---
title: Charmhub | Deploy Containerd using Charmhub - The Open Operator Collection
description: Deploy the latest version of Containerd on any cloud.
url: https://charmhub.io/containerd/configurations
---

# Containerd

[Canonical Kubernetes](https://charmhub.io/publisher/containers "View all packages from Canonical Kubernetes")

* [Canonical Kubernetes](https://charmhub.io/publisher/containers "View all packages from Canonical Kubernetes")

Platform:

24.04

22.04

20.04

18.04

16.04

stable 4d5c139

```
juju deploy containerd
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [config\_version](https://charmhub.io/containerd/configurations#config_version)
* [custom-registry-ca](https://charmhub.io/containerd/configurations#custom-registry-ca)
* [custom\_registries](https://charmhub.io/containerd/configurations#custom_registries)
* [disable-juju-proxy](https://charmhub.io/containerd/configurations#disable-juju-proxy)
* [enable-cgroups](https://charmhub.io/containerd/configurations#enable-cgroups)
* [gpu\_driver](https://charmhub.io/containerd/configurations#gpu_driver)
* [http\_proxy](https://charmhub.io/containerd/configurations#http_proxy)
* [https\_proxy](https://charmhub.io/containerd/configurations#https_proxy)
* [kill\_signal](https://charmhub.io/containerd/configurations#kill_signal)
* [no\_proxy](https://charmhub.io/containerd/configurations#no_proxy)
* [nvidia\_apt\_key\_urls](https://charmhub.io/containerd/configurations#nvidia_apt_key_urls)
* [nvidia\_apt\_packages](https://charmhub.io/containerd/configurations#nvidia_apt_packages)
* [nvidia\_apt\_sources](https://charmhub.io/containerd/configurations#nvidia_apt_sources)
* [runtime](https://charmhub.io/containerd/configurations#runtime)
* [shim](https://charmhub.io/containerd/configurations#shim)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* config\_version | string

  Default: v2

  Containerd config version. Can be "v1" or "v2".

  DEPRECATED: config\_version will be removed in a future release.
* custom-registry-ca | string

  Base64 encoded Certificate Authority (CA) bundle. Setting this config
  allows container runtimes to pull images from registries with TLS
  certificates signed by an external CA.
* custom\_registries | string

  Default: []

  Registry endpoints and credentials. Setting this config allows Kubelet
  to pull images from registries where auth is required.

  The value for this config must be a JSON array of credential objects, like this:
  e.g.: [{"host": "my.registry:port", "username": "user", "password": "pass"}]

  Credential Object Parameters:
  `url: REQUIRED str`
  the URL to the registry, include the port if not it isn't implied from the schema.
  e.g: "url": "https://my.registry:8443"
  e.g: "url": "http://my.registry"

  host: OPTIONAL str - defaults to auto-generated from the url
  could be registry host address or a name
  e.g.: myregistry.io:9000, 10.10.10.10:5432
  e.g.: myregistry.io, myregistry
  Note: It will be derived from `url` if not provided.
  e.g.: "url": "http://10.10.10.10:8000" --> "host": "10.10.10.10:8000"

  username: OPTIONAL str - default ''
  password: OPTIONAL str|dict - default ''
  Used by containerd for basic authentication to the registry.
  If a string, will be rendered wrapped as a double-quoted str (password = "my-strong-password")
  If a dictionary, will be rendered as a single-quoted json (password = '{"my": "json"}')
  e.g.: "password": '"$(jq -c . gce.json)"'

  ca\_file: OPTIONAL str - default ''
  cert\_file: OPTIONAL str - default ''
  key\_file: OPTIONAL str - default ''
  For ssl/tls communication these should be a base64 encoded file
  e.g.: "ca\_file": "'"$(base64 -w 0 < my.custom.registry.pem)"'"

  insecure\_skip\_verify: OPTIONAL bool - default false
  For situatations where the registry has self-signed or expired certs and a quick work-around is necessary.
  e.g.: "insecure\_skip\_verify": true

  example config)
  juju config containerd custom\_registries='[{
  "url": "https://registry.example.com",
  "ca\_file": "'"$(base64 -w 0 < ~/my.custom.ca.pem)"'",
  "cert\_file": "'"$(base64 -w 0 < ~/my.custom.cert.pem)"'",
  "key\_file": "'"$(base64 -w 0 < ~/my.custom.key.pem)"'",
  }]'
* disable-juju-proxy | boolean

  Ignore juju-http(s) proxy settings on this charm.
  If set to true, all juju https proxy settings will be ignored
* enable-cgroups | boolean

  Enable GRUB cgroup overrides cgroup\_enable=memory swapaccount=1. WARNING
  changing this option will reboot the host - use with caution on production
  services.
* gpu\_driver | string

  Default: auto

  Override GPU driver installation. Options are "auto", "nvidia", "none".

  Caution: setting this to nvidia will cause nvidia drivers to be installed on kubernetes-control-plane, even if a GPU is not present.
* http\_proxy | string

  URL to use for HTTP\_PROXY to be used by Containerd. Useful in
  egress-filtered environments where a proxy is the only option for
  accessing the registry to pull images.
* https\_proxy | string

  URL to use for HTTPS\_PROXY to be used by Containerd. Useful in
  egress-filtered environments where a proxy is the only option for
  accessing the registry to pull images.
* kill\_signal | string

  Default: SIGTERM

  Set containerd systemd KillSignal. Options are standard signals from
  https://man7.org/linux/man-pages/man7/signal.7.html
* no\_proxy | string

  Comma-separated list of destinations (either domain names or IP
  addresses) which should be accessed directly, rather than through
  the proxy defined in http\_proxy or https\_proxy. Must be less than
  2023 characters long.
* nvidia\_apt\_key\_urls | string

  Default: https://nvidia.github.io/nvidia-container-runtime/gpgkey
  https://developer.download.nvidia.com/compute/cuda/repos/{id}{version\_id\_no\_dot}/x86\_64/3bf863cc.pub

  Space-separated list of APT GPG key URLs to add when using Nvidia GPUs.

  Supported template options:
  {id}: OS release ID, e.g. "ubuntu"
  {version\_id}: OS release version ID, e.g. "20.04"
  {version\_id\_no\_dot}: OS release version ID with no dot, e.g. "2004"
* nvidia\_apt\_packages | string

  Default: cuda-drivers nvidia-container-runtime

  Space-separated list of APT packages to install when using Nvidia GPUs.
* nvidia\_apt\_sources | string

  Default: deb https://nvidia.github.io/libnvidia-container/stable/deb/$(ARCH) /
  deb https://nvidia.github.io/nvidia-container-runtime/{id}{version\_id}/$(ARCH) /
  deb https://developer.download.nvidia.com/compute/cuda/repos/{id}{version\_id\_no\_dot}/x86\_64 /

  Newline-separated list of APT sources to add when using Nvidia GPUs.

  Supported template options:
  {id}: OS release ID, e.g. "ubuntu"
  {version\_id}: OS release version ID, e.g. "20.04"
  {version\_id\_no\_dot}: OS release version ID with no dot, e.g. "2004"
* runtime | string

  Default: auto

  Set a custom containerd runtime. Set "auto" to select based on hardware.
* shim | string

  Default: containerd-shim

  Set a custom containerd shim.
