Session
CRI-O: Plug It, Tune It, Share It — Extending and Accelerating Your Runtime
Kubernetes operators keep hitting the same friction at the node level. Resource management decisions are locked inside the kubelet with limited configurability. Container-level knobs like ulimits or PID limits require OCI hooks or global kubelet flags instead of per-workload configuration.
NRI plugins intercept container creation to modify CPU sets, memory limits, and device assignments before a container starts, moving resource policy into out-of-tree plugins where vendors and platform teams can iterate without waiting on runtime releases. This session covers how NRI integrates with CRI-O, with plugin examples.
Beyond NRI, CRI-O is tracking upstream CRI changes. Per-container ulimits, per-pod PID limits, exec identity propagation, writable cgroups without privilege escalation, stop signals, and MemoryQoS are at various stages of landing. We cover where CRI-O stands on each.
Since KubeCon EU, we have also continued work on Spegel support for CRI-O and demo what is working.
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top