Container lifecycle

Kubelet containers are created inside a ready pod sandbox, then started, stopped, inspected, listed, streamed, and removed through the CRI v1 lifecycle. Repeated create/start/stop/remove calls are safe. Metadata, labels, annotations, image identity, timestamps, exit details, mounts, resources, users, and log paths are preserved in status responses.

Images named by canonical mocker.images metadata remain Stackie blocks. Other images use verified OCI content. Unsupported Linux fields fail the request explicitly; Stackie never silently weakens a security or namespace request.