When you want to start or stop a container with Kubernetes, Kubernetes talks to CRI-O, and CRI-O talks to an OCI-compliant container runtime such as runc for Docker to start a container. CRI-O can also pull OCI-compliant container images and manage them on a disk. Good news for Container Developers—they do not need to work with CRI-O directly, as Kubernetes handles that automatically. But it is important to understand the concept and overall architecture:
data:image/s3,"s3://crabby-images/cd516/cd51613ca9c0e211d6f1a42114b6535243bcffd9" alt=""
CRI-O architecture
To sum this up, there are a few things to note before we go to the hands-on part and install CRI-O in our lab:
- Kubernetes is configured to talk to CRI-O to launch a new Pod in a container environment
- CRI-O pulls the OCI-compliant Container Image, if necessary, from a registry and manages it locally
- CRI-O talks to OCI-compliant Container Runtime (runc, by default) to...