Q: Can I run Intel TDX confidential computing on an OpenMetal GPU server?

Intel TDX and GPU passthrough cannot be combined in a single trust boundary on OpenMetal GPU servers, so you can run a TDX confidential VM or a passed-through GPU, but not both together. 

Explore GPU servers

The Xeon 6530P in OpenMetal’s GPU servers supports Intel TDX, but an attested confidential VM (Trust Domain) with an in-boundary GPU (the TEE-IO / TDX Connect path) is not available on this platform at this time. GPU workloads therefore run on the RP6000 and H200 as single-tenant bare metal with physical isolation, which is itself the foundational protection for proprietary models and inference data, rather than TDX memory encryption.

If your requirement is a hardware-attested confidential VM, OpenMetal’s non-GPU Granite Rapids bare metal servers provide TDX today. For confidential computing on the GPU host, Intel SGX is available on the CPU for application-level enclaves, alongside TME-MK total memory encryption.

Security diagram: two mutually exclusive options on an OpenMetal GPU host, a TDX confidential VM or GPU passthrough, not both.

This is an evolving area tied to NVIDIA and Intel roadmaps, so re-confirm with OpenMetal before designing around a combined TDX-plus-GPU trust boundary. 

“OpenMetal provided the agility, customization and performance we required to move quickly from just an idea to a fully functioning public cloud offering.”

Anonymous Founder, Founder — Cloud Hosting Company

Interested in OpenMetal Products?

Contact Us

We’re available to answer questions and provide information.

Reach Out

Schedule a Consultation

Get a deeper assessment and discuss your unique requirements.

Schedule Consultation

Try It Out

Take a peek under the hood of our cloud platform or launch a trial.

Trial Options