Este contenido no está disponible en el idioma seleccionado.
Chapter 4. Technology Previews
This section provides a list of all Technology Previews available in OpenShift sandboxed containers 1.12.
See Technology Preview Features Support Scope for more information.
- Confidential containers with GPU
You can deploy confidential containers along with graphics processing unit (GPU) hardware on bare-metal clusters by utilizing NVIDIA H100 GPUs and NVIDIA confidential computing functionalities. This feature extends hardware-based Trusted Execution Environment (TEE) protections to GPU-accelerated workloads by safeguarding sensitive data and models during GPU computation. It offers GPU memory encryption, attestation, and isolation for sensitive compute workloads.
These functionalities reduce the risk of data breaches and ensure compliance with data protection regulations during GPU-accelerated inference and training workloads. This feature is available as a Technology Preview and tested for NVIDIA H100 GPUs with Confidential Computing capabilities on bare-metal OpenShift Container Platform clusters.
- Deploying Red Hat build of Trustee on bare metal
The current release supports deploying Red Hat build of Trustee on bare-metal servers.
Deploying Red Hat build of Trustee on bare metal in disconnected environment
The current release supports deploying Red Hat build of Trustee on bare-metal servers in a disconnected network environment. This feature is a security enhancement, enabling you to run confidential containers workloads without connecting to the internet.
- Intel® TDX remote attestation on bare-metal servers
The current release supports the remote attestation infrastructure used by Intel® Trust Domain Extensions (TDX) on bare-metal servers. The infrastructure includes the following components:
- Data Center Attestation Primitives (DCAP): Software framework that provides the core libraries for the attestation process.
- Quote Generation Service (QGS): Service responsible for generating and signing the cryptographic proof.
- Provisioning Certification Caching Service (PCCS): Service responsible for local caching of cryptographic credentials.
- OpenShift sandboxed containers and confidential containers on IBM Z and IBM LinuxONE with peer pods
This release supports OpenShift sandboxed containers and confidential containers workloads on IBM Z® and IBM® LinuxONE (s390x architecture) by using peer pods.
Jira:KATA-2030