Does dstack support GCP / Azure
dstack is open for PRs to add that support. Currently it focuses on bare metal because it offers the most fine-grained control and access to vanilla TDX.How does KMS key generation work and how can it be modified?
The key generation logic is implemented in the onboard service:Reference: https://github.com/Dstack-TEE/dstack/blob/master/kms/src/onboard\_service.rs#L50
How does on-chain KMS work and how can I customize its governance?
The KMS contract allows for customizable ownership and governance:- During deployment, you can specify an owner
- After deployment, ownership can be transferred using transferOwnership function
Reference: https://github.com/Dstack-TEE/dstack/blob/master/kms/auth-eth/hardhat.config.ts#L96
Where can I find KMS deployment instructions?
Complete deployment documentation is available here: Reference: https://github.com/Dstack-TEE/dstack/blob/master/docs/deployment.mdHow does the current data encryption system work?
The system uses Linux’s built-in LUKS (Linux Unified Key Setup) for disk encryption:Reference: https://github.com/Dstack-TEE/dstack/blob/master/tdxctl/src/fde\_setup.rs#L437-L442

