Memory hook: Build an image, store it in a registry, run it as a container, group it in a Pod.
Must remember
- An image packages application files, dependencies and startup metadata. A container is a running instance with a writable layer and runtime isolation. A registry stores and distributes image artifacts; it does not schedule applications.
- Containers ordinarily share the host kernel. Virtual machines have a guest operating system and kernel. Containers are lightweight process isolation, not a guarantee of the same isolation boundary as separate VMs.
- Linux namespaces give processes isolated views of resources such as process IDs and networking. Control groups, or cgroups, account for and constrain resource use. Linux namespaces and Kubernetes namespaces are different concepts.
- Image layers enable reuse and caching. A tag such as
stablecan point to a different image later; a digest identifies specific content. Pin digests when an exact, reproducible artifact matters. - A Dockerfile describes an image build. A multi-stage build separates compilation tools from the final runtime image. Smaller images can reduce download time and attack surface; they still need patching and vulnerability review.
- The Open Container Initiative, OCI, defines interoperable image, runtime and distribution specifications. Kubernetes' Container Runtime Interface, CRI, lets the kubelet talk to runtimes such as containerd and CRI-O. Image-building tools and node runtimes serve different purposes.
- Kubernetes also uses CNI for container networking integrations and CSI for storage integrations. Remember: CRI runs; CNI connects; CSI stores. These interfaces make implementations replaceable without making their capabilities identical.
- Treat container filesystems as replaceable. Put runtime settings in configuration, keep credentials out of image layers, run as a non-root user where possible, drop unneeded privileges and rebuild patched images instead of manually editing every running container.
- An ordinary init container completes setup before the main application starts. A sidecar supports the application while it runs, for example with a proxy or telemetry agent. Use separate Pods when components need independent scaling or lifecycles.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Guarantee the deployed artifact matches the reviewed artifact | An image digest, supported by signing/provenance checks where required |
| Give a process its own view of networking and process IDs | Linux namespace isolation |
| Restrict a container's resource consumption | Resource controls implemented using mechanisms such as cgroups |
| Run OCI images on a Kubernetes node | A CRI-compatible runtime such as containerd or CRI-O |
| Produce a smaller production image after compiling code | A multi-stage build with a minimal final runtime stage |
Traps
- An image built with Docker can run through a compatible runtime without Docker Engine being the Kubernetes runtime.
- Deleting a secret in a later image layer does not reliably remove it from earlier layers or build history.
latestis a tag, not a promise that an already running Pod continuously updates itself.- A container image must support the target operating system and CPU architecture; packaging does not eliminate platform compatibility requirements.
Active recall
1. A release tag is moved after approval. What reference prevents the deployment from silently choosing new image content?
Pin the approved image digest. Tags are mutable pointers; a digest identifies specific content. Keep the approval, provenance and vulnerability checks tied to that digest.
2. Which interface is involved when a kubelet asks containerd to start a container?
CRI. CNI concerns network connectivity and CSI concerns storage. OCI specifications describe interoperable container artifacts and runtime behaviour.
3. Does placing two applications in different containers mean they use different host kernels?
Ordinary containers on the same Linux host share its kernel. Namespaces, resource controls and additional security mechanisms isolate processes, but this is not identical to running separate virtual machines.
4. A compiler is needed only during the build. How can the runtime image avoid including it?
Use a multi-stage build and copy the required build output into a smaller final stage. Do not copy unnecessary toolchains, temporary files or build credentials into the runtime artifact.
5. An application depends on configuration preparation completing first. Init container or sidecar?
An ordinary init container is appropriate for setup that must finish before the main container starts. A sidecar is appropriate for a supporting service that runs alongside the application.