If one can give strong proof that everything done in a VM is encrypted, then would it be possible to create a "decentralized cloud provider", in which data center owners agree to a common spec for services?
Federated distributed computing relates to what you're thinking of, but it is an extremely difficult topic, and veers into the realm of blockchains and things like that. There is also the whole area of Zero-Knowledge Proofs/Compute that deals with these matters: https://eprint.iacr.org/2013/229.pdf
If your threat model falls under the uber-paranoid category, you have to on-prem everything, preferrably inside your very own bunker. There is no getting around this afaik, and if there is there will probably be major tradeoffs (like the blockchain thingy) instead of a "drop-in" replacement for traditional compute.
https://www.microsoft.com/en-us/research/publication/shieldi...