Part 4 · 1 chapters · ~8 min

OCI Images and Runtimes

The OCI image, distribution and runtime specifications, manifests and digests, multi-architecture image indexes, tags versus digests, registries, containerd and CRI-O, runc and crun, the Container Runtime Interface, RuntimeClass, image signing (cosign) and SBOMs.

5

Specs, digests and runtimes

code
# an image manifest (abridged): everything is addressed by digest
{ "schemaVersion": 2, "mediaType": "application/vnd.oci.image.manifest.v1+json",
  "config": { "digest": "sha256:3b1f…", "size": 7023 },
  "layers": [ { "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip", "digest": "sha256:a8c1…", "size": 29123456 }, … ] }

crane manifest node:22-slim | jq '.manifests[].platform'     # an index: one manifest per architecture (amd64, arm64)
crane digest ghcr.io/acme/api:1.42.0                         # pin deploys to digests: tags can be moved
runc spec                                                    # generate a default config.json
sudo runc run demo                                           # run a bundle directly, no Docker involved
cosign sign ghcr.io/acme/api@sha256:…                        # sign; verify at admission (policy controllers)
syft ghcr.io/acme/api:1.42.0 -o spdx-json > sbom.json        # software bill of materials

Tags versus digests: a tag like :latest or :1.42 can be re-pointed; a digest cannot. Deploy by digest (or resolve tags to digests in CI) so what you tested is what runs.

FROM `kubectl apply` TO A RUNNING PROCESS
the standard layers under Kubernetes
kubeletpod specCRIcontainerd or CRI-Oregistrypull image by digestOCI bundlerootfs + config.jsonOCI runtimerunc, crun, runsc (gVisor), kataprocessnamespaces + cgroups
swipe the figure sideways, or tap expand for full screen
1/4
CRI
The kubelet talks to a container runtime through the Container Runtime Interface; containerd and CRI-O implement it. Docker Engine itself is no longer used by Kubernetes directly (dockershim removed in 1.24).
kubelet → CRIcontainerd or CRI-O