Instead of just swapping out the registry, try baking it into your machine image.
Instead of just swapping out the registry, try baking it into your machine image.
The nomad team made this configurable afterwards.
> This should be part of the containerd distribution
containerd is not the only CRI runtime out there.
Right, that’s the point. A user of the CRI should not have to care about this implementation detail.
> containerd is not the only CRI runtime out there.
Any CRI that needs a pause executable should come with one.
This detail is implemented by K8s, not a container runtime. User has to care about the source of it due to supply chain attacks, though.
> Any CRI that needs a pause executable should come with one.
Which would introduce a simultaneous update across different projects, which is a problem harder than a line of config.
You can also setup a separate service to "push" images directly to your container runtime, someone even demoed one in Show HN post some time ago I think.