Skip to article frontmatterSkip to article content
Site not loading correctly?

This may be due to an incorrect BASE_URL configuration. See the MyST Documentation for reference.

Three Pillars of Confidential Computing

CNCF Confidential Containers

Confidential Computing in cloud-native environments is organized into three deployment tiers, each building on the previous one.

The three pillars:

  1. Confidential Virtual Machine — run a VM inside a TEE (the foundation)

  2. Confidential Container — run a Kubernetes Pod inside a CVM

  3. Confidential Cluster — run Kubernetes nodes themselves inside CVMs


Pillar 1: Confidential Virtual Machine (CVM)

A Confidential Virtual Machine is a VM that runs inside a TEE. It is the foundational building block.

What it provides:


Pillar 2: Confidential Container (Pod)

A Confidential Container runs a Kubernetes Pod inside a CVM (which itself runs inside a TEE).

Key properties:

Confidential Containers — run a Kubernetes Pod inside a CVM

Implementation: The CNCF Confidential Containers (CoCo) project is the primary open-source implementation.


Pillar 3: Confidential Cluster

A Confidential Cluster runs Kubernetes nodes themselves inside CVMs (which run inside TEEs).

Confidential Cluster — Kubernetes nodes run inside CVMs

Comparing the Pillars

Confidential VMConfidential ContainersConfidential Cluster
What’s in the TEEThe entire VMThe entire VM including the podEntire K8s nodes
K8s control planeN/AUntrusted (on regular infra)Trusted (inside CVMs)
Trust boundaryVM levelVM levelCluster level
Admin TrustInfra admin is untrustedInfra and cluster admin are untrustedInfra admin is untrusted
Multi-tenancyN/ASince cluster admin is untrusted, each pod can belong to different tenantSince cluster admin is trusted, it can’t be used for multi-tenancy
Operation TypeStandalone — no K8s requiredDay 2 Operation — can be deployed on existing K8s clusterDay 1 Operation — requires new K8s cluster
Use caseProtect standalone workloadsWorkload isolation within K8sFull cluster isolation

Choosing the Right Pillar

RequirementRecommended Pillar
Protect standalone codePillar 1: CVM
Protect K8s pods from each other and cluster/infra adminPillar 2: Confidential Containers
Protect entire K8s cluster from infra adminPillar 3: Confidential Cluster