containerd 2.1 hands sandbox pods a writable cgroup without the privileged flag
containerd 2.1.0, shipped December 2024, added a cgroup_writable handler that gives a Kubernetes pod a writable cgroup subtree without privileged: true. Set hostUsers: false and the pod can create child cgroups but cannot raise its own memory limit.
Reality
- Evidence60
- Adoption33
- Hype gap−5
- Incentives38
- Confidence55