Skip to content
BotServBotServ
DockerrunccruncontainerdContainer Runtime

Docker Container Runtimes

Understand runc, crun, and containerd. Compare performance, differences, and how to switch Docker runtimes.

S

schutzgeist

3 min read
Docker Container Runtimes

Docker Container Runtimes

What This Article Covers

  • What a container runtime is.
  • Which runtimes Docker uses.
  • Differences between runc and crun.
  • What containerd and shim are.
  • How to switch and verify the runtime.

Introduction: Docker Container Runtimes

For many developers, Docker is the entry point to containers. But if you work with containers in production, you should understand what happens under the hood. Docker relies on containerd, a lightweight container management system, and a low-level runtime like runc or crun. This runtime starts and isolates the actual container processes. The choice of runtime affects speed, resource consumption, and security.

This article explains the key Docker runtimes and how to switch between them.

Key Terms

  • Container runtime: Software that executes and isolates container processes.
  • containerd: High-level container management.
  • runc: Docker’s standard runtime, written in Go.
  • crun: Alternative runtime in C, faster and more resource-efficient.
  • shim: Bridge between containerd and a running container.
  • CRI: Container Runtime Interface.
  • cgroups: Control Groups for resource management.
  • Namespaces: Isolation of processes, networking, and filesystem.

Docker Architecture

Docker works in layers:

  1. Docker Engine: API, CLI, and daemon.
  2. containerd: Manages container lifecycle.
  3. Runtime: Starts and isolates container processes.

A typical container start looks like this:

docker run → Docker Engine → containerd → runc/crun → Container

runc

runc is Docker’s standard runtime. It’s stable, widely used, and supports many features:

  • OCI specification.
  • Cgroups v1 and v2.
  • Namespaces.
  • Seccomp, AppArmor, SELinux.

Drawbacks:

  • Written in Go, resulting in larger binaries and higher memory consumption.
  • Startup can be slower than crun.

crun

crun is a C-based alternative to runc. Advantages:

  • Smaller binary.
  • Faster startup.
  • Lower memory consumption.
  • Better cgroups v2 support.
  • WebAssembly component support.

Drawbacks:

  • Less widespread.
  • Some tools or Kubernetes integrations need to test crun compatibility.
  • Occasionally newer bugs appear.

Installing crun

On Debian/Ubuntu:

sudo apt-get install -y crun

Switching the Runtime in Docker

Docker can configure a runtime via daemon.json:

{
  "runtimes": {
    "crun": {
      "path": "/usr/bin/crun"
    }
  },
  "default-runtime": "crun"
}

Then:

sudo systemctl restart docker

Verification:

docker info | grep "Default Runtime"

Starting Individual Containers with crun

docker run --runtime=crun hello-world

containerd

containerd is an industry-standard runtime used not only by Docker but also by Kubernetes and many other tools. It manages:

  • Images.
  • Container processes.
  • Storage.
  • Network plugins.

containerd alone doesn’t start containers for end users; instead, it provides an API used by Docker, Kubernetes, or the crictl CLI.

Practical Differences

Aspectrunccrun
LanguageGoC
Sizelargersmaller
Startup timefastoften faster
Memoryslightly moreslightly less
cgroups v2supportedoptimized
Adoptionvery highgrowing

For most home labs, the choice makes little practical difference. With many containers or limited hardware, crun can offer benefits.

Security

  • The runtime must be updated regularly.
  • Security features like Seccomp, AppArmor, and cgroups should remain active.
  • Rootless Docker also requires a runtime that supports rootless namespaces.

Common Pitfalls

  • crun not installed: Container fails to start.
  • Incorrect paths: daemon.json points to a non-existent file.
  • Incompatibilities: Some tools expect runc.
  • Kubernetes: crun must be registered in the CRI configuration.
  • Forgotten updates: Runtime stays on an old version.

Further Reading and Resources

FAQ: Container Runtimes

Should I use crun instead of runc? If you run many containers or have limited hardware, it’s worth trying. Otherwise, runc is fine.

Do I need to manage containerd manually? No, Docker handles it for you.

Is crun secure? Yes, it uses the same Linux security mechanisms as runc.

How do I switch runtimes? Add the runtime to /etc/docker/daemon.json and restart Docker.

What is OCI? Open Container Initiative, the standard that both runc and crun follow.

Sources and Further Reading

Summary: Docker Container Runtimes

Docker relies on containerd and a low-level runtime like runc or crun. runc is the proven standard, while crun offers advantages in speed and resource efficiency. For most home labs, runc is sufficient, but crun is a solid alternative when running many containers or on limited hardware. Switching the runtime via daemon.json is straightforward. Understanding this architecture lets you debug Docker more effectively, optimize performance, and operate it more securely.

Back to Blog
Share:

Related Posts