These hands-on confidential computing labs show how to deploy and attest confidential virtual machines and CNCF Confidential Containers. You will use Azure, Kubernetes, Trustee, cococtl, and peer pods in practical exercises that can be completed in order or independently.
| Lab | What you’ll do | Hardware needed |
|---|---|---|
| Lab 1: CVM Attestation on Azure | Provision two Azure VMs (Trustee + SEV-SNP CVM), run hardware attestation end-to-end, retrieve a secret | Azure account |
| Lab 2: CoCo Without Confidential Hardware | Deploy CoCo on a standard Kubernetes cluster using the sample verifier | Any Linux VM |
| Lab 3: CoCo-fy a Workload with cococtl | Transform an existing Kubernetes app into a confidential workload with one command | Any Linux VM |
| Lab 4: CoCo on a Real CVM via Peer-Pods (BYOM) | Run a CoCo pod on a real Azure SEV-SNP CVM using cloud-api-adaptor’s BYOM provider | Azure account |
Component Versions¶
All labs in this chapter use the following pinned versions:
| Component | Version |
|---|---|
| Ubuntu (VMs and CVMs) | 26.04 LTS |
| Kubernetes | 1.36.1 |
| CoCo helm chart (Labs 2 & 3) | 0.21.0 |
| Peerpods helm chart (Lab 4) | 0.3.0 (CAA v0.21.0) |
| Kata Containers | 3.31.0 |
| Trustee | v0.20.0 |
| guest-components | v0.20.0 |