Edgeless Systems today introduced Constellation, a confidential orchestration platform the vendor claims isolates and encrypts entire Kubernetes deployments during runtime and allows enterprises to treat public clouds like their own private cloud.
Constellation utilizes confidential computing to encrypt workloads at runtime and ensure they are cryptographically verifiable. "With these two basic properties, one can strongly and verifiably isolate workloads from the cloud provider," Edgeless Systems CEO Felix Schuster wrote in response to questions.
Unlike some existing confidential computing offerings, Constellation doesn't require any code alterations before using the platform. Three user commands are needed to enable Constellation's full functionality, and "once you are inside Constellation, it simply looks and feels like normal Kubernetes," Schuster said.
On the backend, the platform starts up the confidential virtual machines (VMs), verifies which applications are running, creates a secure network overlay, encrypts persistent storage, and manages the associated cryptographic keys. This means malicious actors or cloud administrators cannot access those isolated workloads because the VMs are protected from the public cloud provider, he explained.
And Constellation doesn't just orchestrate confidential VMs, Schuster noted. Rather, the platform applies confidential computing end-to-end to secure the entire cluster.
This allows organizations to move on-premise workloads to the cloud "with maximum security and full compliance," Schuster said. That extra layer of security is crucial for reducing an organization's risk of cyberattacks or ransomware, and the platform's compliance features speed up legal processes and lower the risk of fines.
Complexity ChallengesOn the other hand, Schuster identified a complex challenge for organizations moving from on-premises infrastructure to Constellation — a lack of cloud-ready architecture based on containers and microservices. But while he acknowledges this is a problem, it should also be an opportunity to push those organizations to "finally add the technological agility that innovative companies require today."
Users appreciate Constellation's Kubernetes-first approach, but that characteristic makes it just as complex as Kubernetes itself. To that end, "additional Kubernetes flavors like OpenShift and managed services become relevant," Schuster said. The vendor plans to offer its open source tools as managed service variations to provide extra support in that area.
The Future of the Cloud Is Confidential and CompetitiveSchuster predicts the entire cloud will soon be confidential — not just sensitive workloads. Confidential computing will become a "mainstream hygiene factor for cloud workloads," following in the footsteps of firewalls in on-premises environments. "Edgeless Systems will play a fundamental role in making this shift happen and become the Kubernetes of the confidential cloud," Schuster said.
Despite its CEO's confidence, Edgeless Systems faces a few competing confidential computing vendors, including U.S.-based Fortanix and Anjuna. Schuster touted Constellation's quick setup, library of open source tools, and European regulatory expertise as differentiating factors.
Comments