Part 4 · 1 chapters · ~8 min
OCI Images and Runtimes
The OCI image, distribution and runtime specifications, manifests and digests, multi-architecture image indexes, tags versus digests, registries, containerd and CRI-O, runc and crun, the Container Runtime Interface, RuntimeClass, image signing (cosign) and SBOMs.
5
Specs, digests and runtimes
code
# an image manifest (abridged): everything is addressed by digest
{ "schemaVersion": 2, "mediaType": "application/vnd.oci.image.manifest.v1+json",
"config": { "digest": "sha256:3b1f…", "size": 7023 },
"layers": [ { "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip", "digest": "sha256:a8c1…", "size": 29123456 }, … ] }
crane manifest node:22-slim | jq '.manifests[].platform' # an index: one manifest per architecture (amd64, arm64)
crane digest ghcr.io/acme/api:1.42.0 # pin deploys to digests: tags can be moved
runc spec # generate a default config.json
sudo runc run demo # run a bundle directly, no Docker involved
cosign sign ghcr.io/acme/api@sha256:… # sign; verify at admission (policy controllers)
syft ghcr.io/acme/api:1.42.0 -o spdx-json > sbom.json # software bill of materialsTags versus digests: a tag like :latest or :1.42 can be re-pointed; a digest cannot. Deploy by digest (or resolve tags to digests in CI) so what you tested is what runs.
FROM `kubectl apply` TO A RUNNING PROCESS
the standard layers under Kubernetes
swipe the figure sideways, or tap expand for full screen
1/4
CRI
The kubelet talks to a container runtime through the Container Runtime Interface; containerd and CRI-O implement it. Docker Engine itself is no longer used by Kubernetes directly (dockershim removed in 1.24).
kubelet → CRIcontainerd or CRI-O