{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T12:59:27Z","timestamp":1780664367457,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":114,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,4,26]],"date-time":"2026-04-26T00:00:00Z","timestamp":1777161600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,27]]},"DOI":"10.1145\/3767295.3769324","type":"proceedings-article","created":{"date-parts":[[2026,4,24]],"date-time":"2026-04-24T20:20:04Z","timestamp":1777062004000},"page":"311-327","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Pyramid: A Secure, Resource-Efficient, and Pluggable Kubernetes for Multi-Tenancy"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8906-0832","authenticated-orcid":false,"given":"Xiang","family":"Li","sequence":"first","affiliation":[{"name":"Tsinghua University, Beijing, China"},{"name":"China Telecom eSurfing Cloud (State Cloud), Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3054-766X","authenticated-orcid":false,"given":"Weijie","family":"Liu","sequence":"additional","affiliation":[{"name":"Nankai University, Tianjin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5877-2693","authenticated-orcid":false,"given":"Fabing","family":"Li","sequence":"additional","affiliation":[{"name":"Ant Group, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-1248-4078","authenticated-orcid":false,"given":"Hongliang","family":"Tian","sequence":"additional","affiliation":[{"name":"Ant Group, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2984-2661","authenticated-orcid":false,"given":"Zheli","family":"Liu","sequence":"additional","affiliation":[{"name":"Nankai University, Tianjin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-9580-5395","authenticated-orcid":false,"given":"Shoumeng","family":"Yan","sequence":"additional","affiliation":[{"name":"Ant Group, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8433-7281","authenticated-orcid":false,"given":"Mingyu","family":"Gao","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"},{"name":"Shanghai Qi Zhi Institute, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,4,26]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"crossref","unstructured":"Shai Almog. 2023. Debugging Kubernetes. In Practical Debugging at Scale: Cloud Native Debugging in Kubernetes and Production. 119\u2013134.","DOI":"10.1007\/978-1-4842-9042-2_6"},{"key":"e_1_3_2_1_2_1","volume-title":"TrustZone: Integrated Hardware and Software Security. White paper","author":"Alves Tiago","year":"2004","unstructured":"Tiago Alves. 2004. TrustZone: Integrated Hardware and Software Security. White paper (2004)."},{"key":"e_1_3_2_1_3_1","volume-title":"Retrieved","year":"2024","unstructured":"Amazon. 2024. Hard Multi-Tenancy. Retrieved September 29, 2024 from https:\/\/aws.github.io\/aws-eks-best-practices\/security\/docs\/multitenancy\/#hard-multi-tenancy"},{"key":"e_1_3_2_1_4_1","volume-title":"AMD SEV-SNP: Strengthening VM Isolation with Integrity Protection and More. Retrieved","author":"AMD.","year":"2022","unstructured":"AMD. 2020. AMD SEV-SNP: Strengthening VM Isolation with Integrity Protection and More. Retrieved July 2, 2022 from https:\/\/www.amd.com\/system\/files\/TechDocs\/SEV-SNPstrengthening-vm-isolation-with-integrity-protection-and-more.pdf"},{"key":"e_1_3_2_1_5_1","volume-title":"AMD SEV-TIO: Trusted I\/O for Secure Encrypted Visualization. Retrieved","author":"AMD.","year":"2023","unstructured":"AMD. 2023. AMD SEV-TIO: Trusted I\/O for Secure Encrypted Visualization. Retrieved December 9, 2023 from https:\/\/www.amd.com\/system\/files\/documents\/sev-tio-whitepaper.pdf"},{"key":"e_1_3_2_1_6_1","volume-title":"Proceedings of the 2nd International Workshop on Hardware and Architectural Support for Security and Privacy.","author":"Anati Ittai","year":"2013","unstructured":"Ittai Anati, Shay Gueron, Simon Johnson, and Vincent Scarlata. 2013. Innovative Technology for CPU Based Attestation and Sealing. In Proceedings of the 2nd International Workshop on Hardware and Architectural Support for Security and Privacy."},{"key":"e_1_3_2_1_7_1","volume-title":"Nimble: Rollback Protection for Confidential Cloud Services. In 17th USENIX Symposium on Operating Systems Design and Implementation. 193\u2013208","author":"Angel Sebastian","year":"2023","unstructured":"Sebastian Angel, Aditya Basu, Weidong Cui, Trent Jaeger, Stella Lau, Srinath Setty, and Sudheesh Singanamalla. 2023. Nimble: Rollback Protection for Confidential Cloud Services. In 17th USENIX Symposium on Operating Systems Design and Implementation. 193\u2013208."},{"key":"e_1_3_2_1_8_1","volume-title":"Applications and Challenges in Securing Time. In 12th USENIX Workshop on Cyber Security Experimentation and Test.","author":"Fatima","unstructured":"Fatima M. Anwar and Mani Srivastava. 2019. Applications and Challenges in Securing Time. In 12th USENIX Workshop on Cyber Security Experimentation and Test."},{"key":"e_1_3_2_1_9_1","volume-title":"Retrieved","author":"ARM.","year":"2021","unstructured":"ARM. 2021. Arm Confidential Compute Architecture. Retrieved July 15, 2023 from https:\/\/www.arm.com\/architecture\/security-features\/arm-confidential-compute-architecture"},{"key":"e_1_3_2_1_10_1","volume-title":"Proceedings of 12th USENIX Symposium on Operating Systems Design and Implementation. 689\u2013703","author":"Arnautov Sergei","year":"2016","unstructured":"Sergei Arnautov, Bohdan Trach, Franz Gregor, Thomas Knauth, Andre Martin, Christian Priebe, Joshua Lind, Divya Muthukumaran, Dan O'Keeffe, Mark L. Stillwell, David Goltzsche, Dave Eyers, R\u00fcdiger Kapitza, Peter Pietzuch, and Christof Fetzer. 2016. SCONE: Secure Linux Containers with Intel SGX. In Proceedings of 12th USENIX Symposium on Operating Systems Design and Implementation. 689\u2013703."},{"key":"e_1_3_2_1_11_1","volume-title":"Retrieved","author":"CoCo Authors The","year":"2023","unstructured":"The CoCo Authors. 2023. Securing the Kata Control Plane. Retrieved September 24, 2023 from https:\/\/github.com\/confidential-containers\/confidential-containers\/issues\/53"},{"key":"e_1_3_2_1_12_1","volume-title":"Retrieved","author":"Container Authors The Confidential","year":"2023","unstructured":"The Confidential Container Authors. 2023. Github Homepage: Confidential Containers. Retrieved September 24, 2023 from https:\/\/github.com\/confidential-containers"},{"key":"e_1_3_2_1_13_1","volume-title":"Retrieved","author":"Authors The Kubernetes","year":"2023","unstructured":"The Kubernetes Authors. 2023. Kubernetes Documents: Custom Resources. Retrieved September 24, 2023 from https:\/\/kubernetes.io\/docs\/concepts\/extend-kubernetes\/api-extension\/custom-resources"},{"key":"e_1_3_2_1_14_1","volume-title":"Retrieved","author":"Authors The Kubernetes","year":"2023","unstructured":"The Kubernetes Authors. 2023. Kubernetes Documents: Pod Lifecycle. Retrieved September 24, 2023 from https:\/\/kubernetes.io\/docs\/concepts\/workloads\/pods\/pod-lifecycle"},{"key":"e_1_3_2_1_15_1","volume-title":"Retrieved","author":"The Kubernetes","year":"2023","unstructured":"The Kubernetes authors. 2023. Kubernetes Homepage. Retrieved September 22, 2023 from http:\/\/kubernetes.io"},{"key":"e_1_3_2_1_16_1","volume-title":"Retrieved","author":"Kamaji Authors","year":"2023","unstructured":"Authors of Kamaji. 2023. Kamaji. Retrieved October 15, 2023 from https:\/\/github.com\/clastix\/kamaji"},{"key":"e_1_3_2_1_17_1","volume-title":"Retrieved","year":"2024","unstructured":"Azure. 2024. Multi-Tenancy Types. Retrieved September 29, 2024 from https:\/\/learn.microsoft.com\/en-us\/azure\/architecture\/guide\/multitenant\/service\/aks#multitenancy-types"},{"key":"e_1_3_2_1_18_1","volume-title":"Avocado: A Secure In-Memory Distributed Storage System. In 2021 USENIX Annual Technical Conference. 65\u201379","author":"Bailleu Maurice","year":"2021","unstructured":"Maurice Bailleu, Dimitra Giantsidi, Vasilis Gavrielatos, Vijay Nagarajan, Pramod Bhatotia, et al. 2021. Avocado: A Secure In-Memory Distributed Storage System. In 2021 USENIX Annual Technical Conference. 65\u201379."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1147\/JRD.2016.2574138"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2799647"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4842-5519-3"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3029806.3029836"},{"key":"e_1_3_2_1_23_1","volume-title":"Kubernetes Scheduling: Taxonomy, Ongoing Issues and Challenges. ACM Computing Surveys 55, 7","author":"Carri\u00f3n Carmen","year":"2022","unstructured":"Carmen Carri\u00f3n. 2022. Kubernetes Scheduling: Taxonomy, Ongoing Issues and Challenges. ACM Computing Surveys 55, 7 (2022)."},{"key":"e_1_3_2_1_24_1","volume-title":"Container Orchestration: A Survey. Systems Modeling: Methodologies and Tools","author":"Casalicchio Emiliano","year":"2019","unstructured":"Emiliano Casalicchio. 2019. Container Orchestration: A Survey. Systems Modeling: Methodologies and Tools (2019), 221\u2013235."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2451116.2451145"},{"key":"e_1_3_2_1_26_1","volume-title":"AutoDECK: Automated Declarative Performance Evaluation and Tuning Framework on Kubernetes. In 2022 IEEE 15th International Conference on Cloud Computing. 309\u2013314","author":"Choochotkaew Sunyanan","year":"2022","unstructured":"Sunyanan Choochotkaew, Tatsuhiro Chiba, Scott Trent, Takeshi Yoshimura, and Marcelo Amaral. 2022. AutoDECK: Automated Declarative Performance Evaluation and Tuning Framework on Kubernetes. In 2022 IEEE 15th International Conference on Cloud Computing. 309\u2013314."},{"key":"e_1_3_2_1_27_1","volume-title":"IPsec Transparent Encryption. Retrieved","author":"Authors Cilium","year":"2024","unstructured":"Cilium Authors. 2024. IPsec Transparent Encryption. Retrieved October 1, 2024 from https:\/\/docs.cilium.io\/en\/stable\/security\/network\/encryption-ipsec\/"},{"key":"e_1_3_2_1_28_1","volume-title":"Retrieved","author":"Community Confidential Containers","year":"2023","unstructured":"Confidential Containers Community. 2023. Enclave-cc. Retrieved October 15, 2023 from https:\/\/github.com\/confidential-containers\/enclave-cc"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-63089-8_9"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560627"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3623393.3623391"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/IEEECloudSummit52029.2021.00008"},{"key":"e_1_3_2_1_33_1","unstructured":"Paul DuBois and Michael Widenius. 2000. MySQL. New Riders Indianapolis IN."},{"key":"e_1_3_2_1_34_1","volume-title":"Retrieved","author":"Systems Edgeless","year":"2023","unstructured":"Edgeless Systems. 2023. MarbleRun: The Easiest Way to Orchestrate Enclaves. Retrieved October 15, 2023 from https:\/\/www.edgeless.systems\/products\/marblerun\/"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-44709-1_21"},{"key":"e_1_3_2_1_36_1","volume-title":"Retrieved","year":"2024","unstructured":"Google. 2024. Multi-Tenancy Overview. Retrieved September 29, 2024 from https:\/\/cloud.google.com\/kubernetes-engine\/docs\/concepts\/multitenancy-overview"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3065913.3065915"},{"key":"e_1_3_2_1_38_1","volume-title":"Benchmarking Serverless Workloads on Kubernetes. In 2021 IEEE\/ACM 21st International Symposium on Cluster, Cloud and Internet Computing. 704\u2013712","author":"Govind Hima","year":"2021","unstructured":"Hima Govind and Horacio Gonz\u00e1lez-V\u00e9lez. 2021. Benchmarking Serverless Workloads on Kubernetes. In 2021 IEEE\/ACM 21st International Symposium on Cluster, Cloud and Internet Computing. 704\u2013712."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-39828-5_17"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3050748.3050763"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/2487726.2488370"},{"key":"e_1_3_2_1_42_1","volume-title":"Applied Cryptography and Network Security","author":"Hu Yih-Chun","unstructured":"Yih-Chun Hu, Markus Jakobsson, and Adrian Perrig. 2005. Efficient Constructions for One-Way Hash Chains. In Applied Cryptography and Network Security. Springer, 423\u2013441."},{"key":"e_1_3_2_1_43_1","volume-title":"Retrieved","year":"2018","unstructured":"Intel. 2018. Intel Software Guard Extensions (Intel SGX) Developer Guide. Retrieved June 30, 2022 from https:\/\/software.intel.com\/content\/www\/us\/en\/develop\/download\/intel-software-guard-extensions-intel-sgx-developer-guide.html"},{"key":"e_1_3_2_1_44_1","volume-title":"Intel Trust Domain Extensions. Retrieved","year":"2022","unstructured":"Intel. 2021. Intel Trust Domain Extensions. Retrieved July 2, 2022 from https:\/\/cdrdv2.intel.com\/v1\/dl\/getContent\/690419"},{"key":"e_1_3_2_1_45_1","volume-title":"Intel TDX Connect TEE-IO Device Guide. Retrieved","year":"2023","unstructured":"Intel. 2023. Intel TDX Connect TEE-IO Device Guide. Retrieved December 9, 2023 from https:\/\/cdrdv2-public.intel.com\/772642\/whitepaper-tee-io-device-guide-v0-6-5.pdf"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICEIB57887.2023.10170110"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/3434770.3459730"},{"key":"e_1_3_2_1_48_1","volume-title":"Parma: Confidential Containers via Attested Execution Policies. arXiv:2302.03976 [cs.CR]","author":"Johnson Matthew A.","year":"2023","unstructured":"Matthew A. Johnson, Stavros Volos, Ken Gordon, Sean T. Allen, Christoph M. Wintersteiger, Sylvan Clebsch, John Starks, and Manuel Costa. 2023. Parma: Confidential Containers via Attested Execution Policies. arXiv:2302.03976 [cs.CR]"},{"key":"e_1_3_2_1_49_1","volume-title":"Feb","author":"Kaplan David","year":"2017","unstructured":"David Kaplan. 2017. Protecting VM Register State with SEV-ES. White paper, Feb (2017)."},{"key":"e_1_3_2_1_50_1","volume-title":"High Availability Storage Server with Kubernetes. In 2020 International Conference on Information Technology Systems and Innovation. IEEE, 74\u201378","author":"Khatami Ali Akbar","year":"2020","unstructured":"Ali Akbar Khatami, Yudha Purwanto, and Muhammad Faris Ruriawan. 2020. High Availability Storage Server with Kubernetes. In 2020 International Conference on Information Technology Systems and Innovation. IEEE, 74\u201378."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2023.3259801"},{"key":"e_1_3_2_1_52_1","first-page":"4","article-title":"Paxos Made Simple","volume":"32","author":"Lamport Leslie","year":"2001","unstructured":"Leslie Lamport. 2001. Paxos Made Simple. ACM SIGACTNews (Distributed Computing Column) 32, 4 (WholeNumber 121, December 2001) (2001), 51\u201358.","journal-title":"ACM SIGACTNews (Distributed Computing Column)"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.5555\/3241189.3241233"},{"key":"e_1_3_2_1_54_1","volume-title":"2023 USENIX Annual Technical Conference. 1\u201315","author":"Li Dingji","year":"2023","unstructured":"Dingji Li, Zeyu Mi, Chenhui Ji, Yifan Tan, Binyu Zang, Haibing Guan, and Haibo Chen. 2023. Bifrost: Analysis and Optimization of Network I\/O Tax in Confidential Virtual Machines. In 2023 USENIX Annual Technical Conference. 1\u201315."},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485253"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.14778\/3583140.3583158"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274720"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2014.2320915"},{"key":"e_1_3_2_1_59_1","volume-title":"Retrieved","author":"Labs Loft","year":"2023","unstructured":"Loft Labs. 2023. Kiosk. Retrieved October 15, 2023 from https:\/\/github.com\/loft-sh\/kiosk"},{"key":"e_1_3_2_1_60_1","volume-title":"Retrieved","author":"Labs Loft","year":"2023","unstructured":"Loft Labs. 2023. Vcluster Homepage. Retrieved September 24, 2023 from https:\/\/www.vcluster.com"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-59851-8_20"},{"key":"e_1_3_2_1_62_1","volume-title":"17th USENIX Symposium on Operating Systems Design and Implementation. 155\u2013172","author":"Mai Haohui","year":"2023","unstructured":"Haohui Mai, Jiacheng Zhao, Hongren Zheng, Yiyang Zhao, Zibin Liu, Mingyu Gao, Cong Wang, Huimin Cui, Xiaobing Feng, and Christos Kozyrakis. 2023. Honeycomb: Secure and Efficient GPU Executions via Static Validation. In 17th USENIX Symposium on Operating Systems Design and Implementation. 155\u2013172."},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"crossref","unstructured":"Philippe Martin and Philippe Martin. 2021. Observability. 175\u2013183.","DOI":"10.1007\/978-1-4842-6494-2_14"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4842-6494-2"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.5555\/2831143.2831198"},{"key":"e_1_3_2_1_66_1","volume-title":"Proceedings of the 26th USENIX Security Symposium. 1289\u20131306","author":"Matetic Sinisa","year":"2017","unstructured":"Sinisa Matetic, Mansoor Ahmed, Kari Kostiainen, Aritra Dhar, David Sommer, Arthur Gervais, Ari Juels, and Srdjan Capkun. 2017. ROTE: Rollback Protection for Trusted Execution. In Proceedings of the 26th USENIX Security Symposium. 1289\u20131306."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/2487726.2488368"},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1051\/epjconf\/202024507025"},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2013.05.179"},{"key":"e_1_3_2_1_70_1","volume-title":"Retrieved","author":"Multicluster Special Interest Group","year":"2023","unstructured":"Multicluster Special Interest Group. 2023. Github Pages about Kubernetes Multi-Cluster. Retrieved September 24, 2023 from https:\/\/github.com\/kubernetes\/community\/tree\/master\/sig-multicluster"},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1109\/APCC55198.2022.9943782"},{"key":"e_1_3_2_1_72_1","volume-title":"2014 USENIX Annual Technical Conference. 305\u2013319","author":"Ongaro Diego","year":"2014","unstructured":"Diego Ongaro and John Ousterhout. 2014. In Search of an Understandable Consensus Algorithm. In 2014 USENIX Annual Technical Conference. 305\u2013319."},{"key":"e_1_3_2_1_73_1","unstructured":"Nigel Poulton. 2023. The Kubernetes Book. NIGEL POULTON LTD."},{"key":"e_1_3_2_1_74_1","unstructured":"Christian Priebe Divya Muthukumaran Joshua Lind Huanzhou Zhu Shujie Cui Vasily A Sartakov and Peter Pietzuch. 2019. SGX-LKL: Securing the Host OS Interface for Trusted Execution. (2019). arXiv:1908.11143 [cs.CR]"},{"key":"e_1_3_2_1_75_1","first-page":"2024","volume-title":"Retrieved","author":"Future Recorded","year":"2024","unstructured":"Recorded Future, Inc. 2024. CVE-2024-21376. Retrieved September 29, 2024 from https:\/\/www.recordedfuture.com\/vulnerability-database\/CVE-2024-21376CVE-2024-21376"},{"key":"e_1_3_2_1_76_1","first-page":"2024","volume-title":"Retrieved","author":"Future Recorded","year":"2024","unstructured":"Recorded Future, Inc. 2024. CVE-2024-21400. Retrieved September 29, 2024 from https:\/\/www.recordedfuture.com\/vulnerability-database\/CVE-2024-21400CVE-2024-21400"},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"crossref","unstructured":"Eric Rescorla. 2000. HTTP over TLS. Technical Report.","DOI":"10.17487\/rfc2818"},{"key":"e_1_3_2_1_78_1","volume-title":"RESTful Web Services","author":"Richardson Leonard","unstructured":"Leonard Richardson and Sam Ruby. 2008. RESTful Web Services. O'Reilly Media, Inc."},{"key":"e_1_3_2_1_79_1","volume-title":"Security Analysis of Confidential-Compute Instruction Set Architecture for Virtualized Workloads. In 2021 International Symposium on Secure and Private Execution Environment Design. 121\u2013131","author":"Sahita Ravi","year":"2021","unstructured":"Ravi Sahita, Dror Caspi, Barry Huntley, Vincent Scarlata, Baruch Chaikin, Siddhartha Chhabra, Arie Aharon, and Ido Ouziel. 2021. Security Analysis of Confidential-Compute Instruction Set Architecture for Virtualized Workloads. In 2021 International Symposium on Secure and Private Execution Environment Design. 121\u2013131."},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1109\/PROC.1975.9939"},{"key":"e_1_3_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60876-1_1"},{"key":"e_1_3_2_1_82_1","unstructured":"Scontain. 2024. Scone and Kubernetes. Retrieved February 7 2024 from https:\/\/sconedocs.github.io\/k8s_concepts"},{"key":"e_1_3_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2023.06.022"},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378469"},{"key":"e_1_3_2_1_85_1","volume-title":"Retrieved","author":"Systems Edgeless","year":"2023","unstructured":"Edgeless Systems. 2023. Constellation: The World's Most Secure Kubernetes. Retrieved September 24, 2023 from https:\/\/docs.edgeless.systems\/constellation"},{"key":"e_1_3_2_1_86_1","volume-title":"Retrieved","author":"Systems Edgeless","year":"2024","unstructured":"Edgeless Systems. 2024. Scale Your Cluster. Retrieved September 29, 2024 from https:\/\/docs.edgeless.systems\/constellation\/workflows\/scale"},{"key":"e_1_3_2_1_87_1","volume-title":"Retrieved","author":"Community The Capsule","year":"2023","unstructured":"The Capsule Community. 2023. Capsule. Retrieved October 15, 2023 from https:\/\/github.com\/projectcapsule\/capsule"},{"key":"e_1_3_2_1_88_1","volume-title":"Retrieved","author":"Authors The","year":"2023","unstructured":"The etcd Authors. 2023. Etcd: A Distributed, Reliable Key-Value Store for the Most Critical Data of a Distributed System. Retrieved September 24, 2023 from https:\/\/etcd.io"},{"key":"e_1_3_2_1_89_1","volume-title":"Three Tenancy Models For Kubernetes. Retrieved Match 3","author":"Authors The Kubernetes","year":"2025","unstructured":"The Kubernetes Authors. 2021. Three Tenancy Models For Kubernetes. Retrieved Match 3, 2025 from https:\/\/kubernetes.io\/blog\/2021\/04\/15\/three-tenancy-models-for-kubernetes\/"},{"key":"e_1_3_2_1_90_1","volume-title":"Retrieved","author":"Authors The Kubernetes","year":"2023","unstructured":"The Kubernetes Authors. 2023. Kubernetes Documents: Container Runtime Interface. Retrieved September 24, 2023 from https:\/\/kubernetes.io\/docs\/concepts\/architecture\/cri\/"},{"key":"e_1_3_2_1_91_1","volume-title":"Kubernetes Documents: kube-apiserver. Retrieved","author":"Authors The Kubernetes","year":"2023","unstructured":"The Kubernetes Authors. 2023. Kubernetes Documents: kube-apiserver. Retrieved October 8, 2023 from https:\/\/kubernetes.io\/docs\/reference\/command-line-tools-reference\/kube-apiserver\/"},{"key":"e_1_3_2_1_92_1","volume-title":"Kubernetes Documents: Kubernetes API. Retrieved","author":"Authors The Kubernetes","year":"2023","unstructured":"The Kubernetes Authors. 2023. Kubernetes Documents: Kubernetes API. Retrieved October 8, 2023 from https:\/\/kubernetes.io\/docs\/reference\/kubernetes-api\/"},{"key":"e_1_3_2_1_93_1","volume-title":"Kubernetes Documents: Leases. Retrieved","author":"Authors The Kubernetes","year":"2023","unstructured":"The Kubernetes Authors. 2023. Kubernetes Documents: Leases. Retrieved October 5, 2023 from https:\/\/kubernetes.io\/docs\/concepts\/architecture\/leases\/"},{"key":"e_1_3_2_1_94_1","volume-title":"Retrieved","author":"Authors The Kubernetes","year":"2023","unstructured":"The Kubernetes Authors. 2023. Kubernetes Documents: Multi-Tenancy. Retrieved September 24, 2023 from https:\/\/kubernetes.io\/docs\/concepts\/security\/multi-tenancy"},{"key":"e_1_3_2_1_95_1","volume-title":"Kubernetes Documents: Pod API. Retrieved","author":"Authors The Kubernetes","year":"2023","unstructured":"The Kubernetes Authors. 2023. Kubernetes Documents: Pod API. Retrieved October 5, 2023 from https:\/\/kubernetes.io\/docs\/reference\/kubernetes-api\/workload-resources\/pod-v1\/"},{"key":"e_1_3_2_1_96_1","volume-title":"Kubernetes Documents: Volumes. Retrieved","author":"Authors The Kubernetes","year":"2023","unstructured":"The Kubernetes Authors. 2023. Kubernetes Documents: Volumes. Retrieved October 8, 2023 from https:\/\/kubernetes.io\/docs\/concepts\/storage\/volumes"},{"key":"e_1_3_2_1_97_1","volume-title":"Network Policies. Retrieved","author":"Authors The Kubernetes","year":"2024","unstructured":"The Kubernetes Authors. 2024. Network Policies. Retrieved October 1, 2024 from https:\/\/kubernetes.io\/docs\/concepts\/services-networking\/network-policies\/"},{"key":"e_1_3_2_1_98_1","volume-title":"Retrieved","author":"Community The Kubernetes","year":"2023","unstructured":"The Kubernetes Community. 2023. The Hierarchical Namespace Controller (HNC). Retrieved October 15, 2023 from https:\/\/github.com\/kubernetes-sigs\/hierarchical-namespaces"},{"key":"e_1_3_2_1_99_1","doi-asserted-by":"publisher","DOI":"10.1145\/3419111.3421273"},{"key":"e_1_3_2_1_100_1","volume-title":"Proceedings of the 2017 USENIX Annual Technical Conference. 645\u2013658","author":"Tsai Chia-Che","year":"2017","unstructured":"Chia-Che Tsai, Donald E Porter, and Mona Vij. 2017. Graphene-SGX: A Practical Library OS for Unmodified Applications on SGX. In Proceedings of the 2017 USENIX Annual Technical Conference. 645\u2013658."},{"key":"e_1_3_2_1_101_1","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670352"},{"key":"e_1_3_2_1_102_1","volume-title":"Proceedings of the 26th USENIX Security Symposium. 1041\u20131056","author":"Bulck Jo Van","year":"2017","unstructured":"Jo Van Bulck, Nico Weichbrodt, R\u00fcdiger Kapitza, Frank Piessens, and Raoul Strackx. 2017. Telling Your Secrets without Page Faults: Stealthy Page Table-Based Attacks on Enclaved Execution. In Proceedings of the 26th USENIX Security Symposium. 1041\u20131056."},{"key":"e_1_3_2_1_103_1","volume-title":"SGX-Aware Container Orchestration for Heterogeneous Clusters. In 2018 IEEE 38th International Conference on Distributed Computing Systems. 730\u2013741","author":"Vaucher S\u00e9bastien","year":"2018","unstructured":"S\u00e9bastien Vaucher, Rafael Pires, Pascal Felber, Marcelo Pasin, Valerio Schiavoni, and Christof Fetzer. 2018. SGX-Aware Container Orchestration for Heterogeneous Clusters. In 2018 IEEE 38th International Conference on Distributed Computing Systems. 730\u2013741."},{"key":"e_1_3_2_1_104_1","volume-title":"Microservice Based Architecture: Towards High-Availability for Stateful Applications with Kubernetes. In IEEE 19th International Conference on Software Quality, Reliability and Security. IEEE, 176\u2013185","author":"Vayghan Leila Abdollahi","year":"2019","unstructured":"Leila Abdollahi Vayghan, Mohamed Aymen Saied, Maria Toeroe, and Ferhat Khendek. 2019. Microservice Based Architecture: Towards High-Availability for Stateful Applications with Kubernetes. In IEEE 19th International Conference on Software Quality, Reliability and Security. IEEE, 176\u2013185."},{"key":"e_1_3_2_1_105_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560639"},{"key":"e_1_3_2_1_106_1","volume-title":"RSDS: Getting System Call Whitelist for Container Through Dynamic and Static Analysis. In 2020 IEEE 13th International Conference on Cloud Computing. 600\u2013608","author":"Wang Xuhao","year":"2020","unstructured":"Xuhao Wang, Qingni Shen, Wu Luo, and Pengfei Wu. 2020. RSDS: Getting System Call Whitelist for Container Through Dynamic and Static Analysis. In 2020 IEEE 13th International Conference on Cloud Computing. 600\u2013608."},{"key":"e_1_3_2_1_107_1","volume-title":"Retrieved","author":"Watch Stack","year":"2024","unstructured":"Stack Watch. 2024. Recent Microsoft Azure Kubernetes Service Security Advisories. Retrieved September 29, 2024 from https:\/\/stack.watch\/product\/microsoft\/azure-kubernetes-service\/"},{"key":"e_1_3_2_1_108_1","volume-title":"Beware of Fragmentation: Scheduling GPU-Sharing Workloads with Fragmentation Gradient Descent. In 2023 USENIX Annual Technical Conference. 995\u20131008","author":"Weng Qizhen","year":"2023","unstructured":"Qizhen Weng, Lingyun Yang, Yinghao Yu, Wei Wang, Xiaochuan Tang, Guodong Yang, and Liping Zhang. 2023. Beware of Fragmentation: Scheduling GPU-Sharing Workloads with Fragmentation Gradient Descent. In 2023 USENIX Annual Technical Conference. 995\u20131008."},{"key":"e_1_3_2_1_109_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00080"},{"key":"e_1_3_2_1_110_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.45"},{"key":"e_1_3_2_1_111_1","volume-title":"Retrieved","author":"Li Yong","year":"2023","unstructured":"Yong Li, Helen Liu. 2023. K-Bench. Retrieved October 15, 2023 from https:\/\/github.com\/vmware-tanzu\/k-bench"},{"key":"e_1_3_2_1_112_1","volume-title":"Proceedings of the 2018 IEEE Symposium on Security and Privacy. 229\u2013244","author":"Zhao Mark","unstructured":"Mark Zhao and G. Edward Suh. 2018. FPGA-Based Remote Power Side-Channel Attacks. In Proceedings of the 2018 IEEE Symposium on Security and Privacy. 229\u2013244."},{"key":"e_1_3_2_1_113_1","doi-asserted-by":"publisher","DOI":"10.1145\/1508293.1508297"},{"key":"e_1_3_2_1_114_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS51616.2021.00042"}],"event":{"name":"EUROSYS '26: 21st European Conference on Computer Systems","location":"McEwan Hall\/The University of Edinburgh Edinburgh Scotland UK","acronym":"EUROSYS '26","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the 21st European Conference on Computer Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3767295.3769324","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T11:59:37Z","timestamp":1780660777000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3767295.3769324"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,26]]},"references-count":114,"alternative-id":["10.1145\/3767295.3769324","10.1145\/3767295"],"URL":"https:\/\/doi.org\/10.1145\/3767295.3769324","relation":{},"subject":[],"published":{"date-parts":[[2026,4,26]]},"assertion":[{"value":"2026-04-26","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}