Servers as they should be – shipping early 2022
oxide.computer
oxide.computer
But if I were looking at this, judging from the quality of people they've amassed in their engineering team, is there any chance they won't be acquired in 6 months?
To anyone looking to take a bet on this, what is the answer to "what's your plan for when your stellar team gets acquired?" And what answer will satisfy that buyer?
Update: Adding another question, does this "environment" (where any really great product with great talent in it can be acquired very quickly) have a chilling effect on purchases for products like this?
Hopefully some Oxide people can answer :-)
Also, if it's of any solace, I really don't think any of the existing players would be terribly interested in buying a company that has so thoroughly and unequivocally rejected so many of their accrued decisions! ;) I'm pretty sure their due diligence would reveal that we have taken a first principles approach here that is anathema to the iterative one they have taken for decades -- and indeed, these companies have shown time and time again that they don't want to risk their existing product lines to a fresh approach, no matter how badly customers want it.
Congrats on the announcement, here's hoping you're right! This looks too interesting to be swallowed by Oracle or HPe.
A catastrophic oxidation reaction leading to total consumption of the fuel?
I hope you drop a new episode soon
I presume you wouldn't consider European remote given your PST timezone requirement, but I guess I'll consider your company one of those dream places to work were I to make my return to the US!
The fact is that it only has to be good enough for them to find the people that they want, rather than for pleasing random HN commenters.
Now I don’t know how oxide is set up, but I’d assume the founders still retain the large majority of shares.
[1] https://oxide.computer/blog/compensation-as-a-reflection-of-...
https://a16z.com/2021/05/27/cost-of-cloud-paradox-market-cap...
This team is, by all measures, going to hit it out of the park. There's just a solid amount of talent, experience and insight all-round.
And to be clear, I am not at all disparaging teams that get acquired – that would be silly. I'm just saying that we are in an environment these days where very few of these kinds of companies get a chance to grow before being acquired and WE are the ones that lose even though the people working at the company rightfully earn a nice payout.
I have the same "fear" about Tailscale, a company whose product we love and have started using, and are about to purchase.
But the fact that a member of the founding team themselves answered my message above in plain english (not surprising), is honestly refreshing.
But on the other hand I can see F500s (oil & gas companies, big engineering and defense firms, etc.) getting a rack or two to run their cloud-like stuff. They would not be taking much risk; this would be one system among many others they have, and it will have a life of 5 to 7 years anyway (a few million dollars and 7 years is peanuts for an oil & gas or mining company whose CapEx goes into the billions, over 50+ years horizons). I think the value is in having a cloud-like system that doesn't require an entire IT/Ops team to run.
Not sure that 'with the software baked in' is a good phrase to use. Sounds inflexible. Perhaps a different phrasing would help?
I don't understand this concern at all.
But second, I'd love to understand the compute vs storage tradeoff chosen here. Looking at the (pretty!) picture [1], I was shocked to see "Wow, it's mostly storage?". Is that from going all flash?
Heading to https://oxide.computer/product for more details, lists:
- 2048 cores
- 30 TB of memory
- 1024 TB of flash (1 PiB)
Given how much of the rack is storage, I'm not sure which Milan was chosen (and so whether that's 2048 threads or 4196 [edit: real cores, 4196 threads]), but it seems like visually 4U is compute? [edit: nope] Is that a mistake on my part, because dual-socket Milan at 128 threads per socket is 256 threads per server, so you need at least 8 servers to hit 2048 "somethings", or do the storage nodes also have Milans [would make sense] and their compute is included [also fine!] -- and so similarly that's how you get a funky 30 TiB of memory?
[Top-level edit from below: the green stuff are the nodes, including the compute. The 4U near the middle is the fiber]
P.S.: the "NETWORK SPEED 100 GB/S" in all caps / CSS loses the presumably 100 Gbps (though the value in the HTML is 100 gb/s which is also unclear).
[1] https://oxide.computer/_next/image?url=%2Fimages%2Frenders%2...
eta: also suspect 30TB total just means they're leaving 64GB ram for the hypervisor OS on each node.
Btw. if I count correctly, they have 20 SSD slots per node (if a node is full width) and 16 nodes. They would need 2 TB to reach 1 PB of "raw" capacity with the obvious redundancy overhead of ~ 20%.
It is also quite possible, they don't use ZFS at all and use e.g. Ceph or something like it but I don't think that is the case, because that wouldn't be cantrillian. :-) E.g. using Minio, they can provide something S3 like on top of a cluster of ZFS storage nodes too but they most likely get better latency with local ZFS and not a distributed filesystem. Financial institutions especially seem to be part of the target here and there latency can be king.
Guessing they aren't counting threads (they say "cores"), so 64 cores per socket, 128 cores per server, 16 servers => 2048 cores.
So maybe that's the better question: what are the 4U worth of stuff surrounding the power? More networking stuff? Management stuff? (There was some swivel to the back of the rack / with networking, but I can't find it now)
Edit: Ahh! The rotating view is on /product and so that ~4U is the fiber. (Hat tip to Jon Olson, too)
As someone who has designed quite a few datacenters, whats more interesting to me in this evolution of computing is the reduction in cabling.
Cabling in a DC is a huge suck on all aspects - plastics, power, blah blah blah - the list is long....
But there are a LOT of cabling companies that do LV out there - so the point is that when these types of systems get more "obelisk" like, are many of these companies going to die? (I'm looking at you Cray and SGI.)
When I worked at Intel - I had a friend who was a proc designer at MIPS - and we talked about rack insertion and a global back-plane for the rack (which we all know to be common now) - but this was ~1997 or so... but when I built the Brocade HQ - cables were still massive and it was an art to properly dress them.
Lucas was the same - so many human work hours spent on just cable mgmt...
Their diagrams of system resiliency is odd in my opinion:
https://i.imgur.com/GB0fzIl.png
That looks like a ton of failures that they can negotiate...
Whats weird is the SPF isn't going to be in your DC/HQ/Whatever - its going to be outside - this is why we have always sought +2+ carrier ISPs or built private infra...
A freaking semi truck crashed into a telephone pole in Sacramento the other day and wiped comcast off the map to half the region.
https://sacramento.cbslocal.com/2021/05/25/citrus-heights-an...
Thats ONE fiber line that brought down 100K+ connections...
---
EDIT: I guess what I am actually saying is that this entire marketing strat is to convince any companies that *"failure is imminent and please buy things that are going to fail, but don't worry because you bought plenty more things to live beyond the epic failure that these devices will have"*
---
Not to discredit anything this company has going for its product - but their name is literally "RUST" (*oxide*) --- which we all know is what kills metal.
And what do we call servers: *Bare Metal*
> With accelerating conviction that we would build a company to do this, we needed a name — and once we hit on Oxide, we knew it was us: oxides form much of the earth’s crust, giving a connotation of foundation; silicon, the element that is the foundation of all of computing, is found in nature in its oxide; and (yes!) iron oxide is also known as Rust, a programming language we see playing a substantial role for us. Were there any doubt, that Oxide can also be pseudo-written in hexadecimal — as 0x1de — pretty much sealed the deal!
http://dtrace.org/blogs/bmc/2019/12/02/the-soul-of-a-new-com...
We built a few racks of Supermicro AMD servers (4 X computes in 2U), and we load tested it to 23kva peak usage (about 1/2 full with nthat type of nodes only, our DC would let us go further)
Were also over 1 PB of disks (unclear how much of this is redundancy), also in NVMe (15.36 TB x 24 in 2U is a lot of storage...)
Other then that not a bad concept, not sure of a premium they will charge or what will be comparable on price.
- There's a bunch of RJ45 up top that I don't quite understand :)
- A bunch of storage sleds
- A compute sled, 100G QSFP switch, compute sled sandwich
- Power distribution (rectifiers, I'd think, unless it's AC to the trays?)
- Another CSC sandwich
- More storage.
I assume in reality we'd have many more cables making things less pretty, given the number of front-facing QSFPs on those ToRs.
Out of data-plane HW mgmt probably
They basically reinvented mainframes. Seems it has a lot in common with Z series.
Scalable locked in hardware, virtualization, reliability, engineered for hardware swaps, upgrades.
A proprietary operating system (?) from what someone said. (Offshoot of Solaris +++ (???) By that I mean that most of it, or all of it might be open sourced forks, but it will be an OS only meant to run on their systems.
(It would be fun to get it working at home, on a couple of PCs or a bunch of PIs)
They lack specialized processors to offload some workloads to.
Perhaps in modern terms shelfs of GPUs or a shelf fast FPGA , DSP processors. The possibilities are huge.
I didn't find any mention of from what I read.
They also lack the gigantic legacy effort to be compatible, which is a good thing.
That being said, this solution is the mother of all lock ins...
I could see it used for the non-critical part of a company's infrastructure. I would not run production stuff on it, but it could work for development systems, test boxes, etc. Basically give developers access and let them create and destroy as many VMs as they need, whenever they need.
Note: I'm typing this from a 9 year old thin-and-light, so that's probably part of the problem.
It’s all fun stories from people doing amazing things with computer hardware and low level software. Like Ring-Sub-Zero and DRAM driver level software.
There are lots of reasons to be enthusiastic about Oxide but for me, this one takes the cake. I hope they are successful, and I hope this attitude spreads far and wide.
- dedicated to virtualization, done their way
- rather inflexible in hardware specs
- vendor-locked at the rack - if you have hardware from someone else, it can't live in the same cabinet
I guess if you just want a pretty data center in a box and look like what they consider a 'normal' enterprise to be, it might appeal. But I'm not sure how many people asked for Apple-style hardware in the DC.
> - rather inflexible in hardware specs
> - vendor-locked at the rack - if you have hardware from someone else, it can't live in the same cabinet
This describes legacy IBM platforms quite well. If they can leverage hyperscaling tech to be better and cheaper than what IBM is currently offering, that's enough to make it worthwhile.
The specs are damn good. When it is all top-of-the-line, inflexibility is kind of a mute point. Where else are you going to go?
> But I'm not sure how many people asked for Apple-style hardware in the DC.
Well integrated, performant and reliable hardware that runs VMs where you can put anything on it is pretty much all everyone running their own hardware is looking for.
Honestly I am surprised how many here completely misunderstand what their value proposition is.
Because if I ran this, would have to manage it. Given that I have lots of virtualization to manage already, I would want it to use the same tooling for rather obvious reasons.
> is pretty much all everyone running their own hardware is looking for.
I don't think you talk to many people who do this, but as someone who manages 8 figures worth of hardware, I can tell you that is absolutely not true.
> The specs are damn good. When it is all top-of-the-line, inflexibility is kind of a mute point. Where else are you going to go?
To some hardware that actually fits my use case, that is managable in an existing environment? Oh wait - I already have that. I mean, seriously - do you think they're the only shop selling nice machines?
The value-add is all wrong, unless you are a greenfield deployment willing to bet it all on this particular single vendor, and your needs match their offering.
I'm not saying you would want to, but maybe their expectation is that you'd plan to transition everything to their system. Either gradually as part of the normal cycle of replacing old hardware or all at once if you want to be aggressive.
If their way is actually better, then it might make sense. You'd go through an annoying transition period but be better off in the end.
The hardware options do seem limited, but maybe that would change if their business takes off and they get enough customers to justify it. They're definitely saying simplicity is a good thing, but maybe that's just marketing spin that sounds better than the alternative of saying they're not yet in a position to offer that flexibility.
It's probably selling to the "Amazon-style hardware in your DC market", which I think should be fairly ripe. Building your own private cloud from parts defeats a lot of the purpose...avoiding your own plumbing.
A smart company would stay away from this kind of strong lock-in.
This is a selling point - if it's actually better (which, why not? most of the existing virtualization management solutions either suck or are hugely expensive).
If it's not better, big deal? I'm assuming you could just throw Linux on these things and run on the metal or use something different, right? Given how much bcantrill (and other Oxide team members) have discussed loving open hardware, I seriously doubt they would intentionally try to lock down their own product!
> vendor-locked at the rack - if you have hardware from someone else, it can't live in the same cabinet
This is aimed at players so big that they want to buy at the rack level and have no desire to ever touch or carve up anything. It's a niche market, but for them this is actually a plus.
If "Apple-style" means lower skilled-labor cost for maintenance - absolutely worth it.
Anyway, glad to finally get a glimpse of what Oxide has to offer. Looking forward to seeing a lot more.
[1]: https://soundcloud.com/user-760920229/why-your-servers-suck-...
If it's a custom software stack, might be nice to get a miniature dev-kit!
In reality I would never want this type of hardware... It reminds me of the old boat anchor bladecenter rigs we used to use. They were great, up until you had to replace one of the blades after the support was up. It's not always practical to replace hardware every 3 years like we're supposed to, so this type of stuff sticks around and gets some barnacles.
What would be fantastic would be if the entire industry committed to an open spec for large chassis like this with a standardized networking and storage overlay... But that would never happen because vendor lock-in is the big money maker in 'enterprise'.
But wow, absolutely gorgeous machines.
Isn't the Open Compute Project supposed to be working on that kind of stuff?
One of the most powerful elements of the trust root system is in audit ability and access control for both service-to-service and human-to-system aspects and I'm really interested in seeing how this plays out.
For example, a service mesh where hosts can be identified securely and authorized in a specific role unlocks a lot of low-friction service-to-service security. I'm curious what Oxide plan to provide in this space API and SDK wise.
I see some Zanzibar related projects on their GitHub, so it can be assumed the ACL system will be based on the principles there - but that's more a framework than an implementation.
On paper with RDMA and NVMe-OF you could access any drive from any compute unit... but that's easier said than done :)
The problem with this model is its no longer commodity hardware. You are kinda locked into their exosystem of specialized network and server equipment.
And it of course introduces some unique failure modes to mitigate too.
Not to say its not a cool idea, it’s just interesting to see how hardware trends oscillate between commodity and highly specialized proprietary designs.
I'm curious about management. Can the rack operate completely standalone? I assume when you have multiple there will be some management abstraction above the rack layer?
The closest direct equivalent that I can think of to this is AWS outposts. Are there any others that I'm forgetting?
I believe Oxide is attempting to capture a much broader market than that.
(Edit: Previous Discussions https://news.ycombinator.com/item?id=21682360 )
Also thinking if the Website is not finished? All the "Read More" actually hide very little information, if so why hide it? And doesn't seems to explain the company very well. Seems like we need to listen to their PodCast to find out what is going on. ( Edit: Found a Youtube Video about it https://www.youtube.com/watch?v=vvZA9n3e5pc )
>Get the most efficient power rating and network speeds of 100GBps without the pain of cable
100GBps would be impressive, 100Gbps would be ... not much?
A interesting thing is all the terminal like graphics are actually HTML/CSS and not images.
100GBps would be impressive, 100Gbps would be ... not much?
Even 100GBps(800Gbps) is not much for 2048 cores, depends on application, in certain applications, 32 cores could drive 100Gbps...
Literally every single server vendor, and almost all (if not all?) storage vendors on the planet are pushing HCI because that is what mid and large size companies want. This is the fastest growing market segment in hardware (because they now realize that hybrid-cloud is the preferred customer model, and most of their customers now are deploying or already have deployed their own internal cloud). Oxide appears to me to be HCI done correctly. I currently work for one of their competitors, and for one, am keeping at eye on their careers page!
Also, 100Gb meets requirements for 99.999% of the customers out there.
Excited to see tech startups do actual tech instead of chasing VC funded growth hacking.
I wonder what sort of enterprise customers this targets.. (definitely not for individual devs)
I'm curious if ARC will be running with primarycache=metadata to rely on low latency storage and in-VM cache, otherwise I could see ARC using a fair bit of that RAM overhead in the hosts.
Intel is losing on the client and server. everyone is jumping ship to either ARM or AMD for client/server. hopefully Intel new engineer CEO can turn it around like AMD engineer CEO (Lisa Su)
Intel could win price/performance, but they would need to cannibalize their own low-end and mid-range market. If they could make a good bet that they would have high yield in one more cycle, that would make sense. If they don't think that will happen, there's nothing much that will save them, and they're extracting the money that they can right now.
I think relatively few people want to buy a rackmount server based on a motherboard that hosts a cannibalized M1 limited to the 16GB of RAM that it came with, paying the price premium for the rest of the machine. An M1 seems to be roughly equivalent to an Ryzen 5000-series CPU, and you can get those for $300 (6c/12t) through $1K (16c/32t) without having to go through the labor costs of pulling out the CPU from a $900 carrier.
That is speaking as someone who wants AMD to grab more market shares ( and has been stating the same for nearly three years and constantly being told off by all AMD fans they are doing fine )
They make really nice chips, but what happens if BigCorpXYZ just gets a quote from AMD and goes straight to Intel to get it matched - i.e. the Cloud isn't that performance-intensive, so now they get to stay on the Intel stack for less money.
Second thoughts: Oh it's former SUN/joyent guys, nvm.
Will the console have fancy ncurses reporting and analytics like then product page?
This is a solid private-cloud play aimed at those corporations (probably mainly financials, but other sectors too I'm sure...) who don't want to outsource to the likes of AWS / GCP.
Government, too (especially non-US).
That "custom software," though, is where the magic often lies. As a software person that worked at hardware companies for most of my career, I know all too well, how disrespectful hardware people are of software. If they have a good software-respecting management chain, then it might be pretty awesome.
[0] https://www.prnewswire.com/news-releases/viking-enterprise-s...
Wanna check out my first professional engineering project ever?
https://littlegreenviper.com/TF30194/TF30194-Manual-1987.pdf (Downloads a PDF)
"The elevation of the room where the rack is installed must be below 10,005 feet (3,050 meters)."
I think it's a good sign that they're aware of the additional support issues associated with higher altitude. Shows that they've really thought things through.
I am posting this info because it seems their "team" page (https://oxide.computer/team/) is no longer working. I thought it was weird there was no way to see the senior leaders from the website. When I first opened the site, I vaguely remembered this brand name, but could not remember who was behind it.
@bcantrill: I assume this is a mistake. Plus I cannot find a 'Team' link anywhere on the current website.
// Edit
I just found section "Meet the Team" on this page: https://oxide.computer/careers
Looks like they did!
proposition is good, history is bad
(plus I suspect there will be more to come...)
Also your site badly crashes Brave iOS browser fwiw.
However I also do not see when I will buy a full shelf of gear, even though I would love to. Will they also release a maxi version, micro version and a nano version? Ie. 2U server, PRO workstation and an small formfactor? I think the innovations they have done to these computers deserve to be even more places than just in a massive and awesome data processing rack.
Probably a lot more than any sane person would pay for a home server.
But I won’t stop you from trying! Wouldn’t it be cool to have that plugged into your local network?
And possibly noisy. Yes, noisy.
But honestly, the equivalent is just libvirt on commodity hardware with openzfs storage; the value here is high end hardware with custom firmware and well-integrated software, not really something you can port usefully.
> Some will say that we should be paying people differently based on different geographical locations. I know there are thoughtful people who pay folks differently based on their zip code, but (respectfully), we disagree with this approach. Companies spin this by explaining they are merely paying people based on their cost of living, but this is absurd: do we increase someone's salary when their spouse loses their job or when their kid goes to college? Do we slash it when they inherit money from their deceased parent or move in with someone? The answer to all of these is no, of course not: we pay people based on their work, not their costs. The truth is that companies pay people less in other geographies for a simple reason: because they can. We at Oxide just don't agree with this; we pay people the same regardless of where they pick up their mail.
More seriously, the animations have "ascii-animation" classes in the dom, tui is probably more fitting aesthetic label if you ask me. Not sure if a lib is involved or its custom. Either way it is done very nicely.
1 PB of flash is quite a bit but you could get perhaps 5x as much with HDDs probably (even with a relatively low density of 40x 12 x 12 TB). The problem really is I think, they wouldn't be able to write the HDD firmware in Rust in time (or at all, because no HDD manufacturer would sell an HDD to them without making sure their proprietary firmware is used). SSDs don't necessarily have this property as they are much more like the other components of a modern server.
Can't miss the Halt and Catch Fire tv references including Haley Clark alongsize Woz and other tech legends and in the blog post about the launch a terminal window with character names like Gordon Clark, etc. Love to see it.
Not great, but this is near COTS hardware. They can do significantly better than that.
That's a rather seamless extension of what OS's have to do already in order to deal with NUMA. Pinning can definitely be worthwhile since the default pointless shuttling of workloads across cores is already killing performance on existing NUMA platforms. But that could be addressed more elegantly by adjusting some tuning knobs and still allowing for migration in rare cases.
So device is not set and forget secure, but you have to physically secure it (not that you wouldn't, but now it can really matter if someone has physical access to the machine).
GPLv3 has been used more recently as a block to others taking code and developing things further given some of the clauses and incompatibilities it introduced.
It takes a huge amount of manpower to maintain a kernel, and this effort is not shared much.
I guess that zfs is the selling point here, but still...
Or https://www.hpe.com/us/en/greenlake.html
Disclaimer vmware employee, but I dont work in this area.
Is this to compete against Nutanix / VCE?
I am not a hater in the least but I really am failing to understand what is unique about this offering. It seems like you have no options regarding the internals, and so scaling compute separately from storage doesn't seem possible. I also am very suspect about offerings like this that have not yet released a second version of their key parts. Everyone says that they are going to be backwards compatible, but then the reality of managing heterogenous generations of gear in a homogenous fashion strikes and you get weird behavior all around.
Long story short, I would love to know what a customer of this scale of physical infrastructure is getting with Oxide that they would not be better served by going to one of the major vendors.
Because that's something the current "major vendors" really are irredeemably terrible at.
Sure, they have a solid team of engineers but what is the value proposition exactly? A blackbox server that we built to our taste (AMD Milan, what if I want Intel Xeon?) to provide you custom software to manage and monitor server health and notify you if you could upgrade/downgrade to a different size? Oh and no cables with lots of aesthetics to make your datacenter look pretty... And?
Congrats Bryan et al.
Oh, and open firmware.
As opposed to what? But seriously, why do all ILOMs suck and are there any exceptions?
It's possible the prices are different now, but you would need customers looking to drop > 1 million dollars in CapEx for the management capabilities they are providing. Possibly non-cloud Fortune-500?
that said, I do feel persistently sad that we can't fix structural problems because the market is such a gradient descent world.
But most of those are so entrenched and wrapped up in their customers. I imagine the target here is actually acquisition, it would just be too hard to get a foothold as an up-and-comer.
Also it usually means giving loaner gear to companies for an extended period for them to evaluate pre-purchase, showing your support, etc. That's a lot of up-front cost for someone without a warchest.
I'm also kind of surprised by the site. It sells to geeks well, but isn't the normal "look at our customers in key industry segments!", "something something Gartner magic quadrant", "whitepapers!" thing. Selling to execs on these things is usually a matter of convincing them they're not making a "bad" decision. They're "cool", but enough industry people agree with them that it's not career limiting if it doesn't pan out.
I like the idea of the product, and it would be nice to have another player. But it's like starting a new car company, and I feel like they're selling to mechanics.
seems to be excluding Bolivia and probably Mars too.
And finally, its nice to see people with brains building real things with nary a mention of "blockchain".
What software are we talking about anyways? It's all incredibly vague, but it seems to reach all the way into the Kubernetes sphere. Why would I run this over something I can use on my next job?
And the idea of "these racks are my kubernetes cluster and are supported by the OEM as such" has a lot of value to a lot of the medium sized IT departments I've run across.
Can you expand on what you mean on "coupling the hardware to the software"?
The software running on M1 is a bespoke fit for it. That's why the performance in macOS on M1 is phenomenal. It was custom made to execute optimally on it.
this makes "Oxide Computer Company" the primary target and point of vulnerability in multiple ways.
1) rogue employees (state-sponsored, corporate espionage) could replace the software. customers could do nothing about it, and might not even be told.
2) sale of the company by the VCs or a Corporate take-over gives no guarantee that what is safe now will be safe in future, no matter what the VCs or the company says right now.
3) whatever expertise "Oxide Computer Company" thinks they have, they're the single-point-of-failure. the larger the number of customers, the less likely that a given vulnerability will be immediately fixed and distributed out.
this is just some of the possibilities. sorry to say that there's so many things wrong with this idea it's really hard to hold back and not say anything.
now, if the full source code right to the bedrock is available, and the CUSTOMER is given FULL CONTROL, THEN we do not have a problem.
by "full control", that includes:
* all DRM keys including TPM signing private keys * all peripheral initialisation source code (including DDR4 firmware, PCIe firmware and USB3 firmware) * BMC (Boot Management Console) source code * BIOS source code * Operating system source code * full source code for all tools and toolchains for the above to avoid vendor lock-in and the possibility of the toolchain itself introducing rogue code.
this is one hell of a list and it's almost impossible to fulfil with today's "NDA'd proprietary firmware 3rd party licensing" mindset. the only company in this secure server space to my knowledge that's achieved this is Raptor Engineering with the TALOS-II, when running with the Kestrel BMC replacement, on the Lattice ECP5 FPGA.
So in other words these servers will implement restrictive code signing practices and will be vendor-controlled, not owner-controlled?
This is not my idea of "secure", and really in the wake of things like the Solarwinds or RSA hacks it shouldn't be anyone's idea of secure. Vendor-holds-the-keys is not an acceptable security model.
A comment below mentions open firmware, open firmware is useless without the right to deploy modified versions of it.
Happy to take clarification on this.
Owner-controlled remote attestation is entirely viable, e.g. Talos II is capable of this with a FlexVer module.
I meant as opposed to keys/signing done in software.
>Owner-controlled remote attestation is entirely viable, e.g. Talos II is capable of this with a FlexVer module.
I skimmed the product brief[1] and it looks like it's basically a TPM that has a secure communications channel (as opposed to LPC which can be MITMed)? I'm not really sure how this is an improvement, because you're still relying on the hardware vendor to send the PCR values. So at the end of the day you still have to trust the hardware vendor, although the signing is done by you, but I'm not really sure how this adds any benefit.
[1] https://www.raptorengineering.com/TALOS/documentation/flexve...
Secure boot chain
Our boot flow is secure by default. Our firmware is open source and attestable.
There is a link to "Explore Repos." Is coreboot the open source firmware?
https://github.com/oxidecomputer/coreboot
Open Firmware is different than coreboot.