arXiv

dstack-capsule: Pod-Level Remote Attestation for Confidential Workloads on Kubernetes

Title: dstack-capsule: Enabling Pod-Level Remote Attestation for Confidential Workloads in Kubernetes

Abstract

The growing adoption of LLM-as-a-Service and other sensitive cloud applications necessitates cryptographic verification that user data is handled within a secure, unaltered environment. Current approaches, such as Confidential Containers (CoCo), rely on a rigid "one Pod per VM" architecture. This model only attests the Guest OS stack, failing to verify individual container identities and resulting in unsustainable resource overhead per virtual machine. To address these limitations, we introduce dstack-capsule, a Kubernetes-based platform that facilitates Pod-level remote attestation using Intel TDX. This system allows multiple Pods to operate within a single Confidential VM while ensuring each maintains a distinct, hardware-backed identity proof.

Our approach relies on a novel two-layer attestation framework. Static platform measurements are permanently locked in RTMR[3] through an irreversible privilege fuse, whereas dynamic Pod identities—specifically pod_uid, pod_spec_hash, and workload_id—are embedded into the report_data field of the TDX Quote. These fields are signed by hardware for every request. dstack-capsule contributes four main components: (1) a Pod-level attestation protocol that links Pod spec digests to hardware-signed Quotes; (2) a privilege fuse that atomically switches a node from setup mode to secure mode; (3) a multi-layer sandbox providing isolation across storage, runtime, admission control, API, and network layers; and (4) a fully open-source implementation built on Kubernetes 1.32, Intel TDX, and Sysbox. Our evaluation of security properties, attestation accuracy, and performance demonstrates that dstack-capsule achieves granular Pod-level verification without the significant resource costs associated with per-VM isolation.


Source: arXiv Generated at: 2026-06-03 00:00:00 UTC

Related Articles

TikTok Billionaire Tops Ambani as Asia’s Second-Richest
Bloomberg

TikTok Billionaire Tops Ambani as Asia’s Second-Richest

TikTok founder surpasses Mukesh Ambani to become Asia’s second-richest person, marking a significant shift in the region...

Publishers in UK can opt out of Google AI search results
BBC News

Publishers in UK can opt out of Google AI search results

UK publishers can now opt out of Google’s AI search summaries, a CMA ruling designed to boost their bargaining power and...

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.
Bloomberg

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.

Kioxia’s market cap nears Toyota’s, signaling a major shift in Japan’s corporate hierarchy. This narrowing gap highlight...

Reuters

Morning Bid: Marvell, a fitting name for the latest AI darling

Reuters highlights Marvell as a top AI stock, noting its name perfectly suits its status as the newest market darling.

Financial Times

Tim Hayward: I built the Jaguar E-Type of computer keyboards

Tim Hayward compares his bespoke keyboard designs to the Jaguar E-Type. He explores high-end customization for personal ...

Financial Times

AI Labs: Zuckerberg’s $100bn gamble

Meta’s $100 billion AI investment aims to secure AI dominance, but questions remain whether sheer spending can outpace c...