OPERATING SYSTEMSOS Linux

Confidential containers on AKS

#AI #Microsoft #copilot #dynamics #powerplatform #Azure #machinelearning

The session discusses confidential containers on Azure Kubernetes Service (AKS), emphasizing data protection in use against insider threats and third-party risks. Microsoft, a Confidential Computing Consortium founding member, follows consortium definitions. Key features include container-level sandboxing, a zero-trust model, transparency, and code integrity. Michael Withrow details AKS foundation, encryption of pod memory, and support for unmodified Linux containers. Trust boundaries segregate functional components from external entities, and a demo by Bryce Fisher showcases end-to-end encrypted Kafka messages within a confidential environment, utilizing security policies, managed identity, and attestation reports. The demonstration highlights the incapacity to decrypt messages outside the confidential environment, ensuring data security in practical application.

source

by tycoon talks

linux foundation