Cloud Native
Security Talks
RSS

KubeCon Europe 2025

Trust No One: Secure Storage With Confidential Containers

Aurélien Bombo, Microsoft

Abstract

If you are processing and storing sensitive data in the cloud, can you really trust anyone (including the cloud)? The answer is no. Confidential Containers (CoCo) is a CNCF project that leverages Trusted Execution Environments (TEEs) to tackle this challenge. A critical aspect in this effort is providing secure and confidential storage solutions that can be seamlessly deployed across cloud providers. This session explores the implementation of trusted storage in CoCo, highlighting key aspects such as Kubernetes storage drivers, device virtualization, and the role of attestation in secure key release and data encryption. We also demonstrate how we prevent attackers from injecting data into the TEE using the CNCF Rego policy language. Overall, we aim to show how cloud providers and end users can securely store and protect sensitive data, enabling the adoption of confidential computing across numerous use cases.

More from KubeCon Europe 2025

Open in the index →
  1. Signed, Sealed, Delivered - Sign and Verify All the ThingsJeremy Rickard, Microsoft 2025-04-02
  2. Securing AI Workloads: Building Zero-Trust Architecture for LLM ApplicationsRohit Ghumare, Taikun & Joinal Ahmed, NTG 2025-04-02
  3. Weaving a VEX Feed Through the Kubernetes ProjectAdolfo García Veytia, Stacklok 2025-04-03
  4. Redefining Access Control: Scaling Policy as Code for Humans and AI AgentsRaz Cohen, Permit.io 2025-04-03
  5. Open Source Malware or a Vulnerability? The Philosophical Debate and How To MitigateBrian Fox, Sonatype; Madelein van der Hout, Forrester Research Inc.; Santiago Torres-Arias, Purdue University 2025-04-03
  6. Mind the Gap: Bridging Supply Chain Policy With Git-less GitOps and GUACMichael Lieberman, Kusari & Andrew Martin, ControlPlane 2025-04-03
  7. Identity-based Trust - Till Death Do We Part?John Kjell, ControlPlane & Kairo De Araujo, Independent 2025-04-03
  8. IAM, Agent: Identity for Autonomous AIMatthew Bates, Cofide 2025-04-03
  9. ​​SPIFFE in Practice: Universal Identity for WebAssembly WorkloadsJoonas Bergius, Cosmonic & Colin Murphy, Adobe 2025-04-03
  10. Zero Trust at Shopify Scale: Automating MTLS Across Thousands of ServicesDani Santos & Michelle Mali, Shopify 2025-04-04
  11. Why Don’t We Have Both? Track Build- and Run-time Information for Security With Kubescape and GUACJeff Mendoza, Kusari & Ben Hirschberg, ARMO 2025-04-04
  12. From Chaos To Control: Migrating Access Control To OpenFGA in a Multi-Tenant WorldJo Guerreiro, Grafana Labs & Poovamraj Thanganadar Thiagarajan, Okta 2025-04-04
  13. Fresh Secrets From the Docks: Lessons Learnt From Analyzing 180,000 Public DockerHub ImagesGuillaume Valadon, GitGuardian 2025-04-04
  14. Enhancing Software Composition Analysis Resilience Against Container Image ObfuscationAgathe Blaise, Thales & Jacopo Bufalino, CNAM 2025-04-04
  15. EVAPorating Kubernetes Security Risk: Adopting Validating Admission Policy at ScaleKaitlyn Lee & Jordan Conard, Datadog 2025-04-04
  16. Do Your Containers Even Lift – A Hardening Guide for K8s ContainersCailyn Edwards & Daniel Murphy, Okta 2025-04-04
  17. Container Runtimes... on Lockdown: The Hidden Costs of Multi-tenant WorkloadsLewis Denham-Parry, Edera & Caleb Woodbine, ii.nz 2025-04-04
  18. Compliance at the Speed of Innovation: Leveraging AI-Driven Automation for Real-Time Regulatory ReadLarry Carvalho, RobustCloud LLC; Simon Metson, EnterpriseDB; Robert Ficcaglia, Sunstone Secure, LLC; Anca Sailer, Red Hat / IBM; Yuji Watanabe, IBM Japa 2025-04-04