Skip to content

Understand extension interfaces (CNI, CSI, CRI, etc.)

Kubernetes relies on a modular, plugin-driven architecture powered by standardised extension interfaces. These are known as the CRI (Container Runtime Interface), CNI (Container Network Interface), CSI (Container Storage Interface), and CPI (Cloud Provider Interface) to decouple core orchestration logic from underlying infrastructure.

These interfaces allow Kubernetes components like kubelet and the control plane to seamlessly interact with third-party container runtimes, networking fabrics, storage systems, and cloud environments.

This plug-and-play design ensures Kubernetes remains vendor-neutral, highly customizable, and capable of operating consistently across any environment, from bare-metal datacenters to managed cloud platforms.

We can visualise this as so:

graph TD
    %% Core Kubernetes Components
    subgraph K8S ["Kubernetes Core"]
        direction LR
        APISERVER["kube-apiserver<br/>(Control Plane)"]
        CCM["cloud-controller-manager<br/>(Control Plane)"]
        KUBELET["kubelet<br/>(Node Agent)"]
    end

    %% Container Runtime Interface
    subgraph CRI ["CRI (Container Runtime Interface)"]
        CRI_API["gRPC Interface<br/>(RuntimeService & ImageService)"]
        RUNTIMES["Container Runtimes<br/>(containerd / CRI-O)"]

        CRI_API --> RUNTIMES
    end

    %% Container Network Interface
    subgraph CNI ["CNI (Container Network Interface)"]
        CNI_SPEC["CNI Exec Plugin Spec<br/>(ADD / DEL / CHECK)"]
        NET_PLUGINS["Network Plugins<br/>(Calico / Cilium / Flannel)"]

        CNI_SPEC --> NET_PLUGINS
    end

    %% Container Storage Interface (Split into Controller & Node responsibilities)
    subgraph CSI ["CSI (Container Storage Interface)"]
        CSI_CTRL["CSI Controller Plugin<br/>(Provision & Attach)"]
        CSI_NODE["CSI Node Plugin<br/>(Format & Mount)"]
        STORAGE_DRIVERS["Storage Plugins<br/>(AWS EBS / Longhorn / Rook)"]

        CSI_CTRL --> STORAGE_DRIVERS
        CSI_NODE --> STORAGE_DRIVERS
    end

    %% Cloud Provider Interface
    subgraph CPI ["CPI (Cloud Provider Interface)"]
        CPI_API["CloudProvider Go Interface"]
        CLOUD_PROVIDERS["Cloud Infrastructure<br/>(AWS / GCP / Azure)"]

        CPI_API --> CLOUD_PROVIDERS
    end

    %% Explicit Interactions
    KUBELET -->|"1. Container Lifecycle"| CRI_API
    KUBELET -->|"2. Pod Network Setup"| CNI_SPEC

    APISERVER -->|"3a. Provisions & Attaches Volumes<br/>(via CSI Sidecars)"| CSI_CTRL
    KUBELET -->|"3b. Mounts Volumes to Pod"| CSI_NODE

    CCM -->|"4. Syncs Node / LB / Route Metadata"| CPI_API

Each plugin type has a specific purpose:

Interface Full Name Primary Responsibility Protocol Key Examples
CRI Container Runtime Interface Manages container lifecycles, image pulling, and pod sandboxes on the node gRPC over Unix Domain Socket containerd, CRI-O
CNI Container Network Interface Configures network interfaces, IP address allocation (IPAM), and routes for Pods Executable binary calls (ADD, DEL, CHECK) Calico, Cilium, Flannel
CSI Container Storage Interface Handles volume lifecycle (provisioning, attaching, mounting, snapshotting) gRPC (Identity, Controller, Node services) AWS EBS CSI, Longhorn, Rook/Ceph
CPI Cloud Provider Interface Integrates Kubernetes control plane with cloud provider infrastructure (Node metadata, LBs, Routes) Go interface inside cloud-controller-manager AWS, GCP, Azure, OpenStack plugins

Exam Tip

CNI and CSI drivers are usually deployed as standard Kubernetes workloads. Therefore, use kubectl to inspect and retrieve the logs for the respective pods for troubleshooting.