Docker Container Runtimes
What This Article Covers
- What a container runtime is.
- Which runtimes Docker uses.
- Differences between runc and crun.
- What containerd and shim are.
- How to switch and verify the runtime.
Introduction: Docker Container Runtimes
For many developers, Docker is the entry point to containers. But if you work with containers in production, you should understand what happens under the hood. Docker relies on containerd, a lightweight container management system, and a low-level runtime like runc or crun. This runtime starts and isolates the actual container processes. The choice of runtime affects speed, resource consumption, and security.
This article explains the key Docker runtimes and how to switch between them.
Key Terms
- Container runtime: Software that executes and isolates container processes.
- containerd: High-level container management.
- runc: Docker’s standard runtime, written in Go.
- crun: Alternative runtime in C, faster and more resource-efficient.
- shim: Bridge between containerd and a running container.
- CRI: Container Runtime Interface.
- cgroups: Control Groups for resource management.
- Namespaces: Isolation of processes, networking, and filesystem.
Docker Architecture
Docker works in layers:
- Docker Engine: API, CLI, and daemon.
- containerd: Manages container lifecycle.
- Runtime: Starts and isolates container processes.
A typical container start looks like this:
docker run → Docker Engine → containerd → runc/crun → Container
runc
runc is Docker’s standard runtime. It’s stable, widely used, and supports many features:
- OCI specification.
- Cgroups v1 and v2.
- Namespaces.
- Seccomp, AppArmor, SELinux.
Drawbacks:
- Written in Go, resulting in larger binaries and higher memory consumption.
- Startup can be slower than crun.
crun
crun is a C-based alternative to runc. Advantages:
- Smaller binary.
- Faster startup.
- Lower memory consumption.
- Better cgroups v2 support.
- WebAssembly component support.
Drawbacks:
- Less widespread.
- Some tools or Kubernetes integrations need to test crun compatibility.
- Occasionally newer bugs appear.
Installing crun
On Debian/Ubuntu:
sudo apt-get install -y crun
Switching the Runtime in Docker
Docker can configure a runtime via daemon.json:
{
"runtimes": {
"crun": {
"path": "/usr/bin/crun"
}
},
"default-runtime": "crun"
}
Then:
sudo systemctl restart docker
Verification:
docker info | grep "Default Runtime"
Starting Individual Containers with crun
docker run --runtime=crun hello-world
containerd
containerd is an industry-standard runtime used not only by Docker but also by Kubernetes and many other tools. It manages:
- Images.
- Container processes.
- Storage.
- Network plugins.
containerd alone doesn’t start containers for end users; instead, it provides an API used by Docker, Kubernetes, or the crictl CLI.
Practical Differences
| Aspect | runc | crun |
|---|---|---|
| Language | Go | C |
| Size | larger | smaller |
| Startup time | fast | often faster |
| Memory | slightly more | slightly less |
| cgroups v2 | supported | optimized |
| Adoption | very high | growing |
For most home labs, the choice makes little practical difference. With many containers or limited hardware, crun can offer benefits.
Security
- The runtime must be updated regularly.
- Security features like Seccomp, AppArmor, and cgroups should remain active.
- Rootless Docker also requires a runtime that supports rootless namespaces.
Common Pitfalls
- crun not installed: Container fails to start.
- Incorrect paths:
daemon.jsonpoints to a non-existent file. - Incompatibilities: Some tools expect runc.
- Kubernetes: crun must be registered in the CRI configuration.
- Forgotten updates: Runtime stays on an old version.
Further Reading and Resources
- BotServ.de Docker Commands
- BotServ.de Docker Security
- BotServ.de Docker Rootless
- BotServ.de Docker Monitoring
FAQ: Container Runtimes
Should I use crun instead of runc? If you run many containers or have limited hardware, it’s worth trying. Otherwise, runc is fine.
Do I need to manage containerd manually? No, Docker handles it for you.
Is crun secure? Yes, it uses the same Linux security mechanisms as runc.
How do I switch runtimes?
Add the runtime to /etc/docker/daemon.json and restart Docker.
What is OCI? Open Container Initiative, the standard that both runc and crun follow.
Sources and Further Reading
- runc: https://github.com/opencontainers/runc
- crun: https://github.com/containers/crun
- containerd: https://containerd.io/
- OCI: https://opencontainers.org/
Summary: Docker Container Runtimes
Docker relies on containerd and a low-level runtime like runc or crun. runc is the proven standard, while crun offers advantages in speed and resource efficiency. For most home labs, runc is sufficient, but crun is a solid alternative when running many containers or on limited hardware. Switching the runtime via daemon.json is straightforward. Understanding this architecture lets you debug Docker more effectively, optimize performance, and operate it more securely.


