Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Linux Foundation

Confidential Containers with the Crun-Krun Container Runtime

Linux Foundation via YouTube

Overview

Explore the crun-krun container runtime in this informative conference talk. Learn how it enables running OCI containers within lightweight KVM-based VMs, providing enhanced process isolation for potentially buggy or malicious workloads. Discover the emerging technology of confidential computing and its role in CPU encryption of guest memory for VM's, preventing malicious hypervisors from accessing or tampering with guest VM memory. Gain insights into crun-krun's recent support for various TEE architectures, allowing for lightweight KVM-based containers with added confidential computing capabilities. Examine the architecture of crun-krun, particularly the libkrun virtualization project that powers it. Understand how it achieves process isolation with minimal performance impact and incorporates confidential computing to run secure containers. Additionally, learn about Podman's recent introduction of support for building crun-krun containers.

Syllabus

Confidential Containers with the Crun-Krun Container Runtime - Tyler Fanelli, Red Hat

Taught by

Linux Foundation

Reviews

Start your review of Confidential Containers with the Crun-Krun Container Runtime

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.