Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Google Cloud has made Intel TDX-based Confidential GKE Nodes and Confidential Space generally available, and added GA support for confidential workloads using NVIDIA H100 GPUs on A3 machines. The announcement also expands Intel TDX availability on C3 machines to 10 regions and 21 zones. These launches extend Google Cloud’s protection for data while it is being processed, but GA applies to specific hardware, services, and locations—not every confidential-computing configuration.

What Google Cloud made generally available

The latest expansion covers three capabilities: Intel TDX Confidential GKE Nodes, Intel TDX Confidential Space, and confidential VM and GKE workloads using NVIDIA H100 GPUs on the A3 machine series. Google’s announcement names the A3 machine type a3-highgpu-1g and these three zones for the H100 offering: europe-west4-c, us-central1-a, and us-east5-a.

Separately, Intel TDX on C3 machines is available in 10 regions and 21 zones, up from three regions and nine zones in the announcement’s earlier availability snapshot. That C3 expansion is not the same as the three-zone availability named for the A3 H100 configuration; check capacity for the precise machine type and zone you plan to use.

“Generally available” applies to the named combinations. It does not establish GA for every accelerator, machine family, region, or GKE operating mode. Google’s announcement of G4 VMs and GKE Nodes with NVIDIA RTX PRO 6000 Blackwell GPUs describes those options as preview, not GA.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Confidential Computing means on Google Cloud

Confidential Computing protects data in use: information held in memory while a workload processes it. Google Cloud’s portfolio page lists Confidential VMs, Confidential GKE, Confidential Dataflow, Confidential Dataproc, and Confidential Space. These options apply the idea at different layers, from a virtual machine to a managed environment for work shared between organizations.

Google introduced Confidential VMs on July 14, 2020, as the first product in the portfolio. That launch described memory encryption on AMD EPYC processors and said applications did not require code changes. The broader concept is still distinct from encryption at rest or in transit: memory protection addresses data during computation, but it does not replace identity controls, network security, software supply-chain safeguards, key-management practices, or application security.

Which option fits your workload?

Option Best fit Protection and hardware notes Availability or operating detail
Confidential VMs Lift-and-shift applications or new workloads that need VM-level memory protection. Google’s original launch described AMD SEV on AMD EPYC. The newer Intel TDX and H100 GA combinations are specific configurations, not a replacement label for all Confidential VMs. Google says enabling Confidential VM protection does not require application code changes. Check machine-family, region, and zone support for the chosen configuration.
Confidential GKE Nodes Kubernetes workloads that need node-level protection for memory in use. Google describes node and workload memory encryption using AMD SEV or Intel TDX. Intel TDX deployments use runtime measurement registers verified by Google Cloud Attestation; node-specific keys are generated and managed by the processor. Intel TDX Nodes are GA in GKE Standard and Autopilot. Standard supports configuration through CLI, API, UI, and Terraform; Autopilot can use custom compute classes. H100-backed A3 GKE Nodes are GA in the specifically named machine type and zones.
Confidential Space Joint analytics, federated learning, private inference, or other computation involving data from multiple parties. A managed trusted-execution environment with code-integrity and hardware-rooted attestation guarantees for collaborative computation. Confidential Space with Intel TDX is GA. Its attestation-oriented design is particularly relevant when participants need assurance about the workload and protection from operators or infrastructure.
Confidential Dataflow and Confidential Dataproc Managed data pipelines or clusters that need confidential-computing infrastructure. Google describes these services as running on Compute Engine Confidential VMs. They are listed in Google Cloud’s confidential-computing portfolio; the cited launch information does not specify a new GA expansion or a universal region list for them.
G4 with NVIDIA RTX PRO 6000 Blackwell GPUs AI inference, fine-tuning, or HPC with restricted data where CPU-to-GPU traffic protection matters. Google says the G4 design uses AMD SEV and encrypts CPU-to-GPU traffic. Announced as preview, not as part of the GA H100 launch. Confirm current status and availability before planning production use.

How to choose between VM, GKE, and Space

Choose Confidential VMs for conventional applications

For a workload already packaged to run on a supported VM, Confidential VMs are the direct route to memory encryption without application code changes, according to Google’s product information. Validate the required processor family and zone before migrating; a no-code-change path does not mean every VM type is eligible or that application security tasks disappear.

Choose Confidential GKE Nodes when the workload is Kubernetes-native

GKE Nodes apply confidential-computing protection to Kubernetes workloads at the node level. Standard provides explicit configuration paths through the command line, API, console UI, or Terraform. Autopilot has a different operational model and can use custom compute classes; do not assume the Standard setup steps or available hardware map one-to-one onto Autopilot.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Synology DS225+ Private Cloud Media Server - Stream, Back Up Photos & Share Files, Intel CPU for Hardware Transcoding (2-Bay Diskless NAS)
  • Your Personal Streaming Server - Build your own Netflix-style media library and stream 4K movies, shows and photos to any device without monthly fees
  • Create Your Own Cloud - Store your entire photo, video and music collection; access from anywhere with fast 282 MB/s transfer speeds
  • Creator-Grade Backup Solution - Protect your irreplaceable content with automated backups to cloud services, external drives and remote NAS
  • Multi-Layered Data Protection - Combine RAID redundancy, automated backups and snapshot technology to prevent data loss from any cause
  • Smart Home Surveillance - Support up to 30 IP cameras with AI detection, instant alerts and secure remote monitoring

Choose Confidential Space when participants need attestation for shared computation

Confidential Space is the more purpose-built option when organizations need to collaborate without simply pooling raw data or fully trusting the infrastructure operator. Its code-integrity and hardware-rooted attestation properties help participants verify the execution environment. Attestation is not a substitute for deciding which code is trustworthy, what data it may access, and what outputs it may release.

Choose an H100 or preview G4 configuration based on status and location

For H100-backed confidential AI, the GA announcement is specific: A3, a3-highgpu-1g, and the three named zones. Google says H100 offerings protect training data, labels, model weights, and queries during compute-intensive work. G4 with RTX PRO 6000 Blackwell is a separate preview option; its announced CPU-to-GPU traffic encryption does not make it a GA alternative to the H100 configuration.

What to verify before deployment

  • Exact service and mode: confirm whether you need a Confidential VM, GKE Standard or Autopilot node, Confidential Space, Dataflow, or Dataproc configuration.
  • Hardware and location: check the machine family, processor or GPU, region, and zone together. The listed A3 H100 availability is only three zones, while the C3 Intel TDX expansion covers 10 regions and 21 zones.
  • Attestation requirements: decide who must verify workload measurements, code integrity, and the trusted execution environment, particularly for multi-party computation.
  • Performance and capacity: test the actual workload and verify current capacity. Google’s qualitative statements about limited performance impact are not a numeric benchmark or a guarantee for every workload.
  • Security boundaries: retain appropriate identity, network, software integrity, key-management, and application controls; memory encryption addresses only one part of the threat model.
  • Cost: calculate the selected machine type, disks, and other VM resources. Google’s January 27, 2025 GKE Autopilot update says additional pricing applies; the announcements do not establish one universal price.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How GA status has changed over time

Availability labels in older announcements are snapshots, not descriptions of current status. Google’s January 27, 2025 update recorded C3D Confidential GKE Nodes as GA in Standard and N2D-based Confidential GKE Nodes as GA in Autopilot, while Intel TDX Confidential Space and H100 Confidential VMs were then in preview. The newer Intel TDX announcement advances several of those capabilities to GA, including Intel TDX Confidential Space and the named H100 configurations. For a production decision, use the current release information for the precise combination you intend to deploy.

Best Value
Rack Mount Bracket for Ubiquiti Unifi Cloud Gateway UCG Max and Ultra, 1U 10-inch, Compatible with UCG-Ultra & UCG-Max (White)
  • COMPATIBILITY: Specially designed to mount Ubiquiti UniFi Cloud Gateway models UCG-Ultra and UCG-Max securely in place
  • RACK SPECIFICATIONS: Standard 1U height rack mount bracket engineered for 10-inch rack installations, offering efficient space utilization
  • MOUNTING SOLUTION: Provides stable and secure placement for your UniFi Cloud Gateway UCG Max or UCG Ultra device in server room or network cabinet setups
  • PACKAGE CONTENTS: Includes one (1x) 1U 10-inch rack mount bracket specifically designed for UniFi UCG Ultra & UCG Max Gateway installations
  • INSTALLATION: Purpose-built bracket ensures proper device positioning and reliable mounting in standard 10-inch rack environments

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.