Two small node components do the plumbing: kube-proxy for traffic, a CRI runtime for containers.
kube-proxy
Services to Pod IPs1 WatchServices and EndpointSlices from the API.
2 Programiptables or IPVS rules on this node.
3 RouteVirtual IP traffic goes to a ready Pod IP.
Without it a Service's virtual IP is just a number. Some CNIs (Cilium) can replace kube-proxy entirely with eBPF, covered in Deck 7.
Container runtime and CRI
runs the containers1
kubeletspeaks CRI
→
2
containerdor CRI-O
→
3
runcnamespaces + cgroups
CRI is a standard interface, so Kubernetes is not tied to one runtime. Docker-built images are OCI images and run unchanged on containerd.
dockershim removal
Kubernetes 1.24 stopped talking to the Docker daemon. Nothing changes for your images; only the runtime on the node.
Debugging tip
On a node use crictl ps and crictl logs, not docker.
Sandboxed runtimes
gVisor or Kata can replace runc for stronger isolation (Deck 5).