🟡 📦 Open Source Published: · 2 min read ·

CNCF: Confidential Containers Advances to Incubating Status with 150+ Contributors and a Focus on Confidential AI

CNCF logo alongside a depiction of the Confidential Containers project's TEE hardware protection

The CNCF Technical Oversight Committee voted to promote Confidential Containers from Sandbox to Incubating status. The project has 1,000+ stars, 1,200+ merged pull requests, and 150+ active contributors from Red Hat, Intel, IBM, Microsoft Azure, AMD, and NVIDIA, and it uses hardware TEEs and the Kata Containers runtime.

🤖

This article was generated using artificial intelligence from primary sources.

What is Confidential Containers, and which TEE technologies does it use?

Confidential Containers is an open-source project launched in 2021 that addresses the problem of protecting data-in-use, not just data at rest or in transit. The project uses hardware Trusted Execution Environments (TEE), isolated and encrypted execution environments within the processor itself, combined with the Kata Containers runtime, which runs containers inside lightweight virtual machines for additional isolation. Together, TEE and Kata Containers enable running sensitive workloads such that not even the infrastructure provider can access the data inside the container while it is being processed.

Why is the TOC promoting the project to Incubating status?

The CNCF Technical Oversight Committee, the Technical Oversight Committee of the Cloud Native Computing Foundation, voted to promote Confidential Containers from Sandbox status, the entry level for new projects, to Incubating status, a level that confirms broader production use and a more mature community. Community metrics back up the decision: the project has more than 1,000 GitHub stars, more than 1,200 merged pull requests, and more than 150 active contributors, coming from companies such as Red Hat, Intel, IBM, Microsoft Azure, AMD, and NVIDIA — competitors collaborating here on shared infrastructure.

Expansion toward confidential AI through KServe

Maintainers Ariel Adam and Mikko Ylinen note that the project is now expanding toward confidential AI, applying TEE protection specifically to AI workloads. Integration with KServe, an open-source platform for serving machine learning models on Kubernetes, enables deploying sensitive ML models in production within a protected TEE environment, so that neither user data nor the model’s own parameters are exposed to the infrastructure operator during inference. This gives the project, originally conceived to protect generic containerized workloads, a clear second application aimed directly at the needs of production AI systems.

Frequently Asked Questions

What is Confidential Containers?
Confidential Containers is an open-source project launched in 2021 that uses hardware Trusted Execution Environments (TEE), isolated and encrypted execution environments, together with the Kata Containers runtime to protect containerized workloads during execution.
What does moving to CNCF Incubating status mean?
CNCF Incubating status is a maturity level above Sandbox within the Cloud Native Computing Foundation, awarded by the Technical Oversight Committee when a project demonstrates broader production use, community growth, and sustainable governance. Confidential Containers has 1,000+ GitHub stars, 1,200+ merged pull requests, and 150+ active contributors.
How is the project expanding toward confidential AI?
Maintainers Ariel Adam and Mikko Ylinen highlight integration with KServe, a platform for serving ML models, through which Confidential Containers enables deploying sensitive AI models in production within protected TEE environments, an area known as confidential AI.

📬 AI news in your inbox

A daily digest built your way — pick topics, sources and cadence. One-click unsubscribe.