crictl - CLI for CRI-compatible container runtimes (containerd) - what the kubelet sees
crictl [global options] command [command options]
Options you will use
ps [-a] [--name RE] [--pod ID] [-q]- containers; -a includes exited ones (the crashed attempts of a static pod)
pods [--name RE] [--namespace NS]- pod sandboxes on this node
logs [--tail N] [-p] ID- a container's log - works when the apiserver is down and kubectl cannot
inspect ID- state, exit code, reason, log path (JSON)
images / rmi --prune- images on the node; --prune deletes every image no container uses
stop ID / rm [-f] ID- stop or remove a container (the kubelet recreates it)
info- runtime + NetworkReady condition: "cni plugin not initialized" when the CNI config is gone
-r, --runtime-endpoint ENDPOINT- Endpoint of CRI container runtime service (unix:///run/containerd/containerd.sock).
-i, --image-endpoint ENDPOINT- Endpoint of CRI image manager service.
-c, --config FILE- Location of the client config file (default /etc/crictl.yaml).
Examples
$ sudo crictl ps -a --name kube-apiserverevery attempt of the apiserver container and how it ended
$ sudo crictl logs --tail 20 $(sudo crictl ps -a --name kube-apiserver -q | head -1)why the newest attempt died
$ sudo crictl rmi --prunefree image space on a node with DiskPressure
Gotchas
- crictl talks to /run/containerd/containerd.sock, which is root-only: without sudo you get "connect: permission denied".
- It lists containers, not Kubernetes objects: pods are sandboxes, static pods show up as normal containers.
- /etc/crictl.yaml sets the endpoint; without it crictl warns and tries the deprecated default list.
Taught in
Try crictl in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.