Commit Graph

475 Commits

Author SHA1 Message Date
Derek McGowan
61b8426ae1 Add mount manager documentation
Signed-off-by: Derek McGowan <derek@mcg.dev>
2025-09-29 17:08:36 -07:00
Mike Brown
9aebe599ec Merge pull request #12217 from klihub/devel/main/update-nri
nri: update NRI to v0.10.0.
2025-08-22 17:37:09 +00:00
Krisztian Litkey
ad207c1ce3 docs: update docs for NRI v0.10.0.
Added v0.1.0 plugin support to the list of deprecated features in
RELEASES.md. Added a chapter about how to enable and configure the
default validator plugin in NRI.md

Signed-off-by: Krisztian Litkey <krisztian.litkey@intel.com>
2025-08-22 13:11:15 +03:00
Akihiro Suda
1321cbc7b6 Merge pull request #12025 from dmcgowan/gc-reverse-ref
Add support for back references in the garbage collector
2025-08-22 04:45:55 +00:00
Divya Rani
37b12bf5e2 Add documentation for cgroup_writable field
Signed-off-by: Divya Rani <ranidivya063@gmail.com>
2025-08-22 07:01:38 +05:30
Akihiro Suda
a92d8700bf Merge pull request #12085 from akhilerm/pause-3.10.1
update pause image to pause:3.10.1
2025-07-15 06:12:20 +00:00
Akhil Mohan
222b2d3e72 update pause image to pause:3.10.1
Signed-off-by: Akhil Mohan <akhilerm@gmail.com>
2025-07-11 11:29:02 +05:30
Gao Xiang
e96ebc0085 erofs-snapshotter: make IMMUTABLE_FL optional
Enabling the IMMUTABLE_FL file attribute causes dirty data to be
flushed synchronously at least on EXT4, which can greatly impact
container launch performance.  In contrast, the overlayfs snapshotter
does not use syncfs by default.

Most users may not need IMMUTABLE_FL, let's make IMMUTABLE_FL optional
to align with the behavior of the overlayfs snapshotter and recover the
original performance.

1. tensorflow

Test commands:
$ nerdctl image pull --snapshotter=X --unpack="false" tensorflow/tensorflow:2.19.0
$ time nerdctl container --snapshotter=X run -d tensorflow/tensorflow:2.19.0 /bin/sh

Results:
 overlayfs                 | 0m18.748s
 erofs (no IMMUTABLE_FL)   | 0m10.090s
 erofs (with IMMUTABLE_FL) | 0m21.074s

2. ubuntu 22.04

Test commands:
$ nerdctl image pull --snapshotter=X --unpack="false" ubuntu:22.04
$ time nerdctl container --snapshotter=X run -d ubuntu:22.04 /bin/sh

Results:
 overlayfs                 | 0m1.147s
 erofs (no IMMUTABLE_FL)   | 0m0.795s
 erofs (with IMMUTABLE_FL) | 0m1.094s

Signed-off-by: Gao Xiang <hsiangkao@linux.alibaba.com>
2025-07-11 02:56:37 +08:00
Aadhar Agarwal
b641933cfa erofs snapshotter: Add tar index mode
Signed-off-by: Aadhar Agarwal <aadagarwal@microsoft.com>

Minor style updates to erofs.md and differ_linux.go

Signed-off-by: Aadhar Agarwal <aadagarwal@microsoft.com>

Add use case for tar index in erofs.md

Signed-off-by: Aadhar Agarwal <aadagarwal@microsoft.com>
2025-07-08 21:44:49 +00:00
Gao Xiang
a0ed14fd48 erofs-differ: fix filesystem UUID for tar-converted layers
Derive filesystem UUIDs (`lsblk -o +UUID`) from the OCI layer digests
(although diffIDs are better in principle, but they're unavailable by
differs in advance) rather than generating a random one.  This allows
EROFS to uniquely identify each layer using the content-addressable
filesystem UUID.

It can also be used for reproducible builds. To achieve this, configure
`mkfs_options` with `-T0 --mkfs-time` (However, `--mkfs-time` requires
erofs-utils 1.8+; Otherwise, all inode timestamps will be reset w/o it):

``` toml
  [plugins."io.containerd.differ.v1.erofs"]
    mkfs_options = ["-T0 --mkfs-time"]
```

Fixes: c73c8e5d52 ("Introduce EROFS differ")
Signed-off-by: Gao Xiang <hsiangkao@linux.alibaba.com>
2025-07-02 08:25:50 +08:00
Derek McGowan
610f299141 Update garbage collection docs
Signed-off-by: Derek McGowan <derek@mcg.dev>
2025-06-24 17:02:38 -07:00
Gao Xiang
ee5ad982f3 docs/snapshotters/erofs.md: a tip for improved performance
It's preferred to use `--sort=none` to avoid tar data twice due to
stricter data ordering.

Link: https://git.kernel.org/xiang/erofs-utils/c/e97530622872
Signed-off-by: Gao Xiang <xiang@kernel.org>
2025-05-14 07:55:53 +08:00
Derek McGowan
5a3bbca1bb Merge pull request #11724 from swagatbora90/cri-image-transfer-doc-update
Update CRI documentation to add information about Image Pull with Transfer Service
2025-05-06 22:51:40 +00:00
Rodrigo Campos
ce73e1b3e9 docs: Run userns example in /tmp
This simplifies the permissions. If it's run on the home, some distros
make the /home/user dir with just permissions for the owner, but we
need +x permissions for others (technically for host user the container
is mapped to, but that is more tricky in this example).

/tmp has the right permissions already, so let's just do the example
there.

While we are there, I just copied the two commands from the runc doc, to
create the rootfs, instead of linking there. Also, I changed the
config.json to include the right path, now that is known.

Having the path fixed makes sure users can't do a mistake when setting
it. This was the cause of #11575 (they were not setting the rootfs as an
absolute path, as documented).

Signed-off-by: Rodrigo Campos <rodrigoca@microsoft.com>
2025-04-24 12:53:47 +02:00
Rodrigo Campos
882b1903cc docs: Fix typo in userns example
Signed-off-by: Rodrigo Campos <rodrigoca@microsoft.com>
2025-04-24 12:53:47 +02:00
Rodrigo Campos
b62339f399 docs: Fix typos to run userns with ctr
While we are there, bash should not be the process, it should be sh. In
the bare-bone image used in the example, bash is not present (or not
present anymore?).

Signed-off-by: Rodrigo Campos <rodrigoca@microsoft.com>
2025-04-24 12:53:47 +02:00
Tony Fang
b694be29a0 Update CRI image service to pull using transfer service
- adds a transfer service progress reporter to handle timeouts. Also other test fixes
- fallback to local image pull when configuration conflict

Signed-off-by: Tony Fang <nhfang@amazon.com>

Co-authored-by: Swagat Bora <sbora@amazon.com>
2025-04-23 18:18:27 +00:00
Swagat Bora
21a6db1b38 Update CRI documentation to add information about Image Pull with Transfer Service
Signed-off-by: Swagat Bora <sbora@amazon.com>
2025-04-22 16:42:05 +00:00
Marco Visin
c1026d5bf6 Fixing install instructions for Windows
Fixing install script to allow using arm64 architecture

Signed-off-by: Marco Visin <marco@visin.ch>
2025-04-14 16:17:09 +02:00
Jin Dong
42effa3b91 Mark NetworkPluginBinDir as DEPRECATED
To make it as DEPRECATED, this PR does the following:

1. Changes config default to use `NetworkPluginBinDirs`;
2. Mark `NetworkPluginBinDir` as deprecated (in config version 3);
3. Add config migration from 2 to 3, which migrates `bin_dir`
  in version 2 to `bin_dirs` in version 3.

Signed-off-by: Jin Dong <djdongjin95@gmail.com>

[wip] add deprecation warning

Signed-off-by: Jin Dong <djdongjin95@gmail.com>
2025-03-21 16:59:32 +00:00
Jin Dong
71f593d4a2 Support multiple CNI plugin bin dirs
Signed-off-by: Jin Dong <djdongjin95@gmail.com>
2025-03-20 17:13:34 +00:00
Philip Laine
c4982bffc6 Add dial timeout field to hosts toml configuration
Signed-off-by: Philip Laine <philip.laine@gmail.com>
2025-03-13 23:33:53 -07:00
Samuel Karp
edd1cc50d5 docs: include note about unprivileged sysctls
We changed the default setting for `enable_unprivileged_ports` and
`enable_unprivileged_icmp` in the CRI plugin in
https://github.com/containerd/containerd/pull/9348, but missed including
this change in the release notes.

Signed-off-by: Samuel Karp <samuelkarp@google.com>
2025-03-06 16:38:38 -08:00
Phil Estes
4ed9adb86b Merge pull request #11402 from z63d/docs/add-cri-plugin-config-runtime-path
docs: add CRI Plugin Config runtime_path
2025-03-05 21:19:24 +00:00
Gao Xiang
971915797a erofs-snapshotter: force the use of loop devices for single-layer images
Currently, containerd cannot dynamically select between EROFS block
or file-based mounting approaches based on the specific runtime (or
the Linux kernel version of the runtime) due to its static mount
structure.

For example, the EROFS snapshotter fails on Linux 5.4 (Ubuntu 20.04)
with `bin/nerdctl run --net=host --snapshotter=erofs busybox:latest`:

FATA[0005] failed to mount {Type:erofs Source:/var/lib/containerd/
io.containerd.snapshotter.v1.erofs/snapshots/1/layer.erofs Target:
Options:[ro]} on "/tmp/initialC1374142795": block device required

Temporarily fix this by appending `-oloop` for single-layer images.
The upcoming mount manager will make it better [1].

[1] https://github.com/containerd/containerd/issues/11303
Signed-off-by: Gao Xiang <hsiangkao@linux.alibaba.com>
2025-03-04 17:07:01 +08:00
Gao Xiang
b477cf8e97 erofs-snapshotter: protect layer blobs with FS_IMMUTABLE_FL
As documented in ioctl_iflags(2):
```
 FS_IMMUTABLE_FL
  The file is immutable: no changes are permitted to the file contents
  or metadata (permissions, timestamps, ownership, link count, and so
  on).  (This restriction applies even to the superuser.)
```

For example, any user cannot delete/move layer blobs when
FS_IMMUTABLE_FL is set:
``` sh
 # cd /var/lib/containerd/io.containerd.snapshotter.v1.erofs/snapshots/4
 # mv layer{,1}.erofs
 mv: cannot move 'layer.erofs' to 'layer1.erofs': Operation not permitted
 # rm layer.erofs
 rm: cannot remove 'layer.erofs': Operation not permitted
```

Note that it's a best-effort approach for data loss prevention.  IOWs,
just warn out if FS_IMMUTABLE_FL cannot be set anyway (e.g., due to lack
of support in the underlying filesystem.)

Signed-off-by: Gao Xiang <hsiangkao@linux.alibaba.com>
2025-03-03 20:11:48 +08:00
ChengyuZhu6
f3b6078f90 erofs-snapshotter: add fsverity support
Add fsverity support to erofs snapshotter to enable data integrity
verification for erofs layers:

- Add an config option `EnableFsverity` for erofs snapshotter
- Add fsverity verification during mount operations
- Enable fsverity on erofs layers during commit
- Add documentation for fsverity support in erofs snapshotter.
- Add TestErofsFsverity to verify fsverity enablement and data protection

The feature can be enabled via config.toml, such as:
```toml
[plugins.'io.containerd.snapshotter.v1.erofs']
    root_path = ''
    ovl_mount_options = []
    enable_fsverity = true
```

Signed-off-by: ChengyuZhu6 <hudson@cyzhu.com>
2025-02-25 10:33:26 +08:00
z63d
a1e7457bc4 docs: add CRI Plugin Config runtime_path
Signed-off-by: Kaita Nakamura <kaita.nakamura0830@gmail.com>
2025-02-19 06:16:24 +09:00
Jin Dong
a502b7931b Clarify port handling in hosts toml
Signed-off-by: Jin Dong <djdongjin95@gmail.com>
2025-02-17 16:50:15 +00:00
Gao Xiang
fd4caef786 Add EROFS snapshotter documentation
Signed-off-by: Gao Xiang <hsiangkao@linux.alibaba.com>
2025-01-13 16:31:21 +08:00
Amal Thundiyil
b78c5c6ed2 docs: fix snapshots api import
Signed-off-by: Amal Thundiyil <mail@amalthundiyil.com>
2024-11-28 12:13:07 +01:00
Samuel Karp
6c1b699bf9 docs: update schema 1 deprecation information
* Correctly reference the only schema 1 mediatype containerd supports.
* Document that `--local` is required for `ctr` when pulling schema 1
  images
* Document CRI users more clearly

Fixes https://github.com/containerd/containerd/issues/10998

Signed-off-by: Samuel Karp <samuelkarp@google.com>
2024-11-13 09:34:47 -08:00
Akihiro Suda
bf47b6ebc9 docs/containerd-2.0.md: add more highlights
- CRI support for user namespaces (PR 8803)
- CRI support for recursive read-only mounts (PR 9787)
- CDI is now enabled by default (PR 9621)

Co-authored-by: Samuel Karp <me@samuelkarp.com>
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
2024-11-02 06:27:18 +09:00
Akihiro Suda
f5ce859ee2 docs/containerd-2.0.md: fix the deprecation release of AUFS
AUFS was deprecated in v1.5, not in v1.7.
See PR 5433

Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
2024-11-02 06:19:04 +09:00
Samuel Karp
bc819bc97a docs: add command for finding schema 1 images
Signed-off-by: Samuel Karp <samuelkarp@google.com>
2024-10-22 20:44:51 -07:00
Samuel Karp
c86b2772ce docs: update min version for deprecation warnings
While some warnings were available in earlier versions, the first
"complete" implementation was in 1.7.12 and 1.6.27.

https://github.com/containerd/containerd/issues/9312 tracks that initial
set of warnings.

Signed-off-by: Samuel Karp <samuelkarp@google.com>
2024-10-22 15:57:26 -07:00
Austin Vazquez
92d327af17 Update tracing docs for containerd 2.0
Signed-off-by: Austin Vazquez <macedonv@amazon.com>
2024-10-18 14:50:05 +00:00
Akihiro Suda
d4cabf7179 Merge pull request #10852 from austinvazquez/update-nri-doc-for-2.0
Update NRI documentation for containerd 2.0
2024-10-18 12:12:40 +09:00
Austin Vazquez
943b196ad6 Update NRI documentation for containerd 2.0
Signed-off-by: Austin Vazquez <macedonv@amazon.com>
2024-10-17 23:33:04 +00:00
Samuel Karp
a6ceb4be0d containerd 2.0 guide: add image verifier plugins
Signed-off-by: Samuel Karp <samuelkarp@google.com>
2024-10-17 14:10:29 -07:00
Austin Vazquez
249dd74744 Format link text in containerd 2.0 doc for readability
Signed-off-by: Austin Vazquez <macedonv@amazon.com>
2024-10-17 17:11:13 +00:00
Akihiro Suda
3eea3536f1 docs/containerd-2.0.md: mention the removal of cri-containerd-*.tar.gz
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
2024-10-17 19:17:34 +09:00
Austin Vazquez
b724b9f231 Add containerd 2.0 doc
Signed-off-by: Austin Vazquez <macedonv@amazon.com>
2024-10-16 17:53:38 +00:00
Maksym Pavlenko
146a977f92 Move features section to a separate file
Signed-off-by: Maksym Pavlenko <pavlenko.maksym@gmail.com>
2024-09-26 15:32:16 -07:00
Akihiro Suda
a3d84a1727 docs: update for containerd v2
Fix issue 10132

Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
2024-08-16 03:09:50 +09:00
Paul Meyer
d036988eec docs/content-flow: fix code fence delimiter
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2024-08-05 12:55:48 +02:00
Avi Deitcher
1a5c711c3c update documentation for content-flow
Signed-off-by: Avi Deitcher <avi@deitcher.net>
2024-07-17 15:29:54 +03:00
bzsuni
22f2af40c0 update pause image to 3.10
Signed-off-by: bzsuni <bingzhe.sun@daocloud.io>
2024-05-25 08:17:46 +08:00
Mike Brown
87bab6cdc7 Merge pull request #10238 from MikeZappa87/feature/provideinternalloup
Add support to set loopback to up
2024-05-20 14:19:43 +00:00
Michael Zappa
332caf1a15 Provide ability to set lo up without CNI
Signed-off-by: Michael Zappa <michael.zappa@gmail.com>
2024-05-17 14:34:55 -06:00