Improving Bootup Performance of Containers with Overlay Images in TEE Environments
Offered By: Linux Foundation via YouTube
Course Description
Overview
Explore techniques for enhancing container bootup performance in Trusted Execution Environments (TEEs) with overlay images. Delve into the challenges faced by cloud service providers when deploying containers with hardware-based TEE techniques like Intel's SGX/TDX and AMD's SEV. Learn about the "Confidential Containers" sandbox project and its impact on security and performance. Discover innovative solutions to address performance drops, including accelerating image downloads with overlayed formats, reducing key negotiation overhead with Key Management Systems (KMS), and leveraging acceleration techniques to offload image decryption from the CPU. Gain insights into balancing security requirements with acceptable performance for container tenants in public cloud environments.
Syllabus
Introduction
Agenda
Background Motivation
Background of Container
Optimization
Contributions
Raster
Conclusion
Taught by
Linux Foundation
Tags
Related Courses
Unifying Confidential Attestation - Strategies and ApproachesLinux Foundation via YouTube Protected KVM on Arm64: A Technical Deep Dive
Linux Foundation via YouTube No More Turtles: The SecondaryVM Framework - An Alternative to Nested Virtualization
Linux Foundation via YouTube The Five Big Problems with Confidential Containers
Linux Foundation via YouTube Live Migration Architecture for Intel TDX-based Confidential VMs
Linux Foundation via YouTube