Blog

Posts in 2026
  • PQC Support in KBS Protocol

    Wednesday, September 23, 2026 in Blog

    IntroductionThose who are interested in Confidential Containers as a framework, already have a high bar for security. The delivery of resources from the trusted Trustee services into untrusted guest components requires resources to be secured in …

    Read more

  • Deploy Trustee in Kubernetes

    Wednesday, August 19, 2026 in Blog

    IntroductionIn this blog, we’ll be going through the deployment of Trustee, the Key Broker Service that provides keys/secrets to clients that want to execute workloads confidentially. Trustee provides a built-in attestation service that complies to …

    Read more

  • Encrypted Persistent Storage for Peer Pods with the CAA CSI Block Driver

    Friday, August 14, 2026 in Blog

    IntroductionWhen you use the Kata remote hypervisor (peer-pods) for confidential containers, you can run into problems if your workload relies on Kubernetes CSI storage for persistent data. Until v0.21.0 we had csi-wrapper. It sat in front of …

    Read more

  • BYOM Provider: Bring Your Own CVMs to run Confidential Containers

    Monday, May 25, 2026 in Blog

    IntroductionThe BYOM (Bring Your Own Machine) provider is a unique Cloud API Adaptor (CAA) provider that enables you to use pre-created CVMs as peer pods. Unlike other CAA providers (AWS, Azure, GCP, etc.) that dynamically provision CVMs, BYOM …

    Read more

  • Extending Trustee Key Broker Service with Remote Plugins

    Tuesday, April 28, 2026 in Blog

    Confidential Computing provides hardware-backed isolation and remote attestation, ensuring workloads execute inside trusted execution environments (TEEs) with verifiable integrity. Building on this, Confidential Containers extends these guarantees to …

    Read more

  • Integrate Trustee with the External Secrets Operator

    Tuesday, March 31, 2026 in Blog

    IntroductionThe Trustee operator simplifies configuring secrets and serving them to confidential container pods that execute inside trusted execution environments (TEEs). You can set up the required secrets as Kubernetes Secret objects and make them …

    Read more

Posts in 2025
Posts in 2024
  • Confidential Containers without confidential hardware

    Tuesday, December 03, 2024 in Blog

    Note This blog post was originally published here based on the very first versions of Confidential Containers (CoCo) which at that time was just a Proof-of-Concept (PoC) project. Since then the project evolved a lot: we managed to merge the work to …

    Read more

  • Policing a Sandbox

    Thursday, August 15, 2024 in Blog

    In a previous article we discussed how we can establish confidence in the integrity of an OS image for a confidential Guest, that is supposed to host a collocated set (Pod) of confidential containers. The topic of this article will cover the …

    Read more