containerd #5

Supports: focal bionic xenial


containerd manages the complete container lifecycle of its host system, from image transfer and storage to container execution and supervision to low-level storage to network attachments and beyond.

Charm for Containerd

This subordinate charm deploys the Containerd engine within a running Juju model. Containerd is an open platform for developers and sysadmins to build, ship, and run distributed applications in containers.

Containerd focuses on distributing applications as containers that can be quickly assembled from components that are run the same on different servers without environmental dependencies. This eliminates the friction between development, QA, and production environments.

This charm is a component of Charmed Kubernetes. For full information, please visit the official Charmed Kubernetes docs.

Note: This is a fork by vern of cs:~containers/containerd-160 as per LP#1915361 and LP#1943545


(string) Base64 encoded Certificate Authority (CA) bundle. Setting this config allows container runtimes to pull images from registries with TLS certificates signed by an external CA.
(string) Registry endpoints and credentials. Setting this config allows Kubelet to pull images from registries where auth is required. The value for this config must be a JSON array of credential objects, like this: [{"host": "my.registry:port", "username": "user", "password": "pass"}] `host` could be registry host address, e.g.:, or a name, e.g.:, myregistry. It will be derived from `url` if not provided, e.g.: url: --> host: If required, you can supply credentials with option keys 'username' and 'password', or 'ca_file', 'cert_file', and 'key_file' for ssl/tls communication, which should be base64 encoded file contents in string form "ca_file": "'"$(base64 -w 0 < my.custom.registry.pem)"'" example config) juju config containerd custom_registries='[{ "url": "", "ca_file": "'"$(base64 -w 0 < ~/"'", "cert_file": "'"$(base64 -w 0 < ~/my.custom.cert.pem)"'", "key_file": "'"$(base64 -w 0 < ~/my.custom.key.pem)"'", }]'
(boolean) Ignore juju-http(s) proxy settings on this charm. If set to true, all juju https proxy settings will be ignored
(boolean) Enable GRUB cgroup overrides cgroup_enable=memory swapaccount=1. WARNING changing this option will reboot the host - use with caution on production services.
(string) Override GPU driver installation. Options are "auto", "nvidia", "none".
(string) URL to use for HTTP_PROXY to be used by Containerd. Useful in egress-filtered environments where a proxy is the only option for accessing the registry to pull images.
(string) URL to use for HTTPS_PROXY to be used by Containerd. Useful in egress-filtered environments where a proxy is the only option for accessing the registry to pull images.
(string) Comma-separated list of destinations (either domain names or IP addresses) which should be accessed directly, rather than through the proxy defined in http_proxy or https_proxy. Must be less than 2023 characters long.
(string) Set a custom containerd runtime. Set "auto" to select based on hardware.
(string) Set a custom containerd shim.