How we wipe an NVMe when you release an instance
Engineering
Every instance's NVMe is a LUKS2 volume with a key generated at provisioning and held in the host TPM, sealed to that instance ID. Releasing the instance asks the TPM to destroy the key — at that point the drive contents are ciphertext with no key anywhere. Then we blkdiscard the namespace and run a 30-second verify pass that samples 2,000 random LBAs and confirms they read as zero. Only after that does the slot go back to inventory. This adds about 90 seconds to the release. We think it's worth it.
Rent the hardware this post is about
Dedicated GPUs by the week or the month, paid in crypto, in three US datacenters.