Infrastructure Platforms Comparison¶
Summary
Side-by-side comparison of Docker, Kubernetes, OpenStack and OpenNebula. They are not direct competitors: Docker builds and runs containers on a host, Kubernetes orchestrates containers across a cluster, and OpenStack and OpenNebula turn servers into VM clouds that Kubernetes often runs on. Versions and facts come from the refreshed topic pages (2026-09-25). For the VM-platform choice including Proxmox VE, see Proxmox VE vs OpenNebula vs OpenStack.
Quick Reference¶
| Dimension | Docker | Kubernetes | OpenStack | OpenNebula |
|---|---|---|---|---|
| Type | Container engine and toolchain | Container orchestrator | Cloud IaaS platform (cloud OS) | Cloud management platform |
| Latest version | Engine 29.8.1 (2026-09-15); Desktop 4.92.0; Compose v5.5.1 | v1.37.1 (v1.37.0 "Garhwal" 2026-08-26) | 2026.1 "Gazpacho" (2026-04-01, SLURP); 2026.2 "Hibiscus" planned 2026-09-30 | 7.4.1 (2026-09-10); 7.4 "Helix" |
| Primary workload | Containers | Containers (Pods) | VMs and bare metal | VMs (KVM) and LXC system containers, edge clusters |
| Architecture | Client and daemon (dockerd on containerd and runc) |
Desired-state, distributed control plane | Distributed services over a message bus | Centralized daemon (oned) |
| Language | Go | Go | Python | C++ (oned), Ruby, JavaScript |
| License | Engine, CLI, Compose, BuildKit: Apache-2.0. Desktop: proprietary | Apache-2.0 | Apache-2.0 | Community Edition Apache-2.0; Enterprise Edition commercial subscription |
| Governance | Docker, Inc. and the Moby project | CNCF (Linux Foundation), graduated 2018 | Technical Committee under the OpenInfra Foundation, part of the Linux Foundation since 2025 | OpenNebula Systems plus community |
Platform Layer Positioning¶
The diagram shows which stack layer each platform manages; the layers stack rather than compete.
flowchart TB
subgraph Layer["Technology stack layers"]
direction TB
APP["Application layer<br/>(microservices, APIs)"]
ORCH["Orchestration layer<br/>(scheduling, scaling, self-healing)"]
INFRA["Infrastructure layer<br/>(compute, network, storage)"]
HW["Hardware<br/>(bare metal, data center)"]
end
Docker["Docker<br/>(builds and runs OCI images)"] -.->|"packages apps"| APP
K8s["Kubernetes<br/>(orchestrator)"] -.->|"manages containers"| ORCH
OS["OpenStack<br/>(IaaS)"] -.->|"manages infrastructure"| INFRA
ON["OpenNebula<br/>(cloud manager)"] -.->|"manages infrastructure"| INFRA
style APP fill:#0db7ed,color:#fff
style ORCH fill:#326ce5,color:#fff
style INFRA fill:#ef3e42,color:#fff
Key insight
These platforms are frequently used together: Kubernetes on OpenStack or OpenNebula VMs (Magnum, Cluster API, OneKS), and images built with Docker running on Kubernetes through containerd.
Which One Should I Pick?¶
Start from the workload and the team, not the product. The flowchart matches the use-case matrix below.
flowchart TD
START["What do you need to run?"] --> Q1{"Containers or VMs?"}
Q1 -->|"Containers"| Q2{"More than one host,<br/>self-healing, autoscaling?"}
Q2 -->|"No: one host, dev or CI"| DOCKER["Docker Engine + Compose"]
Q2 -->|"Yes, simple and small"| SWARM["Docker Swarm mode<br/>(maintained, niche)"]
Q2 -->|"Yes, at scale"| Q3{"Platform team to run<br/>control planes?"}
Q3 -->|"No"| MANAGED["Managed Kubernetes<br/>(EKS, GKE, AKS, ACK, TKE)"]
Q3 -->|"Yes"| K8S["Self-managed Kubernetes"]
Q1 -->|"VMs"| Q4{"Multi-tenant IaaS at hundreds<br/>to thousands of nodes, NFV,<br/>bare metal as a service?"}
Q4 -->|"Yes"| OPENSTACK["OpenStack<br/>(often via a vendor distribution)"]
Q4 -->|"No"| Q5{"Need cloud self-service,<br/>VDC tenancy, edge or GPU factory?"}
Q5 -->|"Yes"| OPENNEBULA["OpenNebula"]
Q5 -->|"No, a virtualization cluster"| PVE["Proxmox VE<br/>(see the Proxmox comparison)"]
Q1 -->|"Both"| BOTH["Kubernetes on OpenStack or OpenNebula VMs,<br/>or KubeVirt for VMs inside Kubernetes"]
Architecture Comparison¶
| Aspect | Docker | Kubernetes | OpenStack | OpenNebula |
|---|---|---|---|---|
| Architecture style | Single daemon (dockerd) per host |
Distributed control plane plus worker nodes | Dozens of services (42 official project teams, 2026-09), each with its own API and workers | Centralized front-end (oned plus scheduler) with thin hypervisor nodes |
| State store | Local filesystem; Swarm uses a Raft store on managers | etcd (distributed key-value store) | MariaDB/Galera plus RabbitMQ (RPC) | SQLite (default) or MySQL/MariaDB |
| Scheduling | None on a single host; Swarm schedules services | kube-scheduler (filter, score, bind) | nova-scheduler with Placement (filter, weigh) | Rank scheduler plus OneDRS (ILP solver with usage forecasts) |
| Networking | bridge, overlay (Swarm, VXLAN), macvlan | CNI plugins (Cilium, Calico, Flannel) | Neutron with ML2/OVN or ML2/OVS (Linux bridge driver removed in 2025.1) | Linux bridge, 802.1Q VLAN, VXLAN, Open vSwitch, SR-IOV |
| Storage | Volumes, bind mounts | PV/PVC with CSI drivers | Cinder, Glance, Swift or Ceph RGW, typically on Ceph | Datastores over Ceph, NFS, local disks, LVM SAN, NetApp ONTAP, Pure Storage |
| API | REST (Docker Engine API) | REST (Kubernetes API, protobuf or JSON) | REST (per-service APIs, catalog in Keystone) | XML-RPC (:2633) and gRPC (:2634, since 7.2) |
| HA | Single daemon; Swarm mode replicates managers with Raft | Multiple control-plane nodes with an etcd quorum | API services active/active behind HAProxy; Galera multi-primary (writes usually pinned to one node); RabbitMQ quorum queues | Three or more front-ends with built-in Raft: one leader behind a floating IP |
Scalability Comparison¶
| Dimension | Docker | Kubernetes | OpenStack | OpenNebula |
|---|---|---|---|---|
| Max nodes | 1 per Engine; Swarm for small multi-host clusters | 5,000 nodes (upstream-tested); GKE 65,000, EKS up to 100,000 | Hundreds to thousands per cloud (Nova cells v2 shard DB and bus) | 500 hypervisors certified per oned; users report ~2,000; federation beyond |
| Max workloads | Host-bound | 150,000 pods, 110 pods per node (upstream-tested) | 50,000+ VMs in large clouds (order-of-magnitude estimate) | 20,000 VMs on 1,250 hosts in the 7.2 gRPC benchmark (synthetic) |
| Horizontal scaling | Via Swarm or an orchestrator | Native (HPA, VPA, Cluster Autoscaler) | Add compute nodes and cells | Add KVM hosts and clusters |
| Multi-region | No | Multi-cluster via add-ons (Cluster API, fleet managers) | Regions sharing Keystone | Federated zones sharing users, groups and ACLs |
| Edge | Yes (lightweight hosts) | Yes (k3s and other lightweight distributions) | Possible, but the control plane is heavy | Edge-native: OneForm provisions remote clusters on-premises, on bare-metal providers or on clouds |
Operational Complexity¶
Estimates
Install times, team sizes and staff figures in this section and in the cost table are rough engineering estimates carried over from earlier versions of this page, not sourced measurements. Use them only as orders of magnitude.
| Dimension | Docker | Kubernetes | OpenStack | OpenNebula |
|---|---|---|---|---|
| Install time | Minutes | Hours (kubeadm) to minutes (managed) | Days to weeks | Hours |
| Team size needed | Developer self-service | 2-5 SREs (fewer on managed) | Dedicated platform team | 1-3 admins |
| Day-2 operations | Minimal | Moderate (upgrades every ~4 months, etcd, CNI) | Heavy (many services, RabbitMQ, Galera, OVN) | Light (one daemon, one database, one log) |
| Upgrade path | Package upgrade; Engine minor every ~5-6 weeks | One minor at a time; ~3 minors a year, each with ~12 months of patches plus 2 months of maintenance | SLURP skip-level upgrades between .1 releases (for example 2025.1 to 2026.1) |
Package upgrade plus onedb upgrade; minor release about every 6 months |
| Troubleshooting | Simple (docker logs, inspect) |
Moderate (events, describe, logs) |
Complex (per-service logs across the constellation) | Simple (oned.log) |
| Learning curve | Low | High | Very high | Low to moderate |
Security Comparison¶
| Dimension | Docker | Kubernetes | OpenStack | OpenNebula |
|---|---|---|---|---|
| Isolation model | Namespaces, cgroups, seccomp | Same kernel primitives plus Pod Security Standards; user namespaces GA (1.36) | Hypervisor (KVM) isolation | Hypervisor (KVM) isolation; LXC for system containers |
| Multi-tenancy | No (single host, single admin) | Namespaces, RBAC, quotas (soft multi-tenancy) | Full: domains, projects, quotas, per-project networks | Full: users, groups, VDCs, ACLs, quotas |
| Network policies | iptables (default) or nftables (experimental, not with Swarm) | NetworkPolicy via the CNI | Security groups (OVN or OVS) | Security groups |
| Secrets management | Swarm secrets | Kubernetes Secrets (base64; enable encryption at rest) | Barbican | VM contextualization; external secret stores |
| Image security | Docker Scout, Docker Hardened Images | Admission control (ValidatingAdmissionPolicy, Gatekeeper, Kyverno) | Not applicable (VM images) | Not applicable (VM images) |
| RBAC | Limited (Engine is root-equivalent) | Fine-grained RBAC | Keystone roles plus per-service policy | Groups and ACLs |
| Rootless | Yes (rootless mode) | Rootless kubelet (KubeletInUserNamespace) beta in 1.37 |
Not applicable (VMs) | Not applicable (VMs) |
Use Case Decision Matrix¶
| Use case | Recommended platform |
|---|---|
| Local development | Docker |
| CI/CD image building | Docker (BuildKit, Buildx) |
| Microservices at scale | Kubernetes |
| Cloud-native applications | Kubernetes |
| Large private cloud (hundreds to thousands of nodes, many tenants) | OpenStack |
| Telecom / NFV | OpenStack |
| VMware replacement (multi-tenant enterprise) | OpenStack or OpenNebula |
| VMware replacement (virtualization cluster, one team) | Proxmox VE or OpenNebula (see the Proxmox comparison) |
| Edge computing | OpenNebula (OneForm) or lightweight Kubernetes (k3s) |
| AI / GPU factory | OpenNebula (NVIDIA GPU fabric orchestration) or Kubernetes with DRA (see AI Platform Engineering) |
| Hybrid clusters on public-cloud or bare-metal providers | OpenNebula (OneForm provisions clusters; the old ec2/azure bursting drivers were removed in 7.0) or Kubernetes multi-cluster |
| Research / university lab | OpenNebula |
| Bare metal provisioning | OpenStack (Ironic) |
| Kubernetes clusters on private IaaS | OpenStack (Magnum or Cluster API provider CAPO) or OpenNebula (OneKS) |
How They Work Together¶
A common enterprise stack puts all four on separate layers of one data center.
flowchart TB
subgraph DataCenter["Enterprise data center"]
subgraph IaaS["IaaS layer"]
OS_DC["OpenStack<br/>(or OpenNebula)"]
end
subgraph K8sLayer["Orchestration layer"]
K8s_DC["Kubernetes cluster<br/>(on IaaS VMs via Cluster API or Magnum)"]
end
subgraph AppLayer["Application layer"]
Docker_DC["Containers from OCI images<br/>(built with Docker, run by containerd)"]
end
end
OS_DC -->|"provisions VMs"| K8sLayer
K8sLayer -->|"schedules containers"| AppLayer
style IaaS fill:#ef3e42,color:#fff
style K8sLayer fill:#326ce5,color:#fff
style AppLayer fill:#0db7ed,color:#fff
Community and Ecosystem¶
| Metric | Docker | Kubernetes | OpenStack | OpenNebula |
|---|---|---|---|---|
| GitHub stars | ~70k+ (moby/moby, recorded by 2026-09) | ~115k+ (2026-07) | N/A (developed on OpenDev; GitHub is a read-only mirror) | ~1.5k (recorded by 2026-08) |
| Release cadence | Engine minor every ~5-6 weeks; Desktop roughly weekly | ~3 minors a year, monthly patches | Every 6 months; .1 releases are SLURP |
Minor about every 6 months; EE maintenance releases about every 3 months |
| Ecosystem | Docker Hub, Hardened Images, Compose | CNCF landscape, operators, Helm | 42 official project teams, several vendor distributions | Marketplace, OneFlow, OneKS, NVIDIA integrations |
| Commercial support | Docker, Inc. (Desktop, Hub, Scout subscriptions) | Cloud providers and distributions (for example Red Hat, SUSE) | Canonical, Red Hat, Rackspace, VEXXHOST and others | OpenNebula Systems (Enterprise Edition) |
| Managed offerings | Docker Hub, Build Cloud | EKS, GKE, AKS, ACK, TKE and others | Managed private or public clouds (for example Rackspace, VEXXHOST, OVHcloud) | Enterprise Edition from OpenNebula Systems; managed service providers are a target user group |
Cost Comparison (100 VM or container equivalent)¶
| Cost item | Docker | Kubernetes (self-hosted) | OpenStack | OpenNebula |
|---|---|---|---|---|
| Software license | Engine free; Desktop paid in larger companies | Free | Free | Free (CE) |
| Infrastructure | 1 server | 3 control-plane nodes + N workers | 3 controllers (RabbitMQ and Galera quorum) + N compute | 1 front-end (3 for HA) + N hosts |
| Operational staff (estimate) | Near 0 FTE | 1-2 FTE | 3-5 FTE | 0.5-1 FTE |
| Paid subscriptions | Desktop Pro $11/mo ($9 annual), Team $16/mo ($15 annual), Business $24/user/mo | Managed control plane $0.10/hr per cluster on EKS, GKE and AKS Standard; distribution subscriptions quote-based | Vendor distributions quote-based | EE subscription: base fee plus per-node fee; no official price list verified (2026-09) |
| Total annual (estimate) | < $5k | $50-200k | $200-500k+ | $10-50k |
Migration and Lock-in¶
| Dimension | Docker | Kubernetes | OpenStack | OpenNebula |
|---|---|---|---|---|
| Vendor lock-in risk | Low (OCI standard) | Low (CNCF conformance); add-ons create lock-in | Low at the software level (open APIs, Apache-2.0); switching deployment tools usually means a redeploy | Low (Apache-2.0 CE, open formats); some integrations are EE-only |
| Image portability | OCI (universal) | OCI | QCOW2, RAW, VMDK | QCOW2, RAW, VMDK |
| Migration tools | docker save / load, registries |
Velero, etcd backup, GitOps repos, Cluster API | VMware driver and migration tooling; vendor tools | OneSwap (VMware import), OneDRS |
| Exit cost | Minimal | Moderate (Kubernetes-specific manifests) | High (deep integration, operational know-how) | Low to moderate |
Sources¶
Facts come from the vault topic pages, which carry the primary sources: Docker, Kubernetes, OpenStack, OpenNebula.
- Docker Engine 29 release notes and Docker pricing
- Kubernetes releases and Kubernetes documentation
- OpenStack releases and OpenStack documentation
- OpenInfra Foundation joins the Linux Foundation
- OpenNebula documentation and OpenNebula subscription plans
- Moby (Docker Engine) repository, Kubernetes repository, OpenStack on OpenDev, OpenNebula repository