# Run Confidential Containers with encrypted images using Arm CCA and Trustee

## In this learning path

- [Introduction](https://learn.arm.com/learning-paths/servers-and-cloud-computing/cca-kata/)
- [Overview of Confidential Containers and Arm CCA Attestation with Trustee](https://learn.arm.com/learning-paths/servers-and-cloud-computing/cca-kata/cca-kata/)
- [Run a confidential container with an encrypted image](https://learn.arm.com/learning-paths/servers-and-cloud-computing/cca-kata/flow/)
- [Next Steps](https://learn.arm.com/learning-paths/servers-and-cloud-computing/cca-kata/_next-steps/)

## About this Learning Path

| Skill level:     | Advanced         |
|------------------|------------------|
| Reading time:    | 1 hr             |
| Last updated:    | 03 Jul 2026      |

| Author:            | Anton Antonov    |
|--------------------|------------------|
| Arm IP:            | [Neoverse](https://support.arm.com/?tab=compute-ip&Product%20Type=Infrastructure%20Processors) [Cortex-A](https://support.arm.com/?tab=compute-ip&Product%20Type=Application%20Processors) |
| Tags:              | [Performance and Architecture](https://learn.arm.com/tag/performance-and-architecture) [Linux](https://learn.arm.com/tag/linux) [macOS](https://learn.arm.com/tag/macos) [FVP](https://learn.arm.com/tag/fvp) [RME](https://learn.arm.com/tag/rme) [CCA](https://learn.arm.com/tag/cca) [Docker](https://learn.arm.com/tag/docker) [Veraison](https://learn.arm.com/tag/veraison) [Trustee](https://learn.arm.com/tag/trustee) [Confidential Containers](https://learn.arm.com/tag/confidential-containers) [Kata Containers](https://learn.arm.com/tag/kata-containers) |

### Who is this for?
This Learning Path is for developers who want to understand how Confidential Containers run in Arm CCA Realms.

### What will you learn?
Upon completion of this Learning Path, you will be able to:
- Gain an overview of Confidential Containers and their role in confidential computing
- Understand how Trustee services are used with Arm CCA attestation to authorize and unlock confidential workloads
- Deploy a Confidential Container from an encrypted image inside an Arm CCA Realm using an Armv9-A AEM Base Fixed Virtual Platform (FVP) with RME support

### Prerequisites
Before starting, you will need the following:
- An AArch64 or x86_64 computer running Linux or macOS. Cloud-based instances can also be used; see the [Arm cloud service providers](https://learn.arm.com/learning-paths/servers-and-cloud-computing/csp/).
- Completion of the [Run an end-to-end Attestation with Arm CCA and Trustee](https://learn.arm.com/learning-paths/servers-and-cloud-computing/cca-trustee) Learning Path.

### Summary
You’ll deploy a confidential container from an encrypted image inside an Arm CCA Realm on an Armv9-A AEM Base Fixed Virtual Platform (FVP) with Realm Management Extension (RME) support. First, you’ll learn about the Confidential Containers design, understand which components run inside the Trusted Execution Environment, and see how Trustee services use Arm CCA attestation to authorize decryption. Then, you’ll start the Trustee services and a local Docker registry, publish an encrypted image, and launch the container on the FVP. By the end, you’ll confirm attestation, key release, and that the workload runs in a Realm only after authorization.

### Frequently asked questions
<details>
<summary>How do I know the Trustee services are ready before pushing the image?</summary>
Confirm that the AS, KBS, and RVPS processes have started and are listening. Check their startup logs for ready or healthy messages before continuing.
</details>

<details>
<summary>Which registry should I use when publishing the encrypted image?</summary>
Use the local Docker registry started as part of this Learning Path. Tag the encrypted image for that registry and push, and proceed only after the push completes without errors.
</details>

<details>
<summary>What result should I expect when launching the confidential container on the FVP?</summary>
The runtime pulls the encrypted image from the local registry, performs Arm CCA attestation via Trustee, obtains decryption keys, and starts the workload inside an Arm CCA Realm. Expect logs indicating successful attestation or authorization and that the container is running.
</details>

<details>
<summary>How can I verify the container is actually running inside an Arm CCA Realm?</summary>
Follow the verification step to check Realm-specific output from the launch. Validation relies on Trustee accepting CCA attestation evidence; without acceptance, the image remains locked and the workload does not start.
</details>

<details>
<summary>What should I check if the encrypted image fails to pull or decrypt during launch?</summary>
Verify the local registry is running and reachable and that the image was pushed with the expected tag. Confirm AS, KBS, and RVPS are up and that attestation evidence is available so the KBS can release keys after authorization.
</details>
