Confidential containers integrate trusted execution environments into Kubernetes to provide hardware-backed workload isolation using Kata Containers as the runtime and Trustee for remote attestation and secret provisioning. The solution enables a zero-trust execution model where pods operate within isolated VM boundaries and secrets are released only after cryptographic verification of runtime integrity on OpenShift bare metal.
An overview of confidential containers on OpenShift bare metal
calendar_today
June 4, 2026
person
Pradipta Banerjee, Leonardo Milleri, Emanuele Giuseppe Esposito, Pei Zhang
domain
red-hat