Skip to main content

Case Study: Measured Boot and Remote Attestation in Confidential Containers

UB4.136 | Day 2 | 12:30 - 12:50 | Speakers: Magnus Kulke

Case Study: Measured Boot and Remote Attestation in Confidential Containers
A picture of a devroom at FOSDEM 2024
Open in browser

Notes

Abstract

In this talk we want to present how the Confidential Containers project is using Measured Boot, vTPMs and Rego policies to provide ephemeral, integrity-protected sandboxes for containers in a Trusted Execution Environment. We'll describe the lifecycle of a such a confidential cloud-native workflow, specifically the remote attestation workflows and the components that are involved. Our experience with the tools that we love (UKIs, mkosi!) and the tools that we can't go around (libtss) will be covered, along with lessons learned and remaining challenges.

Speakers

Magnus Kulke

Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.