Confidential Computing GA in VCF 9.1 Data-in-Use Protection as a Placement Attribute
Intel TDX and AMD SEV-SNP reach general availability, Quick Boot returns on CC-active hosts, and VCF Operations profiles host capability automatically.
Encryption at rest is solved. Encryption in transit is solved and in 9.1, hardware-offloaded via Intel QAT. The remaining exposure has always been data in use: memory contents visible to the hypervisor and to anyone who compromises it. Confidential Computing closes that gap with hardware trusted execution environments, and VCF 9.1 moves the capability to general availability with the operational rough edges addressed.
What GA Includes
• Intel TDX and AMD SEV-SNP support at general availability both major CPU vendors’ trusted execution technologies, so the hardware conversation isn’t vendor-locked.
• Quick Boot re-enabled on Confidential Computing-active hosts the host lifecycle penalty that previously made CC operationally expensive is removed. CC hosts patch and reboot like the rest of the estate.
• VCF Operations automatically profiles ESX hosts for Confidential Computing capability the estate inventory question, which hosts can run CC workloads, is answered by the platform rather than by procurement records and tribal knowledge.
Who Needs This
Three customer profiles drive CC adoption. Sovereign AI deployments, where model weights are the crown jewels and the threat model includes anyone with infrastructure access. Regulated data processing, where controls must hold even against a compromised or malicious infrastructure operator. And multi-tenant estates MSP or internal shared platform where tenants require cryptographic isolation guarantees stronger than hypervisor trust boundaries.
Broadcom’s positioning of VCF 9.1 as the platform for production AI makes the first profile the headline: securing AI workloads, proprietary models, and sensitive data from hypervisor to application layer is exactly the CC use case.
The Operational Shift From Cluster Build to Placement Attribute
The GA changes the design pattern. Previously, Confidential Computing implied a special-purpose cluster build: dedicated hosts, exceptional lifecycle handling, a separate operational island. With Quick Boot restored and host capability profiled automatically, CC becomes a workload placement attribute within the standard estate: VCF Operations knows which hosts are capable, and placement policy in VCF Automation can pin confidential workloads to them the same Infrastructure Policy machinery that handles licence pinning and data residency.
That composition matters. Confidential workloads inherit the standard estate’s lifecycle, observability, and automation instead of maintaining parallel operational processes for an isolated island. The marginal cost of running CC drops accordingly and marginal cost is what has kept CC adoption theoretical in most estates.
The Architect’s Takeaway
Confidential Computing in 9.1 is ready to be designed as a tier, not a project. Put host CC capability in the procurement baseline for AI and regulated clusters, express confidential placement as policy, and let the standard operational model carry it. For sovereign AI conversations in particular, data-in-use protection as a policy-driven platform property is a differentiated answer give it a named tier in the HLD and price the hardware delta honestly.
Sources
• Broadcom Strengthen Zero Trust Platform Security and Resilience with VCF 9.1
• Broadcom VCF 9.1: The Secure, Cost-Effective Private Cloud Platform for Production AI
• Broadcom Streamline, Simplify and Protect all your AI workloads with VCF 9.1
• Broadcom Announcing VCF 9.1: Modern Private Cloud Built for Efficiency and Resilience