Chapter 4. Technology Previews
This section provides a list of all Technology Previews available in OpenShift sandboxed containers 1.11.
See Technology Preview Features Support Scope for more information.
Confidential containers on bare-metal servers
This release supports confidential containers on bare-metal servers for the Intel TDX and AMD SEV-SNP Trusted Execution Environments (TEEs). Confidential container pods run in hardware-isolated TEEs with memory encryption, verified through remote attestation using the Red Hat build of Trustee. Support is also provided for sealed secrets provisioning inside the CVM after successful attestation.
Confidential containers on IBM Z and IBM LinuxONE bare-metal servers
This release supports confidential containers on IBM Z® and IBM® LinuxONE bare-metal servers for the IBM Secure Execution TEE.
Deploying Red Hat build of Trustee on bare metal
The current release supports deploying Red Hat build of Trustee on bare-metal servers.
Deploying Red Hat build of Trustee on bare metal in disconnected environment
The current release supports deploying Red Hat build of Trustee on bare-metal servers in a disconnected network environment. This feature is a security enhancement, enabling you to run confidential containers workloads without connecting to the internet.
Intel TDX remote attestation on bare-metal servers
The current release supports the remote attestation infrastructure used by Intel TDX (Trusted Domain Extensions) on bare-metal servers. The infrastructure includes the following components:
- Data Center Attestation Primitives (DCAP): Software framework that provides the core libraries for the attestation process.
- Quote Generation Service (QGS): Service responsible for generating and signing the cryptographic proof.
- Provisioning Certification Caching Service (PCCS): Service responsible for local caching of cryptographic credentials.
OpenShift sandboxed containers and confidential containers on IBM Z and IBM LinuxONE with peer pods
This release supports OpenShift sandboxed containers and confidential containers workloads on IBM Z® and IBM® LinuxONE (s390x architecture) by using peer pods.
Jira:KATA-2030