8–9 Aug 2026
NTUST
Asia/Taipei timezone

Zero-Trust Workloads with Confidential Containers on Ubuntu

9 Aug 2026, 10:30
30m
TR211 (NTUST)

TR211

NTUST

No. 43, Sec. 4, Keelung Rd., Da'an Dist., Taipei City 106335, Taiwan
Talk Security and Compliance

Speaker

Vutukuri Sreenivas
Jenkins

Description

In terms of protecting sensitive data during execution across diverse cloud environments, typical container isolation mechanisms frequently fall short. While traditional security secures data at rest and in transit, the "data-in-use" gap remains leaving memory and running processes vulnerable to a compromised host, hypervisor, or rogue administrator. Without requiring changes to application code, Confidential Containers (CoCo) is a potent open-source technology that makes it possible to isolate workloads safely and effectively using hardware-based Trusted Execution Environments (TEEs). This session examines how memory encryption, remote attestation, and hardware-level isolation offered by CoCo might improve zero-trust security on Ubuntu systems. Measures like standard Linux namespaces and cgroups are less efficient against contemporary infrastructure-level attacks as a result of the sophistication of modern cloud-native threats. By offering a cryptographic method of isolating system memory without compromising cloud flexibility, CoCo tackles these issues. And CoCo is a crucial tool for contemporary data privacy and compliance since it can protect proprietary code, AI models, and sensitive payloads by executing them inside hardware-attested utility VMs on the Linux kernel.

The talk will focus on the integration of Confidential Containers with Ubuntu, highlighting Canonical’s and the broader open-source community's ecosystem support for TEE-backed virtualization such as Intel TDX and AMD SEV-SNP. Will also include practical demonstrations of CoCo deployments on Ubuntu, showcasing how to use the open-source CoCo Operator for running encrypted pods, managing remote attestation, and preventing unauthorized host-level access to container memory. We will walk through real-world examples of deploying hardware-isolated workloads using CNCF tools such as Kata Containers and the Confidential Containers project alongside Ubuntu's MicroK8s, demonstrating how they enforce a true zero-trust architecture in modern cloud infrastructures.

Participants will have a thorough grasp of how to use Confidential Containers to improve data-in-use security in Ubuntu environments by the end of this session. They will acquire hands-on experience in deploying CoCo for memory encryption, hardware-based workload isolation, and cryptographic attestation, allowing them to leverage this potent technology in their own infrastructure strategies and actively champion advanced cloud security within the Ubuntu ecosystem.

Summary

We encrypt data at rest and in transit, but the "data-in-use" gap still leaves running container memory exposed to compromised hosts and rogue cloud admins. Confidential Containers (CoCo) eliminates this blind spot by leveraging hardware-based Trusted Execution Environments (TEEs) to run unmodified

What audience can learn

Participants will have a better understanding of how Confidential Containers (CoCo) improves data-in-use security in Ubuntu systems at the end of this session. From kernel optimizations for Trusted Execution Environments (TEEs) to integrated cloud-native tooling, they will discover how Ubuntu's environment facilitates CoCo and how it allows for hardware-level memory encryption without requiring changes to application code. Using Ubuntu-native tools and configurations, the session will explore real-world use cases such as isolating sensitive AI models, protecting proprietary code from rogue administrators, and enforcing a zero-trust architecture. Attendees will get practical knowledge about implementing hardware-backed security solutions through practical demonstrations using MicroK8s, Kata Containers, and the CoCo Operator on Ubuntu. In order to guarantee a seamless and safe integration of Confidential Containers into Ubuntu systems, we will lastly go over best practices, performance concerns, and typical hazards.

Biography

V Sreenivas is a DevRel, specializing in cybersecurity, Linux security, and cloud-native security. With a strong background in security engineering and open-source contributions, he has worked extensively on security observability and enforcement mechanisms. Passionate about sharing knowledge, he has spoken at various security conferences and actively contributes to the security community. https://www.linkedin.com/in/v-sreenivas-985088203/

Difficulty level Advanced
Language English

Presentation materials