이 콘텐츠는 선택한 언어로 제공되지 않습니다.

Chapter 2. New features and enhancements


This section describes new features and enhancements introduced in OpenShift sandboxed containers 1.12.

Confidential containers on bare metal

In this update, OpenShift sandboxed containers on bare-metal servers now support encrypted persistent volumes, providing a secure, durable storage solution for sensitive workloads. This enhancement addresses the demand for data persistence within sandboxed environments while ensuring that data remains encrypted at rest.

Key enhancements in this release include:

  • Encrypted block volumes: You can now encrypt, decrypt and mount block volumes directly within the confidential container using raw block volumes. This ensures that encryption and decryption happen inside the Trusted Execution Environment (TEE) rather than at the worker node level, maintaining data confidentiality throughout the storage lifecycle.
  • Red Hat build of Trustee 1.1.0 is now generally available and is the recommended version for use with OpenShift sandboxed containers 1.12.
  • Simplified Trustee configuration: Deployment of Red Hat build of Trustee is significantly simplified through the new TrusteeConfig custom resource. Key features include:

    • Automated resource generation: Automatically generates required secrets, config maps, and the KbsConfig resource.
    • Profile-based configuration: Offers a Permissive profile for quick-start development and a Restricted profile for production-grade security.
    • Service exposure options: Support for ClusterIP, NodePort, and LoadBalancer by using the kbsServiceType field.
    • Platform-specific extensions: Native support for IBM Secure Execution, Intel TDX, and disconnected (air-gapped) environments.
  • Pre-built initramfs: Initial RAM File System (initramfs) images are now pre-built and provide known Measurement Hashes. Hardware evaluates initramfs contents before booting the confidential virtual machine, making initramfs a critical link in the chain of trust. Pre-built images eliminate the need for runtime builds that could be compromised.

    These improvements aim at simplifying the deployment and management of storage and security resources so that end users can manage their confidential container workloads on bare metal more effectively.

Jira:KATA-4394

Red Hat logoGithubredditYoutubeTwitter

자세한 정보

평가판, 구매 및 판매

커뮤니티

Red Hat 소개

Red Hat은 기업이 핵심 데이터 센터에서 네트워크 에지에 이르기까지 플랫폼과 환경 전반에서 더 쉽게 작업할 수 있도록 강화된 솔루션을 제공합니다.

보다 포괄적 수용을 위한 오픈 소스 용어 교체

Red Hat은 코드, 문서, 웹 속성에서 문제가 있는 언어를 교체하기 위해 최선을 다하고 있습니다. 자세한 내용은 다음을 참조하세요.Red Hat 블로그.

Red Hat 문서 정보

Legal Notice

Theme

© 2026 Red Hat
맨 위로 이동