Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add containerd graduation review proposal #165

merged 1 commit into from Feb 28, 2019
Changes from all commits
File filter
Filter file types
Failed to load comments.
Jump to
Jump to file
Failed to load files.


Just for now

@@ -0,0 +1,66 @@
**Containerd Graduation Proposal**

Since the [March 2017 announcement]( at KubeCon Berlin that containerd would be joining the CNCF, the containerd community has been busy continuing the development and testing of a stable, core container runtime for cloud native use cases.

In late 2017, containerd announced its [1.0 release](, followed in early 2018 by a 1.1 release that has been updated with several minor fix releases through 2018. The containerd team has just completed the next major release, [1.2.0](, with more complete Windows runtime support and a new runtime shim v2 API that is [proving]( [valuable]( for [runc]( alternatives like [Kata containers](

At this time, we believe containerd is ready for the [graduation stage]( within the CNCF, and per the guidelines listed there, we detail our readiness in the section below.

### CNCF Graduation Criteria

**Committers from at least two organizations.**

Containerd has had a variety of maintainers and reviewers since its inception, and currently have 12 committers representing Docker, NTT, Google, IBM, Microsoft, Facebook, Tesla, and Cruise Automation. We also recognize **LGTM** rights for a group we call *reviewers*, of which there are currently eight reviewers representing Alibaba, ZTE, Huawei, Docker, Microsoft and an independent developer.

**Have achieved and maintained a Core Infrastructure Initiative Best Practices Badge.**

We have recently validated our CII best practices, and have the badge embedded within our main containerd/containerd repository on GitHub. Our specific status (passing) is shown on [our CII project page here](

**Adopt the CNCF Code of Conduct.**

We have adopted the CNCF code of conduct and prominently make this clear in our []( document, which applies to all containerd projects and sub-projects.

**Explicitly define a project governance and committer process.**

Our project governance is clearly laid out in our []( document, including details on how to become a maintainer and how maintainer and contribution processes are handled. The maintainers for containerd, the CRI project, and all sub-projects are common, and maintained in our core project repo in the [MAINTAINERS]( file.

**Have a public list of project adopters for at least the primary repository.**

This comment has been minimized.

This comment has been minimized.


estesp Nov 28, 2018
Author Contributor

Added, thanks!

Containerd began life prior to its CNCF adoption as a lower-layer runtime manager for the Docker engine. Continuing today, containerd has widest usage and adoption as the layer between the Docker engine and the OCI runc executor. However, as containerd and its CRI plugin project have merged in January 2018, the combined use of containerd and the CRI plugin has grown to include several public cloud providers, as well as several projects who are attracted to the simplicity of the Go client API library for embedding container runtime capabilities.

**_IBM Cloud Kubernetes Service (IKS)_** - offers containerd as the CRI runtime for v1.11 and, soon, v1.12.

**_IBM Cloud Private (ICP)_** - IBM's on-premises cloud offering has containerd as a "tech preview" CRI runtime for the Kubernetes offered within this product for the past two releases, and plans to fully migrate to containerd in a future release.

**_Google Cloud Kubernetes Engine (GKE)_** - offers containerd in "alpha clusters" on recent versions of Kubernetes.

This comment has been minimized.


AkihiroSuda Oct 17, 2018

s/alpha/beta/ ? cc @Random-Liu

cos_containerd OS images are available as a Beta feature in GKE v1.11 and higher.

This comment has been minimized.


Random-Liu Oct 22, 2018

containerd will be beta when GKE v1.11 rollout, which is coming soon.

**_Cloud Foundry_** - The [Guardian container manager]( for CF has been using OCI runC directly with additional code from CF managing the container image and filesystem interactions, but have recently migrated to use containerd as a replacement for the extra code they had written around runC.

**_Alibaba's PouchContainer_** - The Alibaba [PouchContainer]( project uses containerd as its runtime for a cloud native offering that has unique isolation and image distribution capabilities.

**_Rancher's Rio project_** - Rancher Labs [Rio]( project uses containerd as the runtime for a combined Kubernetes, Istio, and container "Cloud Native Container Distribution" platform.

**_Eliot_** - The [Eliot]( container project for IoT device container management uses containerd as the runtime.

**_Balena_** - Resin's [Balena]( container engine, based on moby/moby but for edge, embedded, and IoT use cases, uses the containerd and runc stack in the same way that the Docker engine uses containerd.

**_LinuxKit_** - the Moby project's [LinuxKit]( for building secure, minimal Linux OS images in a container-native model uses containerd as the core runtime for system and service containers.

**_BuildKit_** - The Moby project's [BuildKit]( can use either runC or containerd as build execution backends for building container images. BuildKit support has also been built into the Docker engine in recent releases, making BuildKit provide the backend to the `docker build` command.

**_AWS Firecracker_** - The AWS [Firecracker VMM project]( uses containerd through integration via a v2 shim and custom external snapshotter. More details on their integration is available in the [Firecracker containerd project](

**_Kata containers_** - The [Kata containers]( lightweight-virtualized container runtime project integrates with containerd via a custom v2 shim implementation that drives the Kata container runtime.

**_Docker engine_** - As noted in the opening paragraph, Docker continues to consume containerd as a key component within the Docker engine stack, and is actively working to remove Docker engine implementations where containerd implementations can be used as a replacement.

This comment has been minimized.


resouer Nov 12, 2018

Not sure if it's worth to mention but katacontainers is doing official integration with containerd shimv2 api. We are hoping to merge the PR before KubeCon Seattle.

This comment has been minimized.


estesp Nov 28, 2018
Author Contributor

Sounds great--just added Kata to the list of adopters!

With contributions from Microsoft and AWS, we believe that Azure and AWS are also looking at containerd for potential use within their public cloud offerings as well.

**_Other Projects_** - While the above list provides a cross-section of well known uses of containerd, the simplicity and clear API layer for containerd has inspired many smaller projects around providing simple container management platforms. Two that have come from containerd community participants directly are Michael Crosby's [boss]( project and Evan Hazlett's [stellar]( project, as examples of higher layer functionality that can easily be built on the containerd base.

This comment has been minimized.

This comment has been minimized.


estesp Oct 16, 2018
Author Contributor

Rio is listed above; unless he has another one. I wouldn't put it past him :)

**NOTE:** *The containerd community will be happy to provide adoption and production usage
statistics where available and/or possible to enumerate.*

**Receive a supermajority vote from the TOC to move to graduation stage.**

We believe this document prepares us for a TOC vote on the graduation readiness of containerd.
ProTip! Use n and p to navigate between commits in a pull request.