |
| **Startup volume**    | Cryptographically tied to the image; cannot be swapped |

{% hint style="info" %}
**Note:** An in-guest restart (for example, running `reboot` from inside the OS) terminates the VM without restarting it automatically. To restart the VM, use the DCD **Reset** action or the [<mark style="color:blue;">IONOS CLOUD API</mark>](https://api.ionos.com/docs/cloud/v6/).
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.ionos.com/cloud/compute-services/compute-engine/confidential-computing-vm/how-tos/set-up-confidential-vm-dcd.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
