Red Hat Openshift sandboxed containers provides the capability to run Confidential Containers (CoCo). Confidential Containers are containers deployed within an isolated hardware enclave protecting data and code from privileged users such as cloud or cluster administrators. The CNCF Confidential Containers project is the foundation for the OpenShift CoCo solution. Note that CoCo is an additional feature provided by OpenShift sandboxed containers, and consequently, it’s available through the OpenShift sandboxed containers operator.
In this workshop, we are also showing another operator, the confidential compute attestation operator (also known as Trustee), which can verify the trustworthiness of TEEs remotely. For more information, please refer to this blogpost.
We will show how to set up the Trustee and OSC operator and run a simple hello-openshift Confidential Container running with the kata-remote runtime class (peer pods solution). This effectively means that the hello-openshift container runs in a separate, confidential, independent virtual machine, and not in the worker node. In another example, we will also show how attestation and secure key retrieval workflow happens between a CoCo pod and Trustee.
The goal of this workshop is to provide the user not only an environment and documentation to test CoCo, but also provide additional explanations on the design choices behind some options and the benefit they bring to the overall user experience. CoCo is designed to bring confidential computing at kubernetes level, making it as simple as possible while preserving all security benefits that confidential computing brings.