Skip to content

Infrastructure Platforms Comparison

Summary

Side-by-side comparison of Docker, Kubernetes, OpenStack and OpenNebula. They are not direct competitors: Docker builds and runs containers on a host, Kubernetes orchestrates containers across a cluster, and OpenStack and OpenNebula turn servers into VM clouds that Kubernetes often runs on. Versions and facts come from the refreshed topic pages (2026-09-25). For the VM-platform choice including Proxmox VE, see Proxmox VE vs OpenNebula vs OpenStack.

Quick Reference

Dimension Docker Kubernetes OpenStack OpenNebula
Type Container engine and toolchain Container orchestrator Cloud IaaS platform (cloud OS) Cloud management platform
Latest version Engine 29.8.1 (2026-09-15); Desktop 4.92.0; Compose v5.5.1 v1.37.1 (v1.37.0 "Garhwal" 2026-08-26) 2026.1 "Gazpacho" (2026-04-01, SLURP); 2026.2 "Hibiscus" planned 2026-09-30 7.4.1 (2026-09-10); 7.4 "Helix"
Primary workload Containers Containers (Pods) VMs and bare metal VMs (KVM) and LXC system containers, edge clusters
Architecture Client and daemon (dockerd on containerd and runc) Desired-state, distributed control plane Distributed services over a message bus Centralized daemon (oned)
Language Go Go Python C++ (oned), Ruby, JavaScript
License Engine, CLI, Compose, BuildKit: Apache-2.0. Desktop: proprietary Apache-2.0 Apache-2.0 Community Edition Apache-2.0; Enterprise Edition commercial subscription
Governance Docker, Inc. and the Moby project CNCF (Linux Foundation), graduated 2018 Technical Committee under the OpenInfra Foundation, part of the Linux Foundation since 2025 OpenNebula Systems plus community

Platform Layer Positioning

The diagram shows which stack layer each platform manages; the layers stack rather than compete.

flowchart TB
    subgraph Layer["Technology stack layers"]
        direction TB
        APP["Application layer<br/>(microservices, APIs)"]
        ORCH["Orchestration layer<br/>(scheduling, scaling, self-healing)"]
        INFRA["Infrastructure layer<br/>(compute, network, storage)"]
        HW["Hardware<br/>(bare metal, data center)"]
    end

    Docker["Docker<br/>(builds and runs OCI images)"] -.->|"packages apps"| APP
    K8s["Kubernetes<br/>(orchestrator)"] -.->|"manages containers"| ORCH
    OS["OpenStack<br/>(IaaS)"] -.->|"manages infrastructure"| INFRA
    ON["OpenNebula<br/>(cloud manager)"] -.->|"manages infrastructure"| INFRA

    style APP fill:#0db7ed,color:#fff
    style ORCH fill:#326ce5,color:#fff
    style INFRA fill:#ef3e42,color:#fff

Key insight

These platforms are frequently used together: Kubernetes on OpenStack or OpenNebula VMs (Magnum, Cluster API, OneKS), and images built with Docker running on Kubernetes through containerd.

Which One Should I Pick?

Start from the workload and the team, not the product. The flowchart matches the use-case matrix below.

flowchart TD
    START["What do you need to run?"] --> Q1{"Containers or VMs?"}
    Q1 -->|"Containers"| Q2{"More than one host,<br/>self-healing, autoscaling?"}
    Q2 -->|"No: one host, dev or CI"| DOCKER["Docker Engine + Compose"]
    Q2 -->|"Yes, simple and small"| SWARM["Docker Swarm mode<br/>(maintained, niche)"]
    Q2 -->|"Yes, at scale"| Q3{"Platform team to run<br/>control planes?"}
    Q3 -->|"No"| MANAGED["Managed Kubernetes<br/>(EKS, GKE, AKS, ACK, TKE)"]
    Q3 -->|"Yes"| K8S["Self-managed Kubernetes"]
    Q1 -->|"VMs"| Q4{"Multi-tenant IaaS at hundreds<br/>to thousands of nodes, NFV,<br/>bare metal as a service?"}
    Q4 -->|"Yes"| OPENSTACK["OpenStack<br/>(often via a vendor distribution)"]
    Q4 -->|"No"| Q5{"Need cloud self-service,<br/>VDC tenancy, edge or GPU factory?"}
    Q5 -->|"Yes"| OPENNEBULA["OpenNebula"]
    Q5 -->|"No, a virtualization cluster"| PVE["Proxmox VE<br/>(see the Proxmox comparison)"]
    Q1 -->|"Both"| BOTH["Kubernetes on OpenStack or OpenNebula VMs,<br/>or KubeVirt for VMs inside Kubernetes"]

Architecture Comparison

Aspect Docker Kubernetes OpenStack OpenNebula
Architecture style Single daemon (dockerd) per host Distributed control plane plus worker nodes Dozens of services (42 official project teams, 2026-09), each with its own API and workers Centralized front-end (oned plus scheduler) with thin hypervisor nodes
State store Local filesystem; Swarm uses a Raft store on managers etcd (distributed key-value store) MariaDB/Galera plus RabbitMQ (RPC) SQLite (default) or MySQL/MariaDB
Scheduling None on a single host; Swarm schedules services kube-scheduler (filter, score, bind) nova-scheduler with Placement (filter, weigh) Rank scheduler plus OneDRS (ILP solver with usage forecasts)
Networking bridge, overlay (Swarm, VXLAN), macvlan CNI plugins (Cilium, Calico, Flannel) Neutron with ML2/OVN or ML2/OVS (Linux bridge driver removed in 2025.1) Linux bridge, 802.1Q VLAN, VXLAN, Open vSwitch, SR-IOV
Storage Volumes, bind mounts PV/PVC with CSI drivers Cinder, Glance, Swift or Ceph RGW, typically on Ceph Datastores over Ceph, NFS, local disks, LVM SAN, NetApp ONTAP, Pure Storage
API REST (Docker Engine API) REST (Kubernetes API, protobuf or JSON) REST (per-service APIs, catalog in Keystone) XML-RPC (:2633) and gRPC (:2634, since 7.2)
HA Single daemon; Swarm mode replicates managers with Raft Multiple control-plane nodes with an etcd quorum API services active/active behind HAProxy; Galera multi-primary (writes usually pinned to one node); RabbitMQ quorum queues Three or more front-ends with built-in Raft: one leader behind a floating IP

Scalability Comparison

Dimension Docker Kubernetes OpenStack OpenNebula
Max nodes 1 per Engine; Swarm for small multi-host clusters 5,000 nodes (upstream-tested); GKE 65,000, EKS up to 100,000 Hundreds to thousands per cloud (Nova cells v2 shard DB and bus) 500 hypervisors certified per oned; users report ~2,000; federation beyond
Max workloads Host-bound 150,000 pods, 110 pods per node (upstream-tested) 50,000+ VMs in large clouds (order-of-magnitude estimate) 20,000 VMs on 1,250 hosts in the 7.2 gRPC benchmark (synthetic)
Horizontal scaling Via Swarm or an orchestrator Native (HPA, VPA, Cluster Autoscaler) Add compute nodes and cells Add KVM hosts and clusters
Multi-region No Multi-cluster via add-ons (Cluster API, fleet managers) Regions sharing Keystone Federated zones sharing users, groups and ACLs
Edge Yes (lightweight hosts) Yes (k3s and other lightweight distributions) Possible, but the control plane is heavy Edge-native: OneForm provisions remote clusters on-premises, on bare-metal providers or on clouds

Operational Complexity

Estimates

Install times, team sizes and staff figures in this section and in the cost table are rough engineering estimates carried over from earlier versions of this page, not sourced measurements. Use them only as orders of magnitude.

Dimension Docker Kubernetes OpenStack OpenNebula
Install time Minutes Hours (kubeadm) to minutes (managed) Days to weeks Hours
Team size needed Developer self-service 2-5 SREs (fewer on managed) Dedicated platform team 1-3 admins
Day-2 operations Minimal Moderate (upgrades every ~4 months, etcd, CNI) Heavy (many services, RabbitMQ, Galera, OVN) Light (one daemon, one database, one log)
Upgrade path Package upgrade; Engine minor every ~5-6 weeks One minor at a time; ~3 minors a year, each with ~12 months of patches plus 2 months of maintenance SLURP skip-level upgrades between .1 releases (for example 2025.1 to 2026.1) Package upgrade plus onedb upgrade; minor release about every 6 months
Troubleshooting Simple (docker logs, inspect) Moderate (events, describe, logs) Complex (per-service logs across the constellation) Simple (oned.log)
Learning curve Low High Very high Low to moderate

Security Comparison

Dimension Docker Kubernetes OpenStack OpenNebula
Isolation model Namespaces, cgroups, seccomp Same kernel primitives plus Pod Security Standards; user namespaces GA (1.36) Hypervisor (KVM) isolation Hypervisor (KVM) isolation; LXC for system containers
Multi-tenancy No (single host, single admin) Namespaces, RBAC, quotas (soft multi-tenancy) Full: domains, projects, quotas, per-project networks Full: users, groups, VDCs, ACLs, quotas
Network policies iptables (default) or nftables (experimental, not with Swarm) NetworkPolicy via the CNI Security groups (OVN or OVS) Security groups
Secrets management Swarm secrets Kubernetes Secrets (base64; enable encryption at rest) Barbican VM contextualization; external secret stores
Image security Docker Scout, Docker Hardened Images Admission control (ValidatingAdmissionPolicy, Gatekeeper, Kyverno) Not applicable (VM images) Not applicable (VM images)
RBAC Limited (Engine is root-equivalent) Fine-grained RBAC Keystone roles plus per-service policy Groups and ACLs
Rootless Yes (rootless mode) Rootless kubelet (KubeletInUserNamespace) beta in 1.37 Not applicable (VMs) Not applicable (VMs)

Use Case Decision Matrix

Use case Recommended platform
Local development Docker
CI/CD image building Docker (BuildKit, Buildx)
Microservices at scale Kubernetes
Cloud-native applications Kubernetes
Large private cloud (hundreds to thousands of nodes, many tenants) OpenStack
Telecom / NFV OpenStack
VMware replacement (multi-tenant enterprise) OpenStack or OpenNebula
VMware replacement (virtualization cluster, one team) Proxmox VE or OpenNebula (see the Proxmox comparison)
Edge computing OpenNebula (OneForm) or lightweight Kubernetes (k3s)
AI / GPU factory OpenNebula (NVIDIA GPU fabric orchestration) or Kubernetes with DRA (see AI Platform Engineering)
Hybrid clusters on public-cloud or bare-metal providers OpenNebula (OneForm provisions clusters; the old ec2/azure bursting drivers were removed in 7.0) or Kubernetes multi-cluster
Research / university lab OpenNebula
Bare metal provisioning OpenStack (Ironic)
Kubernetes clusters on private IaaS OpenStack (Magnum or Cluster API provider CAPO) or OpenNebula (OneKS)

How They Work Together

A common enterprise stack puts all four on separate layers of one data center.

flowchart TB
    subgraph DataCenter["Enterprise data center"]
        subgraph IaaS["IaaS layer"]
            OS_DC["OpenStack<br/>(or OpenNebula)"]
        end

        subgraph K8sLayer["Orchestration layer"]
            K8s_DC["Kubernetes cluster<br/>(on IaaS VMs via Cluster API or Magnum)"]
        end

        subgraph AppLayer["Application layer"]
            Docker_DC["Containers from OCI images<br/>(built with Docker, run by containerd)"]
        end
    end

    OS_DC -->|"provisions VMs"| K8sLayer
    K8sLayer -->|"schedules containers"| AppLayer

    style IaaS fill:#ef3e42,color:#fff
    style K8sLayer fill:#326ce5,color:#fff
    style AppLayer fill:#0db7ed,color:#fff

Community and Ecosystem

Metric Docker Kubernetes OpenStack OpenNebula
GitHub stars ~70k+ (moby/moby, recorded by 2026-09) ~115k+ (2026-07) N/A (developed on OpenDev; GitHub is a read-only mirror) ~1.5k (recorded by 2026-08)
Release cadence Engine minor every ~5-6 weeks; Desktop roughly weekly ~3 minors a year, monthly patches Every 6 months; .1 releases are SLURP Minor about every 6 months; EE maintenance releases about every 3 months
Ecosystem Docker Hub, Hardened Images, Compose CNCF landscape, operators, Helm 42 official project teams, several vendor distributions Marketplace, OneFlow, OneKS, NVIDIA integrations
Commercial support Docker, Inc. (Desktop, Hub, Scout subscriptions) Cloud providers and distributions (for example Red Hat, SUSE) Canonical, Red Hat, Rackspace, VEXXHOST and others OpenNebula Systems (Enterprise Edition)
Managed offerings Docker Hub, Build Cloud EKS, GKE, AKS, ACK, TKE and others Managed private or public clouds (for example Rackspace, VEXXHOST, OVHcloud) Enterprise Edition from OpenNebula Systems; managed service providers are a target user group

Cost Comparison (100 VM or container equivalent)

Cost item Docker Kubernetes (self-hosted) OpenStack OpenNebula
Software license Engine free; Desktop paid in larger companies Free Free Free (CE)
Infrastructure 1 server 3 control-plane nodes + N workers 3 controllers (RabbitMQ and Galera quorum) + N compute 1 front-end (3 for HA) + N hosts
Operational staff (estimate) Near 0 FTE 1-2 FTE 3-5 FTE 0.5-1 FTE
Paid subscriptions Desktop Pro $11/mo ($9 annual), Team $16/mo ($15 annual), Business $24/user/mo Managed control plane $0.10/hr per cluster on EKS, GKE and AKS Standard; distribution subscriptions quote-based Vendor distributions quote-based EE subscription: base fee plus per-node fee; no official price list verified (2026-09)
Total annual (estimate) < $5k $50-200k $200-500k+ $10-50k

Migration and Lock-in

Dimension Docker Kubernetes OpenStack OpenNebula
Vendor lock-in risk Low (OCI standard) Low (CNCF conformance); add-ons create lock-in Low at the software level (open APIs, Apache-2.0); switching deployment tools usually means a redeploy Low (Apache-2.0 CE, open formats); some integrations are EE-only
Image portability OCI (universal) OCI QCOW2, RAW, VMDK QCOW2, RAW, VMDK
Migration tools docker save / load, registries Velero, etcd backup, GitOps repos, Cluster API VMware driver and migration tooling; vendor tools OneSwap (VMware import), OneDRS
Exit cost Minimal Moderate (Kubernetes-specific manifests) High (deep integration, operational know-how) Low to moderate

Sources

Facts come from the vault topic pages, which carry the primary sources: Docker, Kubernetes, OpenStack, OpenNebula.