The software described in this documentation is either no longer supported or is in extended support.
Oracle recommends that you upgrade to a current supported release.
When you deploy Kubernetes worker nodes, CRI-O is also deployed. CRI-O is an implementation of the Kubernetes Container Runtime Interface (CRI) to enable using Open Container Initiative (OCI) compatible runtimes. It is a lightweight alternative to using Docker as the runtime for Kubernetes. CRI-O allows Kubernetes to use any OCI-compliant runtime as the container runtime for running pods.
CRI-O delegates containers to run on appropriate nodes, based on
the configuration set in pod files.
Privileged pods can be run using the runC
runtime engine (runc
), and
unprivileged pods can be run using the Kata Containers
runtime engine (kata-runtime
). Defining whether
containers are trusted or untrusted is set in the Kubernetes pod or
deployment file.
For information on how to set the container runtime, see Container Runtimes.