Core Idea
The shim is the thin process that stays alive between the Docker engine and the runtime so it can reap the container and report exit status without keeping the daemon attached to the container.
- Purpose of a shim: lifecycle management and execution handoff to runtimes like runc.
- How the shim works, its benefits, and a process example.
- Evolution: how containerd took the shim idea further.
In Docker, a shim is a lightweight intermediary process that sits between the Docker Engine and a container runtime (such as runc). It plays a crucial role in managing the lifecycle and execution of containers. Here’s a breakdown of its purpose and functionality:
Purpose of a Docker Shim
-
Container Independence:
- When a container is started, the Docker Engine spawns a shim process. The shim allows the Docker Engine to detach from the container once it is running.
- This ensures that even if the Docker Engine or daemon crashes or is restarted, the container processes can continue running independently.
-
Signal Handling:
- The shim handles signals (e.g.,
SIGTERMorSIGKILL) sent to containers, forwarding them to the container’s main process. This ensures proper shutdown or restart of containers.
- The shim handles signals (e.g.,
-
Logging:
- It redirects container standard output (stdout) and standard error (stderr) streams to files or logging systems managed by Docker.
-
Container PID Management:
- The shim keeps track of the process ID (PID) of the container’s main process. This is used to monitor the health and status of the container.
How the Shim Works
- When you run a container:
- Docker spawns a shim process.
- The shim launches the container using a runtime like
runc(or another OCI-compliant runtime). - After the container is launched, the Docker daemon detaches and the shim remains as the parent of the container’s main process.
Benefits of Using a Shim
- Resilience: Containers continue to run even if the Docker daemon crashes or is restarted.
- Modularity: Abstracts the container runtime (
runcor others) from the Docker Engine, making it easier to swap or upgrade runtimes. - Simplified Cleanup: Handles cleanup and proper termination of containers when they stop.
Shim Process Example
If you inspect a running container, you may notice a shim process in the process tree. It typically looks like:
docker-containerd-shim -namespace moby -workdir /var/lib/containerd
This process bridges the Docker Engine and the container runtime, ensuring smooth container operation.
Evolution in Containerd
In modern Docker implementations, the shim is part of containerd, which manages container runtimes and abstracts low-level container operations. The containerd-shim handles the same responsibilities but within the containerd ecosystem.