tag: Container-Runtime · 6 items
- Platform/SRE — Plan: Despite being a patch release, 2.3.4 ships a breaking change: checkpoint restore in CreateContainer is now disabled by default, requiring an explicit config opt-in. Also fixes a memory leak in the OOM watcher and binary protobuf shim corruption. Review workloads using CRIU/checkpoint restore before upgrading; schedule the upgrade this quarter.
- CI/CD — Skip
- Leader — Skip
- Signals: containerd 2.3 EOL 2028-04-30 · deprecation mentioned (no explicit date found)
- Platform/SRE — Plan: containerd 2.2 reaches EOL on 2026-11-06 (81 days), so plan migration to a supported branch before then; also note this patch disables checkpoint restore in CreateContainer by default, which may break CRIU-based workloads that haven’t set enable_experimental_restore_via_create.
- CI/CD — Skip
- Leader — Skip
- Signals: containerd 2.2 reaches EOL in 81d (2026-11-06) · deprecation mentioned (no explicit date found)
- Platform/SRE — Plan: Two regressions introduced in 29.7.0 — image pulls rejecting hardlink targets and file-permission failures on older kernels — are fixed in 29.7.2; if you upgraded to 29.7.x recently, schedule a patch to 29.7.2 to restore stable image pull behavior.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: Two confirmed regressions patched: image pulls failing for layers with implicit parent directories, and CopyToContainer rejecting valid symlink paths like /var/run. Schedule an upgrade to 29.7.1 if running 29.7.x in production.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: Upgrade Docker Engine to v29.7.0 to patch CVE-2026-17106 (go-archive archive-traversal fix) and resolve two daemon panic bugs in container network cleanup paths; the CVE is not KEV-listed so no hard deadline, but schedule this within the current sprint.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-17106 — CISA KEV: not listed, EPSS n/a
- Platform/SRE — Plan: Five CVEs fixed in Docker Engine including a command injection via git bundle checkout and a directory traversal that can wipe /tmp — no KEV listing or known active exploitation, but the severity warrants scheduling an upgrade to 29.6.2 this sprint.
- CI/CD — Plan: If Docker Engine runs on self-hosted CI runners or build hosts, the git-bundle command injection (CVE-2026-15793) and local-source upload bypass (CVE-2026-15789) are directly relevant to build-time workloads; plan to update runner environments to Docker 29.6.2.
- Leader — Skip
- Signals: CVE-2026-15788 — CISA KEV: not listed, EPSS n/a · CVE-2026-15789 — CISA KEV: not listed, EPSS n/a · CVE-2026-15791 — CISA KEV: not listed, EPSS n/a