The global and independent platform for the SAP community.

From Open Source Project to Secure Enterprise Solution

There is further proof of the open source success story: Confidential Containers are now available on a public cloud. A community project has quickly become an enterprise-grade solution for critical processes.
Peter Körner, Red Hat
October 20, 2025
avatar
This text has been automatically translated from German to English.

Confidential Containers is an open source sandbox project of the Cloud Native Computing Foundation that enables cloud-native confidential computing. Confidential Containers builds on hardware security technologies and combines them with new software frameworks to increase the security of the user data used. As part of the project, confidential computing was standardized at container level and its use in Kubernetes was simplified.

This allows Kubernetes users to deploy secure container workloads with familiar workflows and tools without extensive knowledge of confidential computing technologies. Renowned providers have supported the project from the outset. Red Hat offers the OpenShift Confidential Containers feature based on Red Hat OpenShift Sandboxed Containers. It extends the security functions of OpenShift. This enables companies to provide and manage confidential workloads with improved data protection.

OpenShift Confidential Containers is now also generally available on Microsoft Azure. This enables companies to reliably protect their sensitive applications and data on Azure. Security is significantly increased as the workloads are isolated in a hardware-protected, trusted execution environment and the data is protected from external access and remains encrypted even during processing.

A key feature of Confidential Containers is the integration of the Trusted Execution Environment infrastructure into the cloud-native world. A TEE is a hardware-based, isolated environment with increased security. It also forms the basis for OpenShift Confidential Containers in combination with a special virtual machine called "Confidential Virtual Machine" (CVM), which is executed within the TEE. The solution uses CVMs to run pods, creating a confidential container for the secure execution of workloads.

Another important feature of Confidential Containers is attestation, a process for checking whether the target TEE on which the workloads are to be executed is actually trustworthy. By combining TEE and attestation, Confidential Containers provides a secure environment and protects code and data from access by privileged users such as administrators. Remote attestation is used here to separate the responsibility of the cloud operator and the attestation, thus further increasing security.

The technological complexity has no impact on the user, as all functions are provided automatically via OpenShift Confidential Containers.
Typical use cases for the use of confidential containers can be found in a wide range of industries. The same applies to the SAP integration of business-critical, containerized processes with high security and privacy requirements. Confidential containers are the ideal environment for secure AI model training with confidential data.

Support for bare metal servers

The OpenShift Confidential Containers solution is under continuous development and Red Hat plans to support additional environments, including bare metal servers, additional public clouds and managed services. New features will also be introduced, such as support for Confidential GPUs, with a particular focus on joint attestation of the CPU and GPU.

Overall, however, the open source project Confidential Containers and the rapid deployment of curated solutions such as OpenShift Confidential Containers or Confidential Containers on Microsoft Azure already make one thing abundantly clear today: open source should not be missing from any enterprise architecture and platform decision or modernization strategy in terms of future-proofing.

Continue to the partner entry:

avatar
Peter Körner, Red Hat

Peter Körner is Principal Business Development Manager Red Hat SAP Solutions at Red Hat


Write a comment

Working on the SAP basis is crucial for successful S/4 conversion. 

This gives the Competence Center strategic importance for existing SAP customers. Regardless of the S/4 Hana operating model, topics such as Automation, Monitoring, Security, Application Lifecycle Management and Data Management the basis for S/4 operations.

For the second time, E3 magazine is organizing a summit for the SAP community in Salzburg to provide comprehensive information on all aspects of S/4 Hana groundwork.

Venue

FourSide Hotel Salzburg,
Trademark Collection by Wyndham
Am Messezentrum 2, 5020 Salzburg, Austria
+43-66-24355460

Event date

Wednesday, June 10, and
Thursday, June 11, 2026

Early Bird Ticket

Regular ticket

Subscribers to the E3 Magazine Ticket

reduced with promocode STAbo26

Students*

reduced with promocode CCStud26.
Please send proof of studies by e-mail to office@b4bmedia.net.
*The first 10 tickets are free of charge for students. Try your luck! 🍀
EUR 390 excl. VAT
available until November 30, 2025
EUR 590 excl. VAT
EUR 390 excl. VAT
EUR 290 excl. VAT

Venue

Hotel Hilton Heidelberg
Kurfürstenanlage 1
D-69115 Heidelberg

Event date

Wednesday, April 22 and
Thursday, April 23, 2026

Tickets

Early Bird Ticket
Regular ticket
EUR 390 excl. VAT
available until 30.11.2025
EUR 590 excl. VAT
Subscribers to the E3 magazine
reduced with promocode STAbo26
EUR 390 excl. VAT
Students*
reduced with promocode STStud26.
Please send proof of studies by e-mail to office@b4bmedia.net.
EUR 290 excl. VAT
*The first 10 tickets are free of charge for students. Try your luck! 🍀
The event is organized by the E3 magazine of the publishing house B4Bmedia.net AG. The presentations will be accompanied by an exhibition of selected SAP partners. The ticket price includes attendance at all presentations of the Steampunk and BTP Summit 2026, a visit to the exhibition area, participation in the evening event and catering during the official program. The lecture program and the list of exhibitors and sponsors (SAP partners) will be published on this website in due course.