buildOne report1 publisher containerd 2.1.0, shipped December 2024, added a cgroup_writable handler that gives a Kubernetes pod a writable cgroup subtree without privileged: true. Set hostUsers: false and the pod can create child cgroups but cannot raise its own memory limit.
Reality
- Evidence60
- Adoption33
- Hype gap−5
- Incentives38
- Confidence55
buildOne report1 publisher containerd's September 1 advisory says a container restored from an untrusted checkpoint can run as root with full capabilities despite a restrictive Pod spec. Admission approves the spec, and restore then replays saved state without the step that turns a spec into kernel settings.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives20
- Confidence55
buildOne report1 publisher containerd 2.2's mount manager took 29.6 to 47.2 ms per Activate call in a dev.to benchmark, against 23.5 to 25.9 ms for truncate, mkfs, losetup and mount. Most of the gap is design overhead, and a panic plus an orphaned loop device from the same runs are the better reason for shim authors to wait.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence40
buildOne report1 publisher Engine 29.8.0's --umask flag sets one mask for the main process, execs and healthchecks. A side-by-side test on a second daemon also shows it accepting a four-digit value and applying only the last three.
Reality
- Evidence66
- Adoption25
- Hype gap+8
- Incentives22
- Confidence58
buildOne report1 publisher On an ext4 host the overlay2 graphdriver refused --storage-opt size outright with exit code 125. The containerd snapshotter that Docker 29 makes the default accepts the same flag on the same filesystem and enforces nothing.
Reality
- Evidence62
- Adoption40
- Hype gap+5
- Incentives20
- Confidence58
buildOne report1 publisher Kubernetes 1.37 shipped on 26 August 2026 with the containerd CRI fallback still working, because a pull request merged three months earlier moved the removal to 1.38. Two of the guides link to that pull request.
Reality
- Evidence52
- Adoption18
- Hype gap+30
- Incentives55
- Confidence45
buildOne report1 publisher An RKE2 hub-and-spoke design runs Prometheus, Harbor, Vault and ArgoCD once for four clusters and documents in-cluster failover carefully, while the hub's own sizing and outage behaviour stay unwritten.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives30
- Confidence40
buildOne report1 publisher A walkthrough builds one with unshare, chroot and an Alpine tarball, no daemon involved. The useful part is what it tells you the day Docker is not on the box and root is.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+12
- Incentives22
- Confidence46
buildOne report1 publisher The chart was identical on EKS, AKS and GKE. Only GKE's nodes had cgroup v2, and the JVM inside sized its heap from the host's memory instead of the container's.
Reality
- Evidence42
- Adoption
- Insufficient
- Hype gap+20
- Incentives32
- Confidence48