Log in

goodpods headphones icon

To access all our features

Open the Goodpods app
Close icon
Kubernetes Podcast from Google - Confidential Computing, with Fabian Kammel

Confidential Computing, with Fabian Kammel

11/23/23 • 53 min

Kubernetes Podcast from Google

Fabian Kammel is a Security Architect at ControlPlane, where he helps to make the (cloud-native) world a safer place. In his career, he continuously worked to bring hardware security and cloud-native security closer together. His past projects include:

A cloud-native PKIs for on-road vehicle services secured by enterprise HSMs

An always-encrypted Kubernetes distribution that harnesses the power of Confidential Computing

And more recently securing SPIFFE-based machine identities via hardware attestation.

Do you have something cool to share? Some questions? Let us know:

web: kubernetespodcast.com

mail: [email protected]

twitter: @kubernetespod

Links from the interview

Confidential Computing Blog from kubernetes.io

Confidential Computing Consortium

Confidential Computing Whitepaper

Intel SGX Enclave

Swap Memory with Kubernetes in Beta in 1.28

Hardware Security Modules

Trusted Platform Modules (TPM)

Envelope Encryption

Confidential Computing Concepts - Confidential Virtual Machine

AMD Secure Encrypted Virtualization (AMD SEV)

AMD Secure Encrypted Virtualization - Secure Nested Paging (AMD SEV SNP)

Trusted Computing Base (TCB)

Remote Attestation

Confidentiality, Integrity, and Availability: The CIA Triad

Intel SGX Enclaves

Confidential Containers (CoCo)

Katacontainers

AWS Firecracker

plus icon
bookmark

Fabian Kammel is a Security Architect at ControlPlane, where he helps to make the (cloud-native) world a safer place. In his career, he continuously worked to bring hardware security and cloud-native security closer together. His past projects include:

A cloud-native PKIs for on-road vehicle services secured by enterprise HSMs

An always-encrypted Kubernetes distribution that harnesses the power of Confidential Computing

And more recently securing SPIFFE-based machine identities via hardware attestation.

Do you have something cool to share? Some questions? Let us know:

web: kubernetespodcast.com

mail: [email protected]

twitter: @kubernetespod

Links from the interview

Confidential Computing Blog from kubernetes.io

Confidential Computing Consortium

Confidential Computing Whitepaper

Intel SGX Enclave

Swap Memory with Kubernetes in Beta in 1.28

Hardware Security Modules

Trusted Platform Modules (TPM)

Envelope Encryption

Confidential Computing Concepts - Confidential Virtual Machine

AMD Secure Encrypted Virtualization (AMD SEV)

AMD Secure Encrypted Virtualization - Secure Nested Paging (AMD SEV SNP)

Trusted Computing Base (TCB)

Remote Attestation

Confidentiality, Integrity, and Availability: The CIA Triad

Intel SGX Enclaves

Confidential Containers (CoCo)

Katacontainers

AWS Firecracker

Previous Episode

undefined - etcd, with Marek Siarkowicz and Wenjia Zhang

etcd, with Marek Siarkowicz and Wenjia Zhang

Guests are Marek Siarkowicz , Senior Software Engineer in Google Cloud, Tech Lead of SIG-etcd AND Wenjia Zhang, Engineering Manager in Google Cloud, Co-Chair of SIG-etcd, Google. We spoke about the project, the recent change to become a Special Interest Group and how to learn etcd.

Do you have something cool to share? Some questions? Let us know:

web: kubernetespodcast.com

mail: [email protected]

twitter: @kubernetespod

News of the week

Co-host this week is Mofi Rahman [X, LinkedIn]. Cloud Developer Advocate at Google

Karpenter graduated to Beta

The Kubernetes SIG Network announced release 1.0 of the Gateway API

Ingress2gateway new CLI to migrate from Ingress to Gateway

The Call for Proposals for KubeCon EU 2024 will close on Nov 26, 2023

Links from the interview

etcd

Meaning of etcd

etcd history from CoreOs

Raft paper

On the Hunt for Etcd Data Inconsistencies by Marek Siarkowicz - [youtube]

Lessons Learned From Etcd the Data Inconsistency Issues by Marek Siarkowicz - [youtube]

The first pancake rule

etcd as a Kubernetes sig

The Case for SIG-ifying etcd

CNCF Contributor License Agreements (CLA)

Kubernetes Prow

Contributor Experience Special Interest Group

Kubernetes Watch

Go Serialization and Deserialization

Cilium with external etcd

Certified Kubernetes Administrator

etcd mentorship program

etcd @kubecon NA 2023

Links from the post-interview chat

Kubernetes considerations for large clusters

Operating etcd clusters for Kubernetes

Kueue

etcd on the podcast

The Heartbleed Bug

XKCD meme about dependency

Next Episode

undefined - Kubernetes Pen Testing, with Jesper Larsson

Kubernetes Pen Testing, with Jesper Larsson

Jesper Larsson is a Freelance PenTester. Jesper works with a hacker community called Cure53. Co-organizes SecurityFest in Gothenburg, Sweden. Hosts Säkerhetspodcasten or The Security Podcast. Jesper is also a Star on Hackad, a Swedish TV Series about hacking.

Do you have something cool to share? Some questions? Let us know:

web: kubernetespodcast.com

mail: [email protected]

twitter: @kubernetespod

News of the week

Kubernetes Removals, Deprecations, and Major Changes in Kubernetes 1.29

Introducing SIG etcd

etcd, with Marek Siarkowicz and Wenjia Zhang (The Kubernetes Podcast from Google)

WebAssembly (WASM) and OpenShift: A Powerful Duo for Modern Applications

Linux Foundation Events

Pass the torch in ContribEx #7603

Links from the interview

Cure53 Hacker Community

Säkerhetspodcasten

Hackad TV Show on IMDB

SecurityFest Gothenburg

Falco by Sysdig

Wolfi by Chainguard

The Untold Story of NotPetya, the Most Devastating Cyberattack in History

Links from the post-interview chat

The Untold Story of NotPetya, the Most Devastating Cyberattack in History

Episode Comments

Generate a badge

Get a badge for your website that links back to this episode

Select type & size
Open dropdown icon
share badge image

<a href="https://goodpods.com/podcasts/kubernetes-podcast-from-google-281709/confidential-computing-with-fabian-kammel-37591568"> <img src="https://storage.googleapis.com/goodpods-images-bucket/badges/generic-badge-1.svg" alt="listen to confidential computing, with fabian kammel on goodpods" style="width: 225px" /> </a>

Copy