-
Notifications
You must be signed in to change notification settings - Fork 612
Expand file tree
/
Copy pathruntime.md
More file actions
140 lines (103 loc) · 8.84 KB
/
runtime.md
File metadata and controls
140 lines (103 loc) · 8.84 KB
Edit and raw actions
OlderNewer
1
# <a name="runtimeAndLifecycle" />Runtime and Lifecycle
2
3
## <a name="runtimeScopeContainer" />Scope of a Container
4
5
The entity using a runtime to create a container MUST be able to use the operations defined in this specification against that same container.
6
Whether other entities using the same, or other, instance of the runtime can see that container is out of scope of this specification.
7
8
## <a name="runtimeState" />State
9
10
The state of a container includes the following properties:
11
12
* **`ociVersion`** (string, REQUIRED) is the OCI specification version used when creating the container.
13
* **`id`** (string, REQUIRED) is the container's ID.
14
This MUST be unique across all containers on this host.
15
There is no requirement that it be unique across hosts.
16
* **`status`** (string, REQUIRED) is the runtime state of the container.
17
The value MAY be one of:
18
19
* `creating`: the container is being created (step 2 in the [lifecycle](#lifecycle))
20
* `created`: the runtime has finished the [create operation](#create) (after step 2 in the [lifecycle](#lifecycle)), and the container process has neither exited nor executed the user-specified program
21
* `running`: the container process has executed the user-specified program but has not exited (after step 5 in the [lifecycle](#lifecycle))
22
* `stopped`: the container process has exited (step 7 in the [lifecycle](#lifecycle))
23
24
Additional values MAY be defined by the runtime, however, they MUST be used to represent new runtime states not defined above.
25
* **`pid`** (int, REQUIRED when `status` is `created` or `running` on Linux, OPTIONAL on other platforms) is the ID of the container process, as seen by the host.
26
* **`bundle`** (string, REQUIRED) is the absolute path to the container's bundle directory.
27
This is provided so that consumers can find the container's configuration and root filesystem on the host.
28
* **`annotations`** (map, OPTIONAL) contains the list of annotations associated with the container.
29
If no annotations were provided then this property MAY either be absent or an empty map.
30
31
The state MAY include additional properties.
32
33
When serialized in JSON, the format MUST adhere to the following pattern:
34
35
```json
36
{
37
"ociVersion": "0.2.0",
38
"id": "oci-container1",
39
"status": "running",
40
"pid": 4422,
41
"bundle": "/containers/redis",
42
"annotations": {
43
"myKey": "myValue"
44
}
45
}
46
```
47
48
See [Query State](#query-state) for information on retrieving the state of a container.
49
50
## <a name="runtimeLifecycle" />Lifecycle
51
The lifecycle describes the timeline of events that happen from when a container is created to when it ceases to exist.
52
53
1. OCI compliant runtime's [`create`](runtime.md#create) command is invoked with a reference to the location of the bundle and a unique identifier.
54
2. The container's runtime environment MUST be created according to the configuration in [`config.json`](config.md).
55
If the runtime is unable to create the environment specified in the [`config.json`](config.md), it MUST [generate an error](#errors).
56
While the resources requested in the [`config.json`](config.md) MUST be created, the user-specified program (from [`process`](config.md#process)) MUST NOT be run at this time.
57
Any updates to [`config.json`](config.md) after this step MUST NOT affect the container.
58
3. Runtime's [`start`](runtime.md#start) command is invoked with the unique identifier of the container.
59
4. The [prestart hooks](config.md#prestart) MUST be invoked by the runtime.
60
If any prestart hook fails, the runtime MUST [generate an error](#errors), stop the container, and continue the lifecycle at step 9.
61
5. The runtime MUST run the user-specified program, as specified by [`process`](config.md#process).
62
6. The [poststart hooks](config.md#poststart) MUST be invoked by the runtime.
63
If any poststart hook fails, the runtime MUST [log a warning](#warnings), but the remaining hooks and lifecycle continue as if the hook had succeeded.
64
7. The container process exits.
65
This MAY happen due to erroring out, exiting, crashing or the runtime's [`kill`](runtime.md#kill) operation being invoked.
66
8. Runtime's [`delete`](runtime.md#delete) command is invoked with the unique identifier of the container.
67
9. The container MUST be destroyed by undoing the steps performed during create phase (step 2).
68
10. The [poststop hooks](config.md#poststop) MUST be invoked by the runtime.
69
If any poststop hook fails, the runtime MUST [log a warning](#warnings), but the remaining hooks and lifecycle continue as if the hook had succeeded.
70
71
## <a name="runtimeErrors" />Errors
72
73
In cases where the specified operation generates an error, this specification does not mandate how, or even if, that error is returned or exposed to the user of an implementation.
74
Unless otherwise stated, generating an error MUST leave the state of the environment as if the operation were never attempted - modulo any possible trivial ancillary changes such as logging.
75
76
## <a name="runtimeWarnings" />Warnings
77
78
In cases where the specified operation logs a warning, this specification does not mandate how, or even if, that warning is returned or exposed to the user of an implementation.
79
Unless otherwise stated, logging a warning does not change the flow of the operation; it MUST continue as if the warning had not been logged.
80
81
## <a name="runtimeOperations" />Operations
82
83
Unless otherwise stated, runtimes MUST support the following operations.
84
85
Note: these operations are not specifying any command-line APIs, and the parameters are inputs for general operations.
86
87
### <a name="runtimeQueryState" />Query State
88
89
`state <container-id>`
90
91
This operation MUST [generate an error](#errors) if it is not provided the ID of a container.
92
Attempting to query a container that does not exist MUST [generate an error](#errors).
93
This operation MUST return the state of a container as specified in the [State](#state) section.
94
95
### <a name="runtimeCreate" />Create
96
97
`create <container-id> <path-to-bundle>`
98
99
This operation MUST [generate an error](#errors) if it is not provided a path to the bundle and the container ID to associate with the container.
100
If the ID provided is not unique across all containers within the scope of the runtime, or is not valid in any other way, the implementation MUST [generate an error](#errors) and a new container MUST NOT be created.
101
This operation MUST create a new container.
102
103
All of the properties configured in [`config.json`](config.md) except for [`process`](config.md#process) MUST be applied.
104
[`process.args`](config.md#process) MUST NOT be applied until triggered by the [`start`](#start) operation.
105
The remaining `process` properties MAY be applied by this operation.
106
If the runtime cannot apply a property as specified in the [configuration](config.md), it MUST [generate an error](#errors) and a new container MUST NOT be created.
107
108
The runtime MAY validate `config.json` against this spec, either generically or with respect to the local system capabilities, before creating the container ([step 2](#lifecycle)).
109
Runtime callers who are interested in pre-create validation can run [bundle-validation tools](implementations.md#testing--tools) before invoking the create operation.
110
111
Any changes made to the [`config.json`](config.md) file after this operation will not have an effect on the container.
112
113
### <a name="runtimeStart" />Start
114
`start <container-id>`
115
116
This operation MUST [generate an error](#errors) if it is not provided the container ID.
117
Attempting to `start` a container that is not [`created`](#state) MUST have no effect on the container and MUST [generate an error](#errors).
118
This operation MUST run the user-specified program as specified by [`process`](config.md#process).
119
This operation MUST generate an error if `process` was not set.
120
121
### <a name="runtimeKill" />Kill
122
`kill <container-id> <signal>`
123
124
This operation MUST [generate an error](#errors) if it is not provided the container ID.
125
Attempting to send a signal to a container that is neither [`created` nor `running`](#state) MUST have no effect on the container and MUST [generate an error](#errors).
126
This operation MUST send the specified signal to the process in the container.
127
128
### <a name="runtimeDelete" />Delete
129
`delete <container-id>`
130
131
This operation MUST [generate an error](#errors) if it is not provided the container ID.
132
Attempting to `delete` a container that is not [`stopped`](#state) MUST have no effect on the container and MUST [generate an error](#errors).
133
Deleting a container MUST delete the resources that were created during the `create` step.
134
Note that resources associated with the container, but not created by this container, MUST NOT be deleted.
135
Once a container is deleted its ID MAY be used by a subsequent container.
136
137
138
## <a name="runtimeHooks" />Hooks
139
Many of the operations specified in this specification have "hooks" that allow for additional actions to be taken before or after each operation.
140
See [runtime configuration for hooks](./config.md#hooks) for more information.