Confidential containers on ARO

Interactive demo6 mins红帽 OpenShift

发布时间 October 1, 2025 by Ricardo Garcia Cavero

This interactive demo helps users secure sensitive workloads by ensuring containers run in a trusted execution environment. It walks through the full deployment and configuration experience for confidential containers on Azure Red Hat OpenShift.

3D graphic of OpenShift icon, a cloud, and a cursor aimed at a purple target
What you'll learn Next steps 资源 Feedback

What you'll learn in this interactive demo

• Deploying the Red Hat build of Trustee operator in an OpenShift cluster.
• Configuring the Trustee with ConfigMaps for general settings, reference values, resource policy, and attestation policy.
• Creating a Key Broker Service (KBS) Custom Resource to deploy the Key Broker Service.
• Installing the OpenShift sandboxed containers Operator.
• Configuring peer pods with ConfigMaps for feature activation and Azure instance types.
• Deploying a confidential container application using the kata-remote runtime class and verifying its secure execution and restricted access.

About the author of this page

Ricardo Garcia Cavero headshot

Ricardo Garcia Cavero

Principal Portfolio Architect

Ricardo Garcia Cavero joined Red Hat in October 2019 as a Senior Architect focused on SAP. In this role, he developed solutions with Red Hat's portfolio to help customers in their SAP journey. Cavero now works for as a Principal Portfolio Architect for the Portfolio Architecture team. ...