Edgeless Systems Releases Confidential Kubernetes Distribution

By

Constellation is a secure Kubernetes implementation that leverages confidential computing.

Confidential computing is a relatively new security paradigm that addresses the problem of running sensitive workloads on someone else’s infrastructure, says Felix Schuster. Fundamentally, he explains, “confidential computing is about two things: (1) keeping workloads encrypted and isolated during processing and (2) making this circumstance externally verifiable via cryptographic certificates.”

Now, Edgeless Systems has released Constellation, a secure implementation of Kubernetes (K8s) that leverages confidential computing. The open source Constellation distribution is “a CNCF-certified K8s and, from a usability perspective, should work like “normal” K8s distributions. Constellation adds features like Sigstore-based supply chain security to the core Confidential K8s concept,” Schuster says.

According to the website, Constellation runs on Microsoft Azure, Google Cloud Platform, and Amazon Web Services.

Learn more at The New Stack.

10/07/2022

Related content

  • Strengths and Weaknesses of Docker Swarm and Kubernetes
    Docker Swarm and Kubernetes both orchestrate container clusters, manage workloads, improve reliability, and automate the operation of distributed applications, but they are based on different architectures. We compare the two platforms, highlighting their benefits and downsides.
  • Production-ready mini-Kubernetes installations
    Kubernetes can be highly complex, with massive setup routines that are totally over the top for newcomers. If you want to try out Kubernetes or run it in production, you have a number of options, even if you decide not to use the comprehensive packages from established vendors.
  • Encrypt and decrypt files with Age or Rage
    Age and Rage are the Go and Rust implementations of a simple, modern, and secure file encryption tool.
  • Transfer and Destroy Secrets
    An ephemeral communication approach promises a solution to the persistent lifecycle of sensitive data by resorting to messages that self-destruct after being read.
  • Safeguard and scale containers
    Security, deployment, and updates for thousands of nodes prove challenging in practice, but with CoreOS and Kubernetes, you can orchestrate container-based web applications in large landscapes.
comments powered by Disqus