Working with AMD SEV-SNP - Amazon Elastic Compute Cloud
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Working with AMD SEV-SNP

Find supported instance types

You can use the Amazon CLI to find instance types that support AMD SEV-SNP.

To find the instance types that support AMD SEV-SNP using the Amazon CLI, use the following describe-instance-types command.

$ aws ec2 describe-instance-types \ --filters Name=processor-info.supported-features,Values=amd-sev-snp \ --query 'InstanceTypes[*].InstanceType'

Example output.

[ "r6a.2xlarge", "m6a.large", "m6a.2xlarge", "r6a.xlarge", "c6a.16xlarge", "c6a.8xlarge", "m6a.4xlarge", "c6a.12xlarge", "r6a.4xlarge", "c6a.xlarge", "c6a.4xlarge", "c6a.2xlarge", "m6a.xlarge", "c6a.large", "r6a.large", "m6a.8xlarge" ]

Turn on AMD SEV-SNP at launch

You can use the Amazon CLI to launch an instance with AMD SEV-SNP turned on.

To launch an instance with AMD SEV-SNP turned on using the Amazon CLI, use the run-instances command and include the --cpu-options AmdSevSnp=enabled option. For --image-id, specify an AMI with the uefi or uefi-prefered boot mode and an operating system that supports AMD SEV-SNP. For --instance-type, specify a supported instance type.

$ aws ec2 run-instances \ --image-id supported_ami_id \ --instance-type supported_instance_type \ --key-name key_pair_name \ --subnet-id subnet_id \ --cpu-options AmdSevSnp=enabled

Check AMD SEV-SNP status

You can use one of the following methods to find instance types that support AMD SEV-SNP.

Amazon CLI

To check whether AMD SEV-SNP is turned on for an instance using the Amazon CLI, use the describe-instances command. For --instance-ids, specify the ID of the instance to check.

$ aws ec2 describe-instances --instance-ids instance_id

In the command output, the value for AmdSevSnp in CpuOptions indicates whether AMD SEV-SNP is turned on or off.

Amazon CloudTrail

In the Amazon CloudTrail event for the instance launch request, a value of "cpuOptions": {"AmdSevSnp": enabled} indicates that AMD SEV-SNP is turned on for the instance.