-
Notifications
You must be signed in to change notification settings - Fork 48
Adding Initial Overview #3
Adding Initial Overview #3
Conversation
Addressing PR reviews - Updated confidential-containers organization ReadMe to guide people to right repo (operator v documentation. - split original PR - Moved content to documentationn repo PRs (confidential-containers/documentation#3) and (confidential-containers/documentation#4) Signed-off-by: James Magowan [email protected]
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
looks pretty good. I wonder if we can be even clearer about the highlights and what the best way to introduce pods is.
Overview.md
Outdated
|
||
# Confidential Containers | ||
We are interested in integrating existing [Trusted Execution Environments](https://en.wikipedia.org/wiki/Trusted_execution_environment) (TEE) | ||
infrastructure support and technologies with the cloud native world. Our focus is to place a kubernetes pod into a TEE. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Are Confidential Containers inherently connected to pod-centric virtualization? Could we support other runtimes that isolate one container at a time?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks, updated this section to try annd include more detail around this
Overview.md
Outdated
|
||
# Confidential Containers | ||
We are interested in integrating existing [Trusted Execution Environments](https://en.wikipedia.org/wiki/Trusted_execution_environment) (TEE) | ||
infrastructure support and technologies with the cloud native world. Our focus is to place a kubernetes pod into a TEE. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
In the first sentence do we want to mention 1) Transparent deployment of unmodified containers 2) Support for multiple hardware platforms 3) A strict trust model that separates the CSP from guest applications
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks, updated this section to try annd include more detail around this
Adding Initial Overview covering Why/How, What. Signed-off-by: James Magowan [email protected]
Responding to PR comments Signed-off-by: James Magowan [email protected]
ac91d58
to
ee111c5
Compare
Addressing PR reviews - Updated confidential-containers organization ReadMe to guide people to right repo (operator v documentation. - split original PR - Moved content to documentationn repo PRs (confidential-containers/documentation#3) and (confidential-containers/documentation#4) Signed-off-by: James Magowan [email protected]
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM. I agree that maybe we can extend the section about the virtualization boundary with some diagrams at some point, maybe in another doc.
Adding Initial Overview covering Why/How, What.
Signed-off-by: James Magowan [email protected]