Welcome to Optimizing Container Runtimes with containerd and runc. When developers think of containers, they usually think of Docker. However, in modern orchestration environments like Kubernetes, the heavy Docker daemon is often bypassed entirely in favor of lightweight, purpose-built runtimes.
1. The Container Runtime Interface (CRI)
Kubernetes uses the Container Runtime Interface (CRI) to communicate with the node's underlying container technology. Because the Docker daemon historically did not support CRI natively, Kubernetes had to use an adapter (dockershim). This added overhead and complexity.
2. Moving to containerd
To solve this, the container community standardized around containerd. Originally a sub-component of Docker, containerd was spun out as an independent, lightweight daemon that implements the CRI directly. It handles image transfer and storage, container execution, and network attachment, without the bloated developer-facing features of the full Docker engine.
3. The Low-Level Execution: runc
But containerd doesn't actually create the container. It delegates the actual creation of the Linux cgroups and namespaces to an OCI (Open Container Initiative) compliant low-level runtime, typically runc.
When containerd wants to start a container, it unpacks the image into an OCI bundle and passes it to runc. runc interfaces directly with the Linux kernel to sandbox the process, then exits, leaving a lightweight shim process behind to monitor the container.
4. Alternative Low-Level Runtimes (gVisor/Kata)
Because containerd conforms to standard interfaces, you can swap out runc for more secure runtimes. For multi-tenant hosting, you might use Google's gVisor (runsc), which intercepts syscalls to prevent container escapes, or Kata Containers, which wraps each container in a hardware-virtualized micro-VM.
Conclusion
Understanding the stackβKubernetes -> CRI -> containerd -> runc/gVisor -> Kernelβis essential for optimizing node density, reducing memory overhead, and architecting secure multi-tenant cloud environments.