Skip to article frontmatterSkip to article content
Site not loading correctly?

This may be due to an incorrect BASE_URL configuration. See the MyST Documentation for reference.

Confidential Computing Use Cases

CNCF Confidential Containers

Confidential computing is most useful when sensitive data or code must be processed on infrastructure that the workload owner does not fully trust. Common use cases include confidential AI, privacy-preserving data collaboration, secure cloud migration, regulated workloads, and protected blockchain or Web3 services.

1. Secure AI Inference

Problem:

Relevant patterns:

Secure Inference Use Case

2. Secure Chatbot / LLM Serving

This is subtly different from secure inference — here the model is known/public, but user inputs are sensitive. The TEE protects user queries, conversation history, and fine-tuned model variants.

Secure Chatbot Use Case

3. Secure AI Training

Problem:

Secure Training Use Case

4. Secure Multi-Party Analytics

Problem:

Relevant patterns:

Secure Multi-Party Analytics Use Case

5. Secure CI/CD Pipelines

Problem:

6. Segregating Admin Roles

Problem:

This enables a clean separation that was previously impossible:

Admin RoleControlsCan See Workload Secrets?
Infrastructure AdminHosts, hypervisors, physical machines, networks✗ No
Cluster AdminK8s control plane, nodes, networking, RBAC, namespaces✗ No
Workload AdminSpecific workloads and their secrets✔ Yes

Use Case Summary

Use CaseThreat Being MitigatedKey Benefit
Secure InferenceCloud provider steals modelIP protection
Secure ChatbotProvider reads user queriesUser privacy
Secure TrainingData center steals training dataData sovereignty
Multi-party AnalyticsPeers see raw dataCollaboration without exposure
CI/CD ProtectionCompromised runner steals keysSupply chain security
Admin Role SegregationMalicious admin reads secretsZero-trust operations