A computer-implemented method whereby confidential computing control service CCCS 500 automatically controls an execution of workloads on trusted execution environments TEEs 510 while enforcing compliance with constraints required by entities 504. CCCS 500 may be on a
server and TEEs may ne n a cloud. The method comprises: receiving constraints for the execution of a
workload from the entities; automatically generating an execution requirement (e.g. a contract) for controlling the trusted execution environments using the received constraints, the requirement defining execution parameters of the
workload in compliance with the constraints; the generating comprising adding identifiers of the constraints (e.g. checksums of the constraints) to the requirement for an attestation of the constraints being complied with by the trusted executing environments; controlling the trusted execution environments in compliance with the execution requirement, the environments being enabled to provide attestation records for the execution of the
workload comprising the identifiers of the constraints. Execution requirements may relate to: sections of a document being encrypted independently; description of the environment to execute an application, e.g.
logging, virtual machines; data volumes; seeds for deriving
encryption passphrases; cryptographic keys. Constraints are checked for conflicts and detected conflicts are resolved. Each entity 506 relates to developing, managing and deploying services, e.g. KUBERNETES (RTM) K8s for orchestrating workloads in containers.