Inclavare Containers: Confidential Computing for Cloud-Native Workloads cover

Technology · Ebook

Inclavare Containers: Confidential Computing for Cloud-Native Workloads

by Shriira Press

4.8(265)144 pagesPublished 2026

Inclavare Containers is a CNCF sandbox project that brings hardware-based confidential computing to ordinary containers, running them inside trusted execution environments so that even a compromised host OS, hypervisor, or cloud operator cannot read your code and data. This book starts with the cloud trust problem and the enclave model behind Intel SGX, then walks the project's own pieces: the rune OCI runtime that spawns enclaves, the Enclave Runtime PAL API and library operating systems like Occlum, the shim-rune shim that wires it into Kubernetes and containerd, and the attestation machinery — Rats-TLS, inclavared, and the Shelter verifier — that proves an enclave is genuine before trusting it. A closing chapter covers deployment, trade-offs, and where Inclavare fits among confidential-container efforts.

Contents

  1. 1Preface
  2. 2Chapter 1 — The Trust Problem in the Cloud
  3. 3Chapter 2 — What Inclavare Containers Is
  4. 4Chapter 3 — Enclaves and Intel SGX
  5. 5Chapter 4 — rune: The OCI Enclave Runtime
  6. 6Chapter 5 — The PAL API and Enclave Runtimes
  7. 7Chapter 6 — Kubernetes Integration with shim-rune
  8. 8Chapter 7 — Attestation and Establishing Trust
  9. 9Chapter 8 — Inclavare in Practice