Kubernetes Container Runtime Concepts

From NovaOrdis Knowledge Base
Jump to: navigation, search



Container Runtime Interface (CRI)

The Container Runtime Interface (CRI) is an abstraction layer that standardizes the way third-party container runtimes interface with Kubernetes. Irrespective of the container runtime in use (Docker, containerd, CRI-O, the regular Kubernetes commands and patterns apply. CRI exposes a clean documented interface for third-party container runtimes to plug in to.

Container Runtime Interface and Container Metrics


Among other functions, CRI exposes container resource metrics to the kubelet.

Container Runtime

Each Kubernetes node runs a container runtime, usually Docker. However, support for other container runtimes is available, via Container Runtime Interface (CRI). The kubelet gets work (pod) assignments from the control plane but delegates the job of running the containers to the container runtime. A container runtime performs container-related tasks such as pulling images and starting and stopping containers.

Container Runtimes


Kubernetes and Docker are complementary technologies. Docker is the technology that starts and stops containers under Kubernetes' supervision. Kubernetes is the higher-level technology that decides which nodes to run containers on, when to scale an application up or down or when to apply updates. Docker can run without Kubernetes and Kubernetes can run without Docker.



A container runtime that consists in a stripped-down version of Docker. More details:

AKS clusters based on Kubernetes 1.19+ use containerd as their container runtime.


A community-based Open Source port of containerd.



Runtime Classes

Runtime classes is a feature that was introduced in Kubernetes 1.2. It allows for different classes of runtimes (gVisor, Kata Containers, etc).