YoVDO

Trust No One - Bringing Confidential Computing to Containers

Offered By: CNCF [Cloud Native Computing Foundation] via YouTube

Tags

Conference Talks Courses Containers Courses Confidential Computing Courses Kata Containers Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore confidential computing for containers in this 27-minute conference talk from KubeCon + CloudNativeCon North America 2021. Delve into the challenges of protecting container data and code in multi-tenant cloud environments. Learn about Trusted Execution Environments (TEEs) and their role in safeguarding cloud assets at rest, in transit, and during use. Discover how emerging hardware technologies enable tenants to maintain exclusive trust. Examine cloud native gaps in supporting confidential computing, including memory encryption, authenticated launch, and application attestability. Understand how secure container runtimes like Kata can address these challenges. Gain insights into a proposed software architecture for implementing confidential computing in cloud native workloads. Cover topics such as the existing trust computing base, data protection methods, software stack verification, hardware and software dependencies, and potential blockers. Explore solutions like KATA Containers and service offload, and understand their implications for users. Conclude with a summary of the current gaps and future directions in confidential computing for containers.

Syllabus

Introduction
Existing Trust Computing Base
What is Trust No One
How do we get there
Protecting data
Verifying software stack
Hardware dependencies
Software dependencies
Blockers
Solutions
KATA Containers
Service Offload
Walkthrough
What does this mean for the user
Gaps
Summary


Taught by

CNCF [Cloud Native Computing Foundation]

Related Courses

Secure and Fast MicroVM for Serverless Computing
GOTO Conferences via YouTube
KVM Status Update and Kata Containers - Keynote Sessions
Linux Foundation via YouTube
Introducing SPDK Vhost FUSE Target for Accelerated File Access in VMs and Containers
Linux Foundation via YouTube
From Secure Container to Secure Service
Linux Foundation via YouTube
Build Serverless with Kubernetes, Kata Containers and Bare Metal Cloud - Alibaba's Approach
Linux Foundation via YouTube