Confidential Containers
Confidential Containers is an open source CNCF Sandbox project that runs Kubernetes pods inside hardware-backed confidential virtual machines, providing remote attestation, encrypted images, and sealed secrets across Intel, AMD, IBM, ARM, and NVIDIA TEE platforms for regulated, AI, supply chain, and Web3 workloads.
- Company typePrivate
- Founded2022
- Headquarters—
- Headcount—
- GTM typeB2B
- OfferingSoftware
What Confidential Containers does
Confidential Containers is an open source CNCF Sandbox project that deploys Kubernetes pods inside hardware-backed confidential virtual machines (CVMs), combining the Kata Containers runtime with a guest-side attestation stack to isolate workloads from compromised hosts, hypervisors, and operators. The project was first released as v0.1.0 on 2022-09-29 and has maintained roughly a six-week release cadence, reaching v0.8.0 on 2023-11-10 with active development and documentation continuing through 2026. Its architecture has three primary layers: (1) Guest Components running inside the TEE — image-rs, ocicrypt-rs, confidential-data-hub, and attestation-agent — which pull and decrypt container images and handle secrets entirely outside the host's reach; (2) Trustee, the attestation and key-management engine composed of the Key Broker Service (KBS), Attestation Service (AS), and Reference Value Provider Service (RVPS), which validates TCB evidence and conditionally releases secrets; and (3) a Cloud API Adaptor ("peer pods") that lets Kubernetes provision confidential VMs on AWS EKS, AKS, GKE, Alibaba Cloud ACK, and IBM Cloud without requiring bare-metal hardware. Supported TEE platforms include Intel TDX, AMD SEV-SNP, IBM Secure Execution, Intel SGX, ARM CCA, Hygon CSV, and NVIDIA Hopper, RTX Pro 6000 BSE, and Blackwell GPUs.
The project targets four use-case clusters: confidential AI/ML (protecting model weights and training/inference data on shared cloud GPUs), regulated industries such as banking and healthcare (hardware-rooted compliance), secure software supply chains (verifiable build-to-runtime integrity, including SLSA-aligned patterns), and Web3 / blockchain infrastructure (notably oracle security via the Switchboard integration). Security primitives include encrypted OCI images whose symmetric keys are released only after successful remote attestation, signed images via cosign/skopeo, sealed Kubernetes secrets accessible only inside attested enclaves, Confidential EmptyDir using LUKS2 on host-provided block devices, and runtime attestation via an event log plus Init-Data cryptographically verified through Trustee.
Confidential Containers is not a commercial entity. It is distributed under the Apache License 2.0 at no cost, with no pricing model, no disclosed funding, no parent company, no management team in the source data, and no formal corporate domicile — the legal name is "Confidential Containers Contributors." Maintenance is performed by a multi-vendor community of contributors from IBM, Intel, AMD, NVIDIA, Microsoft, Google, and Alibaba Cloud, who use the framework to enhance their respective cloud offerings and hardware platforms. Distribution is entirely self-serve PLG: GitHub repositories under the confidential-containers organization, pre-built images on quay.io, ghcr.io, and nvcr.io, Helm charts, and the Operator Hub. Adoption is driven through documentation, technical blog posts, use-case demonstrations, and integration guides hosted on confidentialcontainers.org. The project's principal revenue-adjacent value accrues to its corporate maintainers via their own cloud and hardware offerings rather than to the project itself.
Confidential Containers firmographics
Firmographics- Name
- Confidential Containers
- Legal name
- Confidential Containers Contributors
- Website
- https://confidentialcontainers.org
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Short description
- Confidential Containers is an open source CNCF Sandbox project that runs Kubernetes pods inside hardware-backed confidential virtual machines, providing remote attestation, encrypted images, and sealed secrets across Intel, AMD, IBM, ARM, and NVIDIA TEE platforms for regulated, AI, supply chain, and Web3 workloads.
- Ownership category
- akta.pro rank
Confidential Containers industry classification
Industry- Product category
- Confidential Computing
- NAICS
- Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (518), Computer Systems Design and Related Services (54151)
- akta.pro primary industry
- Confidential Computing & Hardware-backed Protection (TEE/HSM) (HDADAFAJ)
- akta.pro secondary industries
- Kubernetes & Container Security (KSPM/KCSPM, Runtime) (HDADADAE), Cloud Security for Containers & Kubernetes (KSPM/Kubernetes Security) (HDABAHAO), Secrets Management & Machine Identity (API keys, certificates, workload identity) (HDAEAJAJ), Container Platforms & Orchestration (Kubernetes) (HDABADAF), Kubernetes & Container Platform Management (Private Cloud) (HDABABAC)
Keywords
Confidential Containers business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations
Revenue model
- Open Source Distribution: Confidential Containers is an open source CNCF Sandbox project. Revenue is not generated directly from the open source software; the project is maintained by collaborating companies (IBM, Intel, AMD, NVIDIA, Alibaba Cloud, Microsoft, Google) who use it to enhance their cloud offerings and hardware platforms.
Go-to-market motion1 record
Distribution channels4 records
Marketing channels5 records
Confidential Containers product offering
Product offeringCore offering
Confidential Containers is an open source CNCF Sandbox project that deploys cloud native Kubernetes pods inside hardware-backed confidential virtual machines using Kata Containers. The portfolio includes the Confidential Containers Runtime, Trustee (an attestation and key-management engine), Guest Components (image-rs, attestation-agent, confidential-data-hub), and the Cloud API Adaptor for cloud deployments. It supports Intel TDX, AMD SEV-SNP, IBM Secure Execution, and NVIDIA GPU confidential computing platforms, providing attestation, encrypted and signed container images, sealed secrets, and protected storage.
Product overview
Confidential Containers is an open source CNCF Sandbox project that provides a platform for deploying Cloud Native applications inside confidential virtual machines using hardware-backed isolation. The portfolio consists of the Confidential Containers Runtime (Kata Containers-based confidential VM encapsulation), Trustee (the attestation and key-management engine composed of KBS, AS, and RVPS), Guest Components (image-rs, attestation-agent, confidential-data-hub running inside the TEE), and the Cloud API Adaptor for cloud deployments. These components work together to protect containers while running using Intel TDX, AMD SEV-SNP, IBM Secure Execution, and NVIDIA GPU confidential computing technologies, providing attestation, encrypted/signed images, sealed secrets, and protected storage as key features.
Differentiator
Problem solved
Functional benefit
Quantifiable outcome
- Minimal container modification required for deployment
- +2 more outcomes
Companies that use Confidential Containers
Customer profileSegments4 records
Ideal customer profiles4 records
Confidential Containers technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration18 records
AI capability3 records
Feature10 records
Confidential Containers partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- CNCF (Cloud Native Computing Foundation)coreConfidential Containers is a CNCF Sandbox Project operating under the foundation's governance. The project leverages deep connections to other cloud native projects and benefits from CNCF's ecosystem, security review processes, and community resources.
Scale indicators2 records
Recent moves5 records
Expansion highlights6 records
Confidential Containers competitors and assessment
Company assessmentBroad incumbents
- AWS Nitro Enclaves: AWS's hardware-isolated compute environment for confidential workloads. Provides an alternative to CoCo for AWS-native deployments, though CoCo's CAA provider enables running the project on Nitro-based EC2 instances.
- Microsoft Azure Confidential Computing: Hyperscaler offering confidential VMs and confidential containers on Azure (including AMD SEV-SNP and Intel TDX). A major contributor to CoCo but also a competing integrated offering for customers seeking single-vendor support.
- Google Confidential VMs: Google Cloud's memory encryption offering for VMs (AMD SEV, SEV-SNP, Intel TDX). Overlaps with CoCo's target workload class on GKE, where CoCo provides a more granular pod-level isolation layer on top.
- IBM Hyper Protect: IBM's confidential computing portfolio including Hyper Protect Virtual Servers and IBM Secure Execution — which CoCo directly supports via Trustee attestation. Comparable at the enterprise confidential workload layer.
Direct peers
- Edgeless Systems: Open-core company building confidential computing tooling on Kubernetes including Constellation and Contrast — competes directly with CoCo for the same confidential cloud-native workload deployments.
- Anjuna Security: Commercial platform that similarly runs workloads inside hardware-isolated confidential VMs on Kubernetes and public clouds. Direct competitor in the confidential containers / enclaved Kubernetes category with overlapping target customers in regulated and AI use cases.
- Enarx: Open source project (originally Red Hat) providing hardware-isolated runtime for applications across TEEs (SEV, SGX). Targets a similar confidential compute abstraction layer but at application rather than Kubernetes pod granularity.
- SCONE (Scontain / Niobium): Confidential container platform providing shielded Kubernetes runtimes using SGX and SEV-SNP. Comparable to CoCo in target use cases (regulated workloads, AI, sealed secrets) and cloud-native delivery model.
- Kata Containers: Underlying VM-based container runtime that Confidential Containers extends with guest image pulling, attestation, and Trustee components. Directly comparable because CoCo is built on top of Kata and shares its pod-as-VM isolation model.
Others
- Open Confidential Computing Consortium: Industry consortium under the Linux Foundation defining open standards for confidential computing. Relevant ecosystem peer — Confidential Containers aligns with and benefits from the standards and marketing reach the consortium provides.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
Confidential Containers social profiles
Digital presenceConfidential Containers compliance and trust
Trust signalCompliance1 record
Confidential Containers financial estimates
Financial estimateRevenue estimate
Valuation estimate
Confidential Containers leadership team
Management profileNumber of profiles
Confidential Containers funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Confidential Containers M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Confidential Containers
What does Confidential Containers do?
Confidential Containers is an open source CNCF Sandbox project that deploys cloud native Kubernetes pods inside hardware-backed confidential virtual machines using Kata Containers. The portfolio includes the Confidential Containers Runtime, Trustee (an attestation and key-management engine), Guest Components (image-rs, attestation-agent, confidential-data-hub), and the Cloud API Adaptor for cloud deployments. It supports Intel TDX, AMD SEV-SNP, IBM Secure Execution, and NVIDIA GPU confidential computing platforms, providing attestation, encrypted and signed container images, sealed secrets, and protected storage.
Is Confidential Containers a public or private company?
Confidential Containers is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Confidential Containers founded?
Confidential Containers was founded in 2022.
How does Confidential Containers make money?
One revenue line is on record: open Source Distribution.
Who are Confidential Containers's main competitors?
Broad incumbents on record are AWS Nitro Enclaves, Microsoft Azure Confidential Computing, Google Confidential VMs and IBM Hyper Protect. Direct peers are Edgeless Systems, Anjuna Security, Enarx, SCONE (Scontain / Niobium) and Kata Containers. Open Confidential Computing Consortium is listed as an others.
Does Confidential Containers have an API?
Yes. Confidential Containers exposes a REST API to workloads inside the confidential guest. The API is available at http://127.0.0.1:8006/ and includes endpoints for: (1) /aa/evidence - retrieving attestation evidence, (2) /aa/token - obtaining attestation tokens from KBS, (3) /aa/aael - runtime attestation events log, (4) /cdh/resource - requesting secret resources from Trustee KBS. The API is configured via kernel parameters or Init-Data, with 'agent.guest_components_rest_api=all' enabling full API access. Trustee also provides admin APIs protected by admin keypairs for configuration. Developer documentation is at github.com/confidential-containers/trustee/blob/main/kbs/docs/kbs_attestation_protocol.md.
What industry is Confidential Containers in?
Confidential Containers's product category is Confidential Computing. Its primary akta.pro industry code is HDADAFAJ, Confidential Computing & Hardware-backed Protection (TEE/HSM), with a secondary code of HDADADAE, Kubernetes & Container Security (KSPM/KCSPM, Runtime). Its NAICS code is 518.