RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Project: Confidential ContainersClear ×
Confidential Containersv0.22.0SecurityJul 28, 2026

A release with a breaking authentication change and several operator-visible removals, alongside new integrations, APIs, and configuration capabilities. No security fixes or advisory identifiers are disclosed.

Check if affected (6)

  • breakingKBS client admin-token authentication

    Applies if you use the KBS client.

    The KBS client is now invoked with an admin token rather than an admin private key in v0.22.0.

  • breakingThe CAA docker provider, removed

    Applies if you use the CAA docker provider.

    The CAA docker provider was removed in v0.22.0.

  • breakingThe Fedora-based mkosi-built CAA podvm image, removed

    Applies if you use the Fedora-based mkosi-built CAA podvm image.

    The Fedora-based mkosi-built CAA podvm image was removed in v0.22.0.

  • + 3 more on the release page
Source
Confidential Containersv0.19.0SecurityMar 30, 2026

A release that narrows supported environments and installation paths while adding storage, attestation, GPU, API, signature, and image-handling capabilities. It also updates guest and image handling, including sealed-secret signatures, cosign signatures with newlines, in-memory LUKS headers, and improved Vault/OpenBao support.

Check if affected (5)

  • breakingGo support in CDH removed

    Applies if you use CDH.

    Go support in CDH is removed in this release.

  • breakingCanonical TDX Tech preview support removed

    Applies if you use Canonical TDX Tech preview.

    The [Canonical TDX Tech preview](https://github.com/canonical/tdx) is no longer supported in this release.

  • breakingUbuntu version requirement

    Applies if you use Ubuntu 24.04.4 (linux-image-generic-hwe-24.04) or 25.10.

    Ubuntu 24.04.4 with linux-image-generic-hwe-24.04 or Ubuntu 25.10 must be used.

  • + 2 more on the release page

Plan ahead (1)

  • deprecatedpacker images support, planned for removalremoval date not announced

    Applies if you use packer images.

    Support for packer images will be dropped in some future release.

Source
Confidential Containersv0.18.0SecurityJan 23, 2026

A release that removes or deprecates several operator-facing components while adding capabilities and changing supported formats and behavior. It also updates shipped platform components, including Trustee, image-rs, guest kernels, and OVMF.

Check if affected (2)

  • breakingProcess-based confidential computing via enclave-cc, removed

    Applies if you use enclave-cc.

    Support for process-based confidential computing via enclave-cc is removed in this release.

  • breakingExperimental Secure Comms mode, removed from the Cloud API Adaptor

    Applies if you configure Secure Comms mode.

    The Cloud API Adaptor has dropped support for the experimental Secure Comms mode.

Plan ahead (2)

  • breakingThe CoCo operator, deprecated, with Helm chart installation

    Applies if you use the CoCo operator.

    The CoCo operator is deprecated. The project is now installed via a Helm chart.

  • deprecatedpacker guest images, deprecated in favor of mkosiremoval date not announced

    Applies if you use packer images.

    The Cloud API Adaptor is moving away from building guest images with packer in favor of mkosi. Support for packer images will be dropped in a future release.

Source
Browse by month