<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Container-Runtime on CuraDevOps</title><link>https://curadevops.metacog.co.kr/tags/container-runtime/</link><description>Recent content in Container-Runtime on CuraDevOps</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 17 Aug 2026 12:38:40 +0000</lastBuildDate><atom:link href="https://curadevops.metacog.co.kr/tags/container-runtime/index.xml" rel="self" type="application/rss+xml"/><item><title>containerd 2.2.7 released; 2.2 branch EOL 2026-11-06</title><link>https://curadevops.metacog.co.kr/insights/2026-08-17-containerd-2-2-7/</link><pubDate>Mon, 17 Aug 2026 12:38:40 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-17-containerd-2-2-7/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> containerd 2.2 reaches EOL on 2026-11-06 (81 days), so plan migration to a supported branch before then; also note this patch disables checkpoint restore in CreateContainer by default, which may break CRIU-based workloads that haven&amp;rsquo;t set enable_experimental_restore_via_create.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> containerd 2.2 reaches EOL in 81d (2026-11-06) · deprecation mentioned (no explicit date found)&lt;/li>
&lt;/ul></description></item><item><title>containerd 2.3.4 released with breaking checkpoint-restore change</title><link>https://curadevops.metacog.co.kr/insights/2026-08-17-containerd-2-3-4/</link><pubDate>Mon, 17 Aug 2026 12:38:40 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-17-containerd-2-3-4/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> Despite being a patch release, 2.3.4 ships a breaking change: checkpoint restore in CreateContainer is now disabled by default, requiring an explicit config opt-in. Also fixes a memory leak in the OOM watcher and binary protobuf shim corruption. Review workloads using CRIU/checkpoint restore before upgrading; schedule the upgrade this quarter.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> containerd 2.3 EOL 2028-04-30 · deprecation mentioned (no explicit date found)&lt;/li>
&lt;/ul></description></item><item><title>Docker Engine 29.7.2 fixes image pull regressions from 29.7.0</title><link>https://curadevops.metacog.co.kr/insights/2026-08-10-v29-7-2/</link><pubDate>Mon, 10 Aug 2026 13:02:04 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-10-v29-7-2/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> Two regressions introduced in 29.7.0 — image pulls rejecting hardlink targets and file-permission failures on older kernels — are fixed in 29.7.2; if you upgraded to 29.7.x recently, schedule a patch to 29.7.2 to restore stable image pull behavior.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Docker Engine 29.7.0 patches CVE-2026-17106 and daemon panics</title><link>https://curadevops.metacog.co.kr/insights/2026-08-03-v29-7-0/</link><pubDate>Mon, 03 Aug 2026 14:33:55 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-03-v29-7-0/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> Upgrade Docker Engine to v29.7.0 to patch CVE-2026-17106 (go-archive archive-traversal fix) and resolve two daemon panic bugs in container network cleanup paths; the CVE is not KEV-listed so no hard deadline, but schedule this within the current sprint.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-17106 — CISA KEV: not listed, EPSS n/a&lt;/li>
&lt;/ul></description></item><item><title>Moby/Docker 29.7.1 fixes image-pull and container-copy regressions</title><link>https://curadevops.metacog.co.kr/insights/2026-08-03-v29-7-1/</link><pubDate>Mon, 03 Aug 2026 14:33:55 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-03-v29-7-1/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> Two confirmed regressions patched: image pulls failing for layers with implicit parent directories, and CopyToContainer rejecting valid symlink paths like /var/run. Schedule an upgrade to 29.7.1 if running 29.7.x in production.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Docker Engine 29.6.2 patches five security CVEs</title><link>https://curadevops.metacog.co.kr/insights/2026-07-20-v29-6-2/</link><pubDate>Mon, 20 Jul 2026 14:01:18 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-20-v29-6-2/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> Five CVEs fixed in Docker Engine including a command injection via git bundle checkout and a directory traversal that can wipe /tmp — no KEV listing or known active exploitation, but the severity warrants scheduling an upgrade to 29.6.2 this sprint.&lt;/li>
&lt;li>&lt;strong>CI/CD — Plan:&lt;/strong> If Docker Engine runs on self-hosted CI runners or build hosts, the git-bundle command injection (CVE-2026-15793) and local-source upload bypass (CVE-2026-15789) are directly relevant to build-time workloads; plan to update runner environments to Docker 29.6.2.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-15788 — CISA KEV: not listed, EPSS n/a · CVE-2026-15789 — CISA KEV: not listed, EPSS n/a · CVE-2026-15791 — CISA KEV: not listed, EPSS n/a&lt;/li>
&lt;/ul></description></item></channel></rss>