Skip to content

docs: confidential compute KBS registries, storage, and sealed secrets - #1313

Draft
cloud-j-luna wants to merge 1 commit into
mainfrom
docs/confidential-compute-kbs-storage-registry
Draft

docs: confidential compute KBS registries, storage, and sealed secrets#1313
cloud-j-luna wants to merge 1 commit into
mainfrom
docs/confidential-compute-kbs-storage-registry

Conversation

@cloud-j-luna

@cloud-j-luna cloud-j-luna commented Aug 18, 2026

Copy link
Copy Markdown
Member

No description provided.

@cloud-j-luna
cloud-j-luna force-pushed the docs/confidential-compute-kbs-storage-registry branch 3 times, most recently from cd70dc1 to 8f96d64 Compare August 18, 2026 15:39
Update the Confidential Compute docs for the tenant-controlled KBS features
landing across chain-sdk#352, provider#427, and the upstream CoCo/Kata/Trustee
PRs. The feature stays experimental; these pages describe the new SDL and
provider surface.

Tenant guide (learn/core-concepts/confidential-compute):
- new "Confidential Registries, Storage, and Secrets" section
- private registry credentials via credentials.uri (kbs:///repo/type/tag)
- persistent encrypted storage via storage keyRef + persistent block class
- sealed environment variables (fail-closed unseal)
- KBS provider/tenant modes (params.kbs)
- refreshed limitations (private registries, persistent volumes, first-mount cost)

Operator guide (providers/.../kubespray/confidential-compute):
- STEP 4b: provider KBS flags and confidential storage class allowlist
- fix stale tee: {type: sev-snp} example -> tee: cpu

Hardware compatibility: Hopper/Blackwell local GPU attestation note.
SDL advanced-features: replace stale private-registry warning.
@cloud-j-luna
cloud-j-luna force-pushed the docs/confidential-compute-kbs-storage-registry branch from 8f96d64 to 6396902 Compare August 19, 2026 13:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant