Glossary · Automation software engineering and architecture
Container runtime
Also known as: Container engine
German: Container-Laufzeit
In software engineering, a container runtime is the software on a host that creates, starts, stops and isolates containers from container images, using operating system features such as namespaces and control groups. Examples include containerd, CRI-O and runc.
- Software engineering
In one sentence
A container runtime is the host software that creates, starts, stops and isolates containers from images.
Example
The industrial PC's container runtime starts the historian container with a memory limit and read-only file system as defined in its deployment file.
How it applies
- Engineering: The runtime applies the isolation and resource limits defined for each container: CPU, memory, devices, network and file system access. Access to hardware interfaces, such as fieldbus cards or serial ports, must be granted explicitly.
- Operation and security: The runtime is part of the trusted base of the device and must be kept up to date. Running containers with extensive privileges weakens the isolation the runtime provides.
- Documentation: State the supported runtimes and versions for each product, required privileges and device mappings. Service documentation should explain how to inspect running containers and collect their logs with the runtime's tools.
Container runtime vs. orchestration
The runtime manages containers on a single host. Container orchestration manages many hosts and instructs the runtimes on each of them. Small edge devices sometimes use a runtime alone, without orchestration.