VRT-210 · Virtualization & Containers

Container Runtimes & the OCI Spec

What runc, containerd and the OCI specifications actually define, and how images become running processes.

Practitioner 3 days in person6 half-days online Max 14 in person

Who this course is for

Platform engineers operating container infrastructure — runc, containerd, Kubernetes nodes — who need to know what the OCI specifications actually define and where to look when a container will not start.

Prerequisites

VRT-201 or equivalent namespace/cgroup knowledgeDaily container usage (Docker or similar)JSON and shell fluency

Course outline

Day 1 — The OCI specifications

  • What OCI standardises and what it deliberately does not
  • The runtime spec: config.json, the lifecycle states and hooks
  • The image spec: manifests, configs, layers and content digests
  • runc under the microscope: from spec to running process
  • Reading a real runtime configuration and predicting its behaviour

Day 2 — Images and storage

  • Image layers as a content-addressed store
  • overlayfs: lowerdir, upperdir, work dir and the copy-up path
  • Storage drivers and why overlay won
  • Pulling, inspecting and diffing an image without Docker
  • The true storage cost of a container that writes

Day 3 — containerd, CRI and rootless

  • containerd architecture: content store, snapshotters, runtime shims
  • CRI and how the kubelet drives containerd
  • Rootless containers: user namespace mapping, subuid/subgid and the network limits
  • A systematic method for containers that will not start
  • Where the Docker/Moby layer fits above all of this

Hands-on labs

Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach

  1. Lab: run a container by hand with runc and a hand-written config.json — no Docker anywhere in the loop
  2. Lab: dissect an OCI image: pull it with registry tooling, walk the manifest and config, and follow layers by digest
  3. Lab: reproduce copy-up on overlayfs and measure the storage and latency cost of writes inside a container
  4. Lab: drive containerd directly with ctr or nerdctl, then trace a Kubernetes pod from the kubelet down to its runc process
  5. Lab: debug three injected start failures — a bad rootfs, a namespace mapping error, a seccomp rejection — from their actual error paths

Capstone project

Assemble the full stack by hand and then break it: run a workload directly on runc, the same workload through containerd, and the same again as a pod — capturing the configuration and process tree at each layer. The deliverable is a layer-by-layer map of a real container's lifecycle with the exact files and APIs involved, plus a triage record for the three injected failures you diagnosed, written so a colleague could follow it during an incident.

What you leave with

  • A precise model of what runc, containerd and the kubelet each do
  • Hands-on OCI image inspection skills independent of any one vendor's CLI
  • Overlayfs mechanics understood by measurement, not description
  • A convergent debugging method for container start failures
  • Rootless container configuration you have actually run

How it runs

Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.

Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.

Questions

Who is this course for?

Platform engineers operating container infrastructure — runc, containerd, Kubernetes nodes — who need to know what the OCI specifications actually define and where to look when a container will not start. It sits at practitioner level within the Virtualization & Containers track.

What do I need to know already?

Specific prerequisites for this course: VRT-201 or equivalent namespace/cgroup knowledge; Daily container usage (Docker or similar); JSON and shell fluency. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.

Can this run privately for my team?

Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.

What is the difference between in-person and online?

In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.

Do you invoice companies?

Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.

Upcoming dates

DatesWhereSeatsEarly birdRegular
18 Oct – 20 Oct 20263 full days RiyadhIn person · KAFD Conference Centre 9 of 14 —SAR 7,880
25 Oct – 27 Oct 20263 full days Kuwait CityIn person · Al Hamra Tower 4 of 14 —KWD 650
1 Nov – 3 Nov 20263 full days MuscatIn person · Knowledge Oasis Muscat 9 of 14 —OMR 810
1 Nov – 8 Nov 20266 half-days Gulf bandLive online · 09:00–13:00 GMT+3 15 of 20 —US$1,500
2 Nov – 4 Nov 20263 full days OttawaIn person · Kanata North Tech Park 4 of 14 —CAD 2,860
9 Nov – 11 Nov 20263 full days TorontoIn person · MaRS Discovery District 9 of 14 CAD 2,570until 10 OctCAD 2,860
9 Nov – 16 Nov 20266 half-days Europe bandLive online · 09:00–13:00 CET 4 of 20 US$1,350until 10 OctUS$1,500
16 Nov – 18 Nov 20263 full days LondonIn person · Shoreditch Works 4 of 14 GBP 1,480until 17 OctGBP 1,640
16 Nov – 18 Nov 20263 full days BerlinIn person · Factory Görlitzer Park 9 of 14 EUR 1,740until 17 OctEUR 1,930
16 Nov – 23 Nov 20266 half-days Americas bandLive online · 13:00–17:00 ET 9 of 20 US$1,350until 17 OctUS$1,500

Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.

More in Virtualization & Containers