Cloud Native
Security Talks
RSS

KubeCon North America 2025

Hybrid-Confidential-Cloud: Democratize Secure AI With GPUs and Confidential Containers

Zvonko Kaiser, NVIDIA

Abstract

Secure AI workloads require verifiable trust regardless of where GPUs operate—on-premises, private clouds, or public CSPs. CNCF Confidential Containers facilitate infrastructure-agnostic, lift-and-shift deployments of GPU workloads, delivering confidentiality seamlessly without needing modifications. This is accomplished by layering trust-oriented elements over Kubernetes for compute, networking, storage, and the control plane. Hardware-backed confidential VMs ensure runtime integrity for GPU workloads, identity-based overlay networks, and a confidential storage layer safeguards highly valuable data against replay attacks. A confidential control plane overlays K8S default control plane, offering mechanisms for multi-tenancy, key lifecycle management, and maintenance of trust boundaries. This architecture supports trusted, portable AI infrastructure at scale, enabling secure AI deployments across any IaaS—on-premises, private cloud, or CSP—facilitating true hybrid secure AI at scale.

More from KubeCon North America 2025

Open in the index →
  1. The Good, the Bad, and the Ugly: Hacking 3 Cloud Native AI Services With 1 VulnerabilityHillai Ben-Sasson & Nir Ohfeld, Wiz 2025-11-11
  2. Modern PostgreSQL Authorization With Keycloak: Cloud Native Identity Meets Database SecurityYoshiyuki Tabata, Hitachi, Ltd. & Gabriele Bartolini, EDB 2025-11-11
  3. It’s 2025; Why Are You OK With an Insecure Network? 🤯Alex Leong, Buoyant 2025-11-11
  4. In AI We Trust? Securing the Future, One Agent at a TimeLin Sun & Yuval Kohavi, Solo.io; Hannah Foxwell, Mindgard.ai; Andrew Martin, ControlPlane; Ricardo Aravena, CNCF 2025-11-11
  5. From Bespoke To Bulletproof: SPIFFE/SPIRE With ESO for Enterprise Zero TrustMay Large & Ivy Alkhaz, State Farm 2025-11-11
  6. End-to-End Security With gRPC in KubernetesShiva & Abhishek Agrawal, Google 2025-11-11
  7. Demonstration of Automatic Kubernetes Network Policies GenerationBoaz Michaely, Red Hat & Adi Sosnovich, IBM Research 2025-11-11
  8. Security Theater or Real Defense? Navigating Open Source Security in a Cloud Native WorldRotem Refael, ARMO; Constanze Roedig, Technical University of Vienna; Megan Wolf, Defense Unicorns; Stefana Muller, Salesforce; Oshrat Nir, Independent 2025-11-12
  9. Securing AI Agent Infrastructure: AuthN/AuthZ Patterns for MCP and A2AYoshiyuki Tabata, Hitachi, Ltd. 2025-11-12
  10. Safely Sourcing OSS - Beyond 0 CVEsJohn Kjell, ControlPlane 2025-11-12
  11. Red Vs. Blue: A Live Attacker-Defender Showdown in Kubernetes SecurityLucy Sweet, Uber & Sandeep Kanabar, Gen 2025-11-12
  12. Quantum-Resistant Kubernetes: Realities, Risks & (Versioning) PitfallsFabian Kammel, ControlPlane 2025-11-12
  13. Patch Me If You Can: Tackling Outdated Addons Before They Become a RiskStevie Caldwell & Andy Suderman, Fairwinds 2025-11-12
  14. You Deployed What?! Data-Driven Lessons on Unsafe Helm Chart DefaultsYossi Weizman, Microsoft 2025-11-13
  15. Tools and Strategies for Making the Most of Kubernetes Access ControlLucas Käldström, Upbound & Micah Hausler, AWS 2025-11-13
  16. The Ultimate Container Challenge: An Interactive Trivia Game on Supply Chain SecurityAurélie Vache, OVHcloud & Sherine Khoury, Red Hat 2025-11-13
  17. Securing Data Applications at Pinterest With Finer Grained Access Control on KubernetesSoam Acharya & William Tom, Pinterest 2025-11-13
  18. Authenticating and Authorizing Every Connection at UberYangmin Zhu & Matt Mathew, Uber 2025-11-13
  19. Aligning Enterprise AI Security With MITRE ATLAS Using Open Source TechnologiesDoron Caspin & Valentina Rodriguez Sosa, Red Hat 2025-11-13
  20. 🎤 Who Wants To Secure Clusters ?Henrik Rexed & Simon Reisinger, Dynatrace 2025-11-13