Skip to article frontmatterSkip to article content
Site not loading correctly?

This may be due to an incorrect BASE_URL configuration. See the MyST Documentation for reference.

Confidential Computing Hands-On Labs

CNCF Confidential Containers

These hands-on confidential computing labs show how to deploy and attest confidential virtual machines and CNCF Confidential Containers. You will use Azure, Kubernetes, Trustee, cococtl, and peer pods in practical exercises that can be completed in order or independently.

LabWhat you’ll doHardware needed
Lab 1: CVM Attestation on AzureProvision two Azure VMs (Trustee + SEV-SNP CVM), run hardware attestation end-to-end, retrieve a secretAzure account
Lab 2: CoCo Without Confidential HardwareDeploy CoCo on a standard Kubernetes cluster using the sample verifierAny Linux VM
Lab 3: CoCo-fy a Workload with cococtlTransform an existing Kubernetes app into a confidential workload with one commandAny Linux VM
Lab 4: CoCo on a Real CVM via Peer-Pods (BYOM)Run a CoCo pod on a real Azure SEV-SNP CVM using cloud-api-adaptor’s BYOM providerAzure account

Component Versions

All labs in this chapter use the following pinned versions:

ComponentVersion
Ubuntu (VMs and CVMs)26.04 LTS
Kubernetes1.36.1
CoCo helm chart (Labs 2 & 3)0.21.0
Peerpods helm chart (Lab 4)0.3.0 (CAA v0.21.0)
Kata Containers3.31.0
Trusteev0.20.0
guest-componentsv0.20.0