RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Project: Confidential ContainersClear ×
Confidential Containersv0.22.0SecurityJul 28, 2026

A release with a breaking authentication change and several operator-visible removals, alongside new integrations, APIs, and configuration capabilities. No security fixes or advisory identifiers are disclosed.

Check if affected (6)

  • breakingKBS client admin-token authentication

    Applies if you use the KBS client.

    The KBS client is now invoked with an admin token rather than an admin private key in v0.22.0.

  • breakingThe CAA docker provider, removed

    Applies if you use the CAA docker provider.

    The CAA docker provider was removed in v0.22.0.

  • breakingThe Fedora-based mkosi-built CAA podvm image, removed

    Applies if you use the Fedora-based mkosi-built CAA podvm image.

    The Fedora-based mkosi-built CAA podvm image was removed in v0.22.0.

  • + 3 more on the release page
Source
Confidential Containersv0.21.0SecurityMay 29, 2026

A release with Trustee, KBS, attestation, and platform-support changes, plus a security advisory fix. It also deprecates several CAA components and images planned for removal in 0.22.

Action needed (1)

  • securityGHSA-84rc-2q4r-45pc advisory fix

    The release patches GHSA-84rc-2q4r-45pc in the guest components.

Plan ahead (4)

  • deprecatedpacker-built CAA podvm image deprecationdeprecated since 0.17 · removal planned in 0.22

    Applies if you use the packer-built CAA podvm image.

    The packer-built CAA podvm image has been deprecated since 0.17 and is planned for removal in 0.22.

  • deprecatedCAA docker provider deprecationdeprecated since 0.20 · removal planned in 0.22

    Applies if you use the CAA docker provider.

    The CAA docker provider has been deprecated since 0.20 and is planned for removal in 0.22.

  • deprecatedFedora-based mkosi-built CAA podvm image deprecationdeprecated since 0.20 · removal planned in 0.22

    Applies if you use the Fedora-based mkosi-built CAA podvm image.

    The Fedora-based mkosi-built CAA podvm image has been deprecated since 0.20 and is planned for removal in 0.22.

  • + 1 more on the release page
Source
Confidential Containersv0.20.0SecurityMay 5, 2026

Confidential Containers v0.20.0 combines operator-visible capability and compatibility updates with deprecations of several image and provider paths. It also includes a security fix identified by GHSA-q49m-57vm-c8cc.

Action needed (1)

  • securityhighGHSA-q49m-57vm-c8cc security fix

    The release includes a fix for the security issue identified by GHSA-q49m-57vm-c8cc.

Plan ahead (3)

  • deprecatedThe Docker CAA provider, deprecatedremoval date not announced

    Applies if you use the Docker CAA provider.

    The Docker CAA provider is deprecated and planned to be dropped in the next release.

  • breakingThe Fedora-based mkosi CAA podvm image, deprecatedremoval date not announced

    Applies if you use the Fedora-based mkosi CAA podvm image.

    The Fedora-based mkosi CAA podvm image is deprecated and replaced with an Ubuntu image. It is planned to be dropped in the next release.

  • deprecatedSupport for packer images, deprecatedremoval date not announced

    Applies if you use packer images.

    Support for packer images is deprecated and will be dropped in some future release.

Source
Confidential Containersv0.19.0SecurityMar 30, 2026

A release that narrows supported environments and installation paths while adding storage, attestation, GPU, API, signature, and image-handling capabilities. It also updates guest and image handling, including sealed-secret signatures, cosign signatures with newlines, in-memory LUKS headers, and improved Vault/OpenBao support.

Check if affected (5)

  • breakingGo support in CDH removed

    Applies if you use CDH.

    Go support in CDH is removed in this release.

  • breakingCanonical TDX Tech preview support removed

    Applies if you use Canonical TDX Tech preview.

    The [Canonical TDX Tech preview](https://github.com/canonical/tdx) is no longer supported in this release.

  • breakingUbuntu version requirement

    Applies if you use Ubuntu 24.04.4 (linux-image-generic-hwe-24.04) or 25.10.

    Ubuntu 24.04.4 with linux-image-generic-hwe-24.04 or Ubuntu 25.10 must be used.

  • + 2 more on the release page

Plan ahead (1)

  • deprecatedpacker images support, planned for removalremoval date not announced

    Applies if you use packer images.

    Support for packer images will be dropped in some future release.

Source
Confidential Containersv0.18.0SecurityJan 23, 2026

A release that removes or deprecates several operator-facing components while adding capabilities and changing supported formats and behavior. It also updates shipped platform components, including Trustee, image-rs, guest kernels, and OVMF.

Check if affected (2)

  • breakingProcess-based confidential computing via enclave-cc, removed

    Applies if you use enclave-cc.

    Support for process-based confidential computing via enclave-cc is removed in this release.

  • breakingExperimental Secure Comms mode, removed from the Cloud API Adaptor

    Applies if you configure Secure Comms mode.

    The Cloud API Adaptor has dropped support for the experimental Secure Comms mode.

Plan ahead (2)

  • breakingThe CoCo operator, deprecated, with Helm chart installation

    Applies if you use the CoCo operator.

    The CoCo operator is deprecated. The project is now installed via a Helm chart.

  • deprecatedpacker guest images, deprecated in favor of mkosiremoval date not announced

    Applies if you use packer images.

    The Cloud API Adaptor is moving away from building guest images with packer in favor of mkosi. Support for packer images will be dropped in a future release.

Source
Browse by month