containerd and CRI-O

Under Docker and Kubernetes sit the low-level runtimes that actually run containers: containerd (with runc) and CRI-O. On a Kubernetes node these are the engine, and their control sockets are root-equivalent just like the Docker daemon. Reaching one from a node foothold creates privileged containers and reads everything the runtime stores, including image pull credentials.

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more