Skip to content

Container/Pod integrity details in the attestation report #3385

Closed Answered by derpsteb
arijit8972 asked this question in Q&A
Discussion options

You must be logged in to vote

Hi,
thank you for the question :). Workload attestation in the way you describe it is not part of Constellation. However, depending on your threat model it may be possible to achieve your goals with a policy engine like Kyverno. With it you can enforce attributes on workloads. The question remains: why trust Kyverno.

If you require workload attestation, Contrast may be just what you want to look at. Contrast is one of our other projects. It is a verification service that builds on confidential containers to provide attested workloads.

Best,
Otto

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@arijit8972
Comment options

Answer selected by arijit8972
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants