Skip to content

Conversation

@erikaheidi
Copy link
Collaborator

@erikaheidi erikaheidi commented Oct 21, 2025

This PR adds initial docs for Chainguard VMs. It creates a new top-level item in the menu under "Libraries". Two documentation pages are included: "Overview" and "FAQ".

Preview Links:

@erikaheidi erikaheidi requested a review from a team as a code owner October 21, 2025 15:54
@netlify
Copy link

netlify bot commented Oct 21, 2025

Deploy Preview for ornate-narwhal-088216 ready!

Name Link
🔨 Latest commit 1775b2a
🔍 Latest deploy log https://app.netlify.com/projects/ornate-narwhal-088216/deploys/68f8fe4127181f0008b5a6fa
😎 Deploy Preview https://deploy-preview-2703--ornate-narwhal-088216.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

Copy link
Member

@smythp smythp left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pretty polished stuff. I mostly suggested adding links and small edits. 👍


## Compliance and SLAs

Chainguard VMs (running Chainguard OS) are intentionally designed to minimize risk, maximize transparency, and satisfy security standards such as CIS Benchmarks, FedRAMP, SOC 2, and others.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we link to some of our own content on the ATO processes (fedramp etc)


Chainguard VMs (running Chainguard OS) are intentionally designed to minimize risk, maximize transparency, and satisfy security standards such as CIS Benchmarks, FedRAMP, SOC 2, and others.

* CVE remediation backed by an industry-leading SLA: 7 days for critical, 14 days for all others
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Link to our SLA page


## Learn More and Get Started

Chainguard VMs are available through a subscription. To learn more and get started today, use [this form](https://get.chainguard.dev/vmearlyaccesswaitlist?utm_source=cg-academy&utm_medium=referral&utm_campaign=dev-enablement).
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"use this form" seems a little abrupt, maybe "join the waitlist" or something more descriptive.


## What are Container Host VMs and which versions are available?

Container Host VMs allow you to run containerized workloads on a hardened VM runtime. We currently offer container host VMs for AWS Container Services ECS and EKS, and also for native compute instances on AWS EC2, Google Compute Engine, and Azure Compute.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

More links here might be good


## Do Chainguard VMs support FIPS?

Yes, Chainguard VMs support Kernel Independent FIPS.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this needs more elaboration (or leave it out as it raises more questions than it answers). Are there FIPS versions of the containers? Why would there be kernel-indep FIPS if there's a kernel shipped with the VM?

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You answer pretty well below but still think it might be best to consolidate or take out.


This is more relevant in on-prem environments.

Chainguard VMs support kernel independent FIPS. This means that application workloads use a FIPS validated entropy source independent of the kernel. The advantage to this approach is that the certification of the entropy source does not need to be performed against a specific kernel, so customers can take advantage of new kernel features while remaining FIPS compliant. It also means that VMs no longer need to be booted in FIPS mode. The disadvantage is that some low level operating system functions such as disk encryption, IPSEC etc.. are not able to use FIPS validated entropy. In clouds, disk volumes are encrypted and provided with FIPS validated entropy, as is network and filesystem encryption. In cloud, kernel independent FIPS is a more efficient way of servicing FIPS workloads in VMs.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

in clouds > on cloud platforms
in cloud (at end) > on the cloud

erikaheidi and others added 4 commits October 22, 2025 17:53
Co-authored-by: Patrick Smyth <[email protected]>
Signed-off-by: Erika Heidi <[email protected]>
Co-authored-by: Patrick Smyth <[email protected]>
Signed-off-by: Erika Heidi <[email protected]>
Co-authored-by: Patrick Smyth <[email protected]>
Signed-off-by: Erika Heidi <[email protected]>
Co-authored-by: Patrick Smyth <[email protected]>
Signed-off-by: Erika Heidi <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants