Skip to article frontmatterSkip to article content
Site not loading correctly?

This may be due to an incorrect BASE_URL configuration. See the MyST Documentation for reference.

Conclusion

CNCF Confidential Containers

What We Covered

This book walked through Confidential Computing from first principles to production deployment:

Why it exists — Traditional cloud security cannot protect data in use. The hypervisor, host OS, and infrastructure administrators all have unrestricted access to running workload memory. Confidential Computing moves the trust boundary down to the hardware itself, making those privileged layers irrelevant to workload security.

How it works — TEEs combine memory encryption with hardware-enforced access control and measured boot. Remote attestation closes the remaining gap: before trusting a TEE with secrets, a remote party can cryptographically verify that the correct software is running inside a genuine, unmodified hardware environment.

What to deploy — Three deployment tiers match different threat models:

The ecosystem — CNCF CoCo provides an open-source foundation that abstracts AMD SEV-SNP, Intel TDX, and IBM Secure Execution behind a common API. Trustee (KBS + AS + RVPS) handles remote attestation and secret delivery. The IETF RATS framework provides the conceptual vocabulary that ties vendors and projects together.


What This Technology Does Not Solve

Confidential Computing reduces the trust you must place in cloud infrastructure. It does not:


Where the Technology Is Heading

Confidential Computing is maturing rapidly. Key trends as of the time of writing:


Getting Started

If you have not yet run the labs, start with Lab 1 (CVM attestation on Azure) for a hardware-backed experience, or Lab 2 (CoCo without confidential hardware) if you want to experiment locally without specialized hardware.

For production deployments, the recommended path:

  1. Start with Pillar 2 (CoCo) on a cloud provider that supports SEV-SNP or TDX

  2. Use Trustee as your attestation and secret delivery service

  3. Validate your threat model against the three-pillar framework in this book


About the Author

Pradipta Banerjee is a Project Maintainer of the CNCF Confidential Containers project. The author’s work focuses on bringing Confidential Computing into cloud-native ecosystems and making it accessible to practitioners without hardware security backgrounds.


Acknowledgements

And many others in the community whose work and feedback shaped this material.