Mary Writes

Kata containers: the overlooked Kubernetes workload isolation for secure AI

The Stack

February 04, 2026

Mary Branscombe's avatar
Mary Branscombe
3d

when containers first came along, it wasn't always clear if that was a good enough isolation boundary, especially to people used to VMs; Kata Containers promises stronger isolation with the performance and scalability of containers. the coming V4 is poised for trusted AI at scale and sovereign cloud

Kata containers: Kubernetes workload isolation for secure AI

Kata containers: Kubernetes workload isolation for secure AI

Kata's stepping up from an isolation boundary for untrusted code to a mainstream option for sovereign cloud compute or trusted AI at scale


https://www.thestack.technology/kata-containers-kubernetes-isolation-ai/
Mary Branscombe's avatar
Mary Branscombe
3d

Cloud providers already use Kata themselves: IBM and Ant Group (who runs Alipay) use it for multi-tenant isolation, running untrusted code in a CLI or CI/CD pipeline and increasingly, as an AI agent sandbox - again, that's untrusted code running on their infrastructure.

Kata containers: Kubernetes workload isolation for secure AI

Kata containers: Kubernetes workload isolation for secure AI

Kata's stepping up from an isolation boundary for untrusted code to a mainstream option for sovereign cloud compute or trusted AI at scale


https://www.thestack.technology/kata-containers-kubernetes-isolation-ai/
Mary Branscombe's avatar
Mary Branscombe
3d

Azure uses Kata for its new sandbox pods; RedHat does the same with OpenShift sandbox containers and you can burst to the cloud for scale. Add in improved GPU management in the (increasingly rustified) V4 and Confidential Containers which now support TEES on GPU for privacy and integrity at scale

Kata containers: Kubernetes workload isolation for secure AI

Kata containers: Kubernetes workload isolation for secure AI

Kata's stepping up from an isolation boundary for untrusted code to a mainstream option for sovereign cloud compute or trusted AI at scale


https://www.thestack.technology/kata-containers-kubernetes-isolation-ai/
Mary Branscombe's avatar
Mary Branscombe
3d

There *is* a little extra work to adopt Kata and more to move to confidential containers, but as trusted AI and sovereign cloud become more important priorities, Kata offers a way to do that without giving up Kubernetes: I talk to IBM, Red Hat and Ant about what it takes to run it in production

Kata containers: Kubernetes workload isolation for secure AI

Kata containers: Kubernetes workload isolation for secure AI

Kata's stepping up from an isolation boundary for untrusted code to a mainstream option for sovereign cloud compute or trusted AI at scale


https://www.thestack.technology/kata-containers-kubernetes-isolation-ai/
With the upcoming v4 release, Kata is stepping up from an isolation boundary for untrusted code to a mainstream option for sovereign cloud compute or trusted AI at scale.
Kata containers: Kubernetes workload isolation for secure AI
Kata's stepping up from an isolation boundary for untrusted code to a mainstream option for sovereign cloud compute or trusted AI at scale
https://www.thestack.technology/kata-containers-kubernetes-isolation-ai/

Subscribe to Mary Writes
to get updates in Reader, RSS, or via Bluesky Feed
Secure messaging on Windows with Signal

the stack