qemu-system-x86_64 -enable-kvm -nographic -nodefaults -machine q35,vmport=off,confidential-guest-support=sev0,memory-backend=ram0 -cpu EPYC-v4 -smp 4 -object memory-backend-memfd,id=ram0,size=8G,share=true,prealloc=false -m 8G -object sev-snp-guest,id=sev0,cbitpos=47,reduced-phys-bits=1,kernel-hashes=on,policy=0x30000 -bios /usr/share/ovmf/OVMF.amdsev.fd -kernel ./vmlinuz -initrd ./initrd.img -append "root=/dev/vda2 console=ttyS0 earlyprintk=serial ro" -drive if=none,id=os,file=guest-luks.qcow2,format=qcow2,cache=none,aio=native,discard=unmap -device virtio-blk-pci,drive=os,disable-legacy=on,iommu_platform=true -netdev user,id=net0,hostfwd=tcp:127.0.0.1:2222-:22 -device virtio-net-pci,netdev=net0,disable-legacy=on,iommu_platform=true -serial mon:stdio -monitor none -display none