Integrity Policy Enforcement
IPE is a Linux Security Module that makes allow/deny decisions based on the integrity properties of files — whether a file is backed by dm-verity, protected by fs-verity, or originates from the initramfs.
Deployed in production
IPE is used in Microsoft Azure infrastructure:
- Azure Linux with OS Guard — code integrity enforcement on AKS node images
- Azure Boost — locked-down host stack for offloaded hypervisor workloads