Docs

Browse releases →

containerd

containerd — industry-standard container runtime

containerd

containerd — industry-standard container runtime

2.3.5 · aarch64-linux

Standalone runtime

Installing containerd is inert. Enable this package only for a standalone host runtime; k3s consumes containerd binaries as subordinate payloads and does not enable this service.

Privilege and state

This is an explicit root-equivalent workload with kernel, cgroup, state, runtime, and socket access. Durable state uses /var/lib/containerd and volatile state uses /run/containerd.

Registry configuration

Provision hosts.toml beneath registryConfigPath using host policy. Registry passwords must use an external credential helper or platform-managed file, never runtime Nix values.

OptionTypeDescription
configattribute set of attribute set of any valueDesired values for the package's declared config artifacts.
credentialsattribute set of submoduleOpaque references for the package's declared credentials.
defaultRuntimeone of ["runc"]Default OCI runtime registered with the CRI plugin.
disabledPluginslist of string matching [A-Za-z0-9][A-Za-z0-9._-]*Containerd plugins disabled at startup.
enablebooleanWhether to run containerd as a standalone host runtime.
grpcAddressstring matching /run/containerd(/[A-Za-z0-9._/-]+)?Unix socket used by local containerd clients.
metricsAddressstring matching [^[:space:]]+:[0-9]+ or nullOptional Prometheus metrics listen address.
registryConfigPathstring matching /etc/containerd(/[A-Za-z0-9._/-]+)?Root containing host-specific registry configuration.
requiredPluginslist of string matching [A-Za-z0-9][A-Za-z0-9._-]*Plugins whose initialization failure aborts startup.
rootstring matching /var/lib/containerd(/[A-Za-z0-9._/-]+)?Persistent containerd content and metadata root.
sandboxImagestring matching [^[:space:]]+CRI pod sandbox image reference.
snapshotterone of ["overlayfs","native"]Default CRI image snapshotter.
statestring matching /run/containerd(/[A-Za-z0-9._/-]+)?Volatile containerd state directory.
systemdCgroupbooleanWhether runc delegates cgroup management to systemd.