cri-o/cri-o:README に基づく導入ガイド
README、メタデータ、ライセンスに基づく cri-o/cri-o の導入と確認ガイドです。
プロジェクトの範囲
cri-o/cri-o の README はプロジェクトを「Open Container Initiative-based implementation of Kubernetes Container Runtime Interface」と説明しています。ここではリポジトリで確認できる事実だけを整理します。star 数やバッジは注目度の手掛かりであり、品質の証明ではありません。「Compatibility matrix: CRI-O ⬄ Kubernetes」には次の説明があります。CRI-O follows the Kubernetes release cycles with respect to its minor versions (1.x.y). Patch releases (1.x.z) for Kubernetes are not in sync with those from CRI-O, because they are scheduled for each month, whereas CRI-O provides them。これは範囲の説明であり、本番検証の結果ではありません。
向いている用途
README の「What is the scope of this project?」にある内容から、用途が合うかを先に判断できます。Support for multiple means to download images including trust & image verification。目的が違うなら、人気だけで採用する理由にはなりません。プロジェクト名やコマンドは原文のまま残し、一次資料へ戻って用語を確認できるようにしています。 README には次の確認可能な項目もあります。Support multiple image formats including the existing Docker image format。初回テストの材料にはなりますが、実際の環境での確認を省略する理由にはなりません。
動作の考え方
動作の説明は「Compatibility matrix: CRI-O ⬄ Kubernetes」など複数の箇所に分かれています。確認できる情報は次の通りです。For more information visit the Kubernetes Version Skew Policy.。書かれていない構成、性能、セキュリティを推測で補いません。導入時はディレクトリ、設定ファイル、release 履歴を確認してください。
インストールと初回起動
初回導入は README の入口から始めます。確認できるコマンドは次の通りです。 $ sudo curl -v --unix-socket /var/run/crio/crio.sock http://localhost/info | jq { "storage_driver": "btrfs", "storage_root": "/var/lib/containers/storage", "cgroup_driver": "systemd", "default_id_mappings": { ... } } 実行可能なコマンドがない場合は手順を作らず、「Compatibility matrix: CRI-O ⬄ Kubernetes」で依存関係、待受ポート、初回設定を確認します。
設定と日常運用
日常運用は公式文書の範囲に限ります。「Compatibility matrix: CRI-O ⬄ Kubernetes」には| CRI-O | Kubernetes | Maintenance status | | ------------------------------- | ------------------------------- | --------------------------------------------------------------------- | | main branch | master branch | Features from theとあります。設定、環境変数、権限、データ保存先は明記されたものだけを扱います。未記載の既定値は隔離環境で確認し、戻せる設定を保存してください。 同じ資料にはContainer image management (managing image layers, overlay filesystems, etc)ともあります。