What is the Container Runtime Interface (CRI)?
CRI is the abstraction layer kubelet calls to start, stop and inspect containers, decoupling Kubernetes from any specific runtime. It satisfies the stem's requirement by defining the gRPC API between kubelet and runtimes such as containerd or CRI-O, so runtimes can be swapped without recompiling kubelet.
Why this answer
The Container Runtime Interface (CRI) is a plugin interface that enables the kubelet to use a variety of container runtimes without needing to recompile the kubelet. It defines a gRPC API (protocol buffers) for the kubelet to communicate with the container runtime, covering operations like pod lifecycle management and image management. Option D correctly identifies this as the API between the kubelet and the container runtime.
Exam trap
The trap here is that candidates often confuse the CRI with container image specifications (OCI Image Spec) or container runtime tools (like Docker), but the CRI is strictly an API interface between the kubelet and the runtime, not a tool or a specification for images.
How to eliminate wrong answers
Option A is wrong because building container images is the job of tools like Docker Build, Buildah, or Kaniko, not the CRI, which is an interface for runtime orchestration. Option B is wrong because the CRI does not standardize container runtime logs; log management is handled by the kubelet via the logging interface (e.g., using the 'kubectl logs' command) and the container runtime's logging driver. Option C is wrong because container image specifications are defined by the OCI Image Spec (Open Container Initiative), not by the CRI, which focuses on runtime operations like starting and stopping containers.