I would like to present "IBM Secure Execution" feature for RedHat CoreOS. "IBM Secure Execution" is a hardware based security solution first introduced with IBM z15 and LinuxONE III. It protects KVM Guests and their data from being accessed by hardware/KVM administrators or KVM code. With OCP 4.12 IBM and RedHat are releasing for the first time a Tech Preview of Secure Execution with RedHat CoreOS. This not only implements Secure Execution inside RedHat OpenShift (OCP), but instead offers an out of the box solution to enhancing the security of customers OCP Clusters. During the presentation I'll present: - what "Secure Execution" is - how it works in Linux - what kind of challenges we faced during its development for CoreOS and OCP 4.12 - what's next?