Docker¶
Summary
Docker is the most widely used toolchain for building, shipping, and running OCI containers. The open-source
Docker Engine (built from the Moby project, Apache 2.0) provides the dockerd daemon, the docker CLI,
BuildKit, and the Buildx and Compose plugins on top of containerd and runc. Docker Desktop, the proprietary
developer app, adds the GUI, VM, Kubernetes, and security and AI tooling, and requires a paid subscription in
larger companies. The current line is Engine 29.8.1 (2026-09-15). Since 29.0, fresh installs use the
containerd image store by default.
Key Facts¶
| Attribute | Detail |
|---|---|
| Latest Version | Engine 29.8.1 (2026-09-15); Desktop 4.92.0 (2026-09-21); Compose v5.5.1; Buildx v0.37.1 |
| Current major | 29.x (29.0.0 GA 2025-11-10); only maintained upstream Engine branch besides vendor-sponsored 25.0 |
| Release cadence | Engine minor roughly every 5-6 weeks (29.2 to 29.8), with patch releases between; Desktop roughly weekly in 2026 |
| Repository | github.com/moby/moby (Engine), docker/cli, docker/compose, moby/buildkit |
| Language | Go |
| License | Engine, CLI, Compose, BuildKit: Apache 2.0. Docker Desktop: proprietary, paid for companies with more than 250 employees or more than $10M revenue |
| Company | Docker, Inc. (CEO Don Johnson since 2025-02-12) |
| Runtime stack | dockerd -> containerd 2.x -> containerd-shim-runc-v2 -> runc |
| Default storage (fresh v29 install) | containerd image store (overlayfs snapshotter); upgraded hosts keep overlay2 |
Overview¶
Docker introduced the modern container workflow in 2013: a Dockerfile describes an image, the image is pushed to a registry, and any host with a compatible runtime can run it. The image and runtime formats were standardized by the Open Container Initiative (OCI), so images built with Docker run on Kubernetes (via containerd or CRI-O), Podman, and cloud container services.
"Docker" names several distinct things:
- Docker Engine / Moby: the open-source daemon and CLI you install on Linux servers.
- Docker Desktop: the proprietary desktop app for macOS, Windows, and Linux that runs the Engine in a VM.
- Docker Hub: the default public registry, now joined by
dhi.iofor Docker Hardened Images. - Docker Compose, Buildx, Scout, Build Cloud, Testcontainers Cloud, Offload: tools and services layered on top, several of them bundled into the Docker subscription plans.
Architecture at a Glance¶
This diagram shows the Engine component chain; the detailed version is in Explanation.
flowchart LR
CLI["docker CLI<br/>+ buildx, compose"] -->|"Engine REST API"| D["dockerd"]
D --> BK["BuildKit<br/>(builds)"]
D --> NET["libnetwork<br/>(iptables / nftables)"]
D -->|"gRPC"| C["containerd 2.x<br/>(content store + snapshotter)"]
C --> S["containerd-shim-runc-v2"]
S --> R["runc"]
R --> K["Linux kernel<br/>namespaces, cgroups v2, seccomp"]
C <-->|"pull / push"| REG[("Docker Hub / dhi.io /<br/>private registry")]
Evaluation¶
Why teams choose it: Docker has the most familiar developer workflow and the largest public image ecosystem (Docker Hub, Docker Official Images, and free Hardened Images since 2025-12). OCI-standard images run everywhere. BuildKit and Buildx provide fast, cacheable, multi-platform builds with SBOM and provenance attestations, and Compose makes multi-container development a one-file affair.
When it fits:
- Local development and testing (Compose, Desktop, Testcontainers)
- CI/CD image building (Buildx, registry cache, Build Cloud)
- Single-host deployments and small edge nodes
- Application packaging and distribution
- Swarm mode for simple multi-host clusters where Kubernetes is overkill
When it does not fit:
- Large multi-host orchestration: use Kubernetes (which runs OCI images via containerd, not
dockerd) - Daemonless or rootless-by-default requirements: consider Podman
- Strict multi-tenant isolation: add VM-based runtimes (Kata, gVisor) or use VMs
| Pros | Cons |
|---|---|
| Ubiquitous and well documented | Docker Desktop license costs for larger enterprises |
| Massive image ecosystem (Docker Hub, DHI) | Not a full orchestrator; Swarm is maintained but a niche next to Kubernetes |
| OCI-standard, portable images | Daemon-based architecture, rootful by default |
| BuildKit: parallel, cached, multi-platform builds | Daemon socket is root-equivalent; a large attack surface if exposed |
| Compose v5 for multi-service apps, now also a Go SDK | Upstream maintains only the latest major; frequent breaking changes at majors (v29) |
| Free Hardened Images (Apache 2.0) since 2025-12 | Docker Hub pull limits for anonymous and Personal users |
Recent Developments (2025-2026)¶
| Date | Change | Source |
|---|---|---|
| 2025-02-12 | Don Johnson (ex-Oracle Cloud Infrastructure) becomes CEO of Docker, Inc. | Docker press release |
| 2025-02-19 | Engine 28.0.0: image mounts, gateway priority, hardened bridge port publishing | v28 notes |
| 2025-04 | Planned stricter Docker Hub pull limits postponed; 100/200 pulls per 6 h remain | Docker blog |
| 2025-11-10 | Engine 29.0.0: containerd image store default for fresh installs, experimental nftables, DCT removed, cgroup v1 deprecated, API min v1.44 | v29 notes |
| 2025-12-02 | Compose v5.0.0: official Go SDK; internal builder removed, builds delegated to Bake | docker/compose v5.0.0 |
| 2025-12-16 | Desktop 4.55.0 announces deprecation of Wasm workloads | Desktop notes |
| 2025-12-17 | Docker Hardened Images made free and open source (Apache 2.0), more than 1,000 images | Docker press release |
| 2026-03 to 2026-07 | Security releases for AuthZ bypass, docker cp escapes, BuildKit frontends, kernel "Copy Fail" hardening |
Reference: advisories |
| 2026-05-14 | Engine 29.5.0: gvisor-tap-vsock becomes default rootless network driver; container time namespaces |
v29 notes |
| 2026-07-30 | Engine 29.7.0: --mount type=image GA; experimental embedded containerd; default-stop-timeout |
v29 notes |
| 2026-09-03 | Engine 29.8.0: --umask, BuildKit v0.33.0, runc v1.5.1, configurable AppArmor template |
v29 notes |
Licensing and Pricing¶
The Engine is free under Apache 2.0 for any use. Docker Desktop is free for personal use, education, non-commercial open source, and companies with fewer than 250 employees and less than $10M annual revenue; otherwise it needs a paid seat. Plans since 2024-12-10: Personal $0, Pro $11/mo ($9 annual), Team $16/mo ($15 annual), Business $24/user/mo. Docker Hub pull limits, Build Cloud minutes, Scout, and Testcontainers Cloud are bundled into these plans. Full tables: Subscription Pricing, Desktop License Terms, and Docker Hub Pull Limits.
Key Features¶
| Feature | Detail |
|---|---|
| Container Engine | Build, run, stop, remove containers; restart policies, health checks |
| Image Building | Dockerfile + BuildKit (multi-stage, cache and secret mounts, attestations) |
| Buildx / Bake | Multi-platform builds, remote builders, cache export, declarative build groups |
| Docker Compose v5 | YAML multi-service apps, watch for live sync, Go SDK |
| Docker Hub | Default public registry; Official Images; pull limits for free users |
| Docker Hardened Images | Free (Apache 2.0) minimal images with SBOM, VEX, SLSA L3 provenance; paid FIPS/STIG and SLA tiers |
| Networking | bridge, host, overlay, macvlan, ipvlan, none; iptables or experimental nftables |
| Storage | containerd image store or overlay2; volumes, bind mounts, tmpfs, image mounts |
| Docker Scout | CVE analysis, base-image recommendations, policy evaluation |
| Docker Init / Debug | Generate Dockerfile and Compose files; debug shells in slim containers |
| Desktop AI tooling | Model Runner, MCP Toolkit, Ask Gordon, Docker Offload (Desktop only) |
| Wasm workloads | Desktop-only, experimental, deprecated in Desktop 4.55.0 |
Compatibility¶
Engine packages exist for Ubuntu, Debian, Fedora, RHEL, and CentOS on amd64 and arm64 (plus ppc64le, s390x, and 32-bit ARMv7 on some distributions), and as static binaries. cgroup v2 is recommended (v1 is deprecated), and containerd 2.x with runc is the default runtime. See the Platform Support and Compatibility Matrix tables.
Alternatives¶
| Alternative | Relationship to Docker | Choose it when |
|---|---|---|
| Podman (+ Buildah) | Daemonless, rootless-first, Docker CLI compatible, Red Hat-backed | You want no central daemon, or you target RHEL / systemd Quadlets |
| containerd + nerdctl | Same lower layer Docker uses, with a Docker-like CLI | You want containerd directly (for example on Kubernetes nodes) |
| Kubernetes | Orchestrates OCI containers across clusters; uses containerd or CRI-O, not dockerd |
Multi-host production scheduling and self-healing |
| Rancher Desktop, OrbStack, Colima | Desktop alternatives to Docker Desktop | You need a Desktop replacement due to licensing or performance |
Migration and Lock-in¶
Lock-in is low at the artifact level: images are OCI and portable, Compose files follow an open specification, and Dockerfiles build with BuildKit, Buildah, or Kaniko. Lock-in is higher for Docker-specific services (Docker Hub organizations and automated builds, Scout policies, Build Cloud, Desktop admin settings) and for Swarm stacks, which need translation to Kubernetes manifests.
Topic Map¶
- How-to Guides: install and upgrade, containerd image store migration, nftables, rootless mode, builds, signing, Compose, networking, troubleshooting
- Reference: versions, support policy, pricing, pull limits, DHI tiers, daemon keys, capabilities, advisories, deprecations
- Explanation: component architecture, image storage, layers, lifecycle, BuildKit, networking, security model, Desktop architecture
Related Topics¶
- Kubernetes: orchestrates the OCI images Docker builds
- OpenStack and OpenNebula: IaaS layers that host Docker hosts
- Proxmox: virtualization platform often used to run Docker VMs
- AI Platform Engineering: container-based AI platform tooling
- Infrastructure Platforms Comparison: Docker vs Kubernetes vs OpenStack vs OpenNebula
- CI/CD: pipelines that build and deploy container images
- Networking: CNI plugins (Calico, Cilium, Flannel) used when containers move to Kubernetes
- Tools Catalogue
Sources¶
Questions¶
Open Questions¶
- When will Engine 30.0 ship, and will it remove the
--pauseoption ondocker commitand the legacy-links escape hatch as planned? (No 30.x release or RC found as of 2026-09-25.) - When will the nftables firewall backend leave experimental status and support Swarm overlay networks?
- When will Docker Desktop actually remove Wasm workloads (deprecated in 4.55.0)?
- Will Docker re-attempt tighter Docker Hub pull limits? Docker promised at least 6 months' notice.
Answered Questions¶
- What is the production readiness of Docker's Wasm runtime support? Wasm workloads were only ever a Docker Desktop feature (containerd shims such as wasmtime and WasmEdge, requiring the containerd image store). Desktop 4.55.0 (2025-12-16) announced their deprecation and future removal, so do not build production plans on them.
- What is Docker Scout's detection rate vs Trivy/Grype? No independent, reproducible benchmark was found. All three draw on overlapping advisory sources (GitHub Advisory Database, NVD, distro feeds). Scout's advantage is the Docker-native workflow (Desktop, Hub, base-image recommendations); Trivy and Grype are common standalone CI choices.
- How does the experimental nftables support compare to iptables in Docker v29? It is enabled with
"firewall-backend": "nftables"(since 29.0.0). It uses Docker-owneddocker-bridgestables instead of fixed iptables chains, does not enable IP forwarding itself, ignoresDOCKER-USER, and does not support Swarm overlay networks. Docker has published no throughput benchmarks, and it is still experimental as of 29.8.1. See Explanation. - Is Docker Swarm deprecated? No. Swarm mode is still maintained in Engine 29.x (29.8.0 shipped several Swarm networking fixes), but Kubernetes is the dominant orchestrator. Only "classic Swarm" with external key-value stores was removed (v23.0).
- Does Docker support rootless mode? Yes, GA since Engine 20.10. Since 29.5.0 it defaults to the
gvisor-tap-vsocknetwork driver. - What is containerd vs Docker? containerd is the CNCF-graduated runtime that Docker uses underneath for image content, snapshots, and container supervision. Docker adds the API, CLI, BuildKit builds, networking, volumes, and Compose. See Explanation.
- Which Engine versions get security fixes? Upstream maintains only
docker-29.x, plus the vendor-sponsored 25.0 branch (Mirantis and Amazon) until 2026-12-04. See Support Policy.