Worker nodes
kube-proxy and CRI
34 / 82

Two small node components do the plumbing: kube-proxy for traffic, a CRI runtime for containers.

k-proxy icon

kube-proxy

Services to Pod IPs
1 WatchServices and EndpointSlices from the API.
2 Programiptables or IPVS rules on this node.
3 RouteVirtual IP traffic goes to a ready Pod IP.

Without it a Service's virtual IP is just a number. Some CNIs (Cilium) can replace kube-proxy entirely with eBPF, covered in Deck 7.

containerd logo

Container runtime and CRI

runs the containers
1
kubelet
speaks CRI
→
2
containerd
or CRI-O
→
3
runc
namespaces + cgroups

CRI is a standard interface, so Kubernetes is not tied to one runtime. Docker-built images are OCI images and run unchanged on containerd.

dockershim removal

Kubernetes 1.24 stopped talking to the Docker daemon. Nothing changes for your images; only the runtime on the node.

Debugging tip

On a node use crictl ps and crictl logs, not docker.

Sandboxed runtimes

gVisor or Kata can replace runc for stronger isolation (Deck 5).