Skip to content

Docker

Summary

Docker is the most widely used toolchain for building, shipping, and running OCI containers. The open-source Docker Engine (built from the Moby project, Apache 2.0) provides the dockerd daemon, the docker CLI, BuildKit, and the Buildx and Compose plugins on top of containerd and runc. Docker Desktop, the proprietary developer app, adds the GUI, VM, Kubernetes, and security and AI tooling, and requires a paid subscription in larger companies. The current line is Engine 29.8.1 (2026-09-15). Since 29.0, fresh installs use the containerd image store by default.

Key Facts

Attribute Detail
Latest Version Engine 29.8.1 (2026-09-15); Desktop 4.92.0 (2026-09-21); Compose v5.5.1; Buildx v0.37.1
Current major 29.x (29.0.0 GA 2025-11-10); only maintained upstream Engine branch besides vendor-sponsored 25.0
Release cadence Engine minor roughly every 5-6 weeks (29.2 to 29.8), with patch releases between; Desktop roughly weekly in 2026
Repository github.com/moby/moby (Engine), docker/cli, docker/compose, moby/buildkit
Language Go
License Engine, CLI, Compose, BuildKit: Apache 2.0. Docker Desktop: proprietary, paid for companies with more than 250 employees or more than $10M revenue
Company Docker, Inc. (CEO Don Johnson since 2025-02-12)
Runtime stack dockerd -> containerd 2.x -> containerd-shim-runc-v2 -> runc
Default storage (fresh v29 install) containerd image store (overlayfs snapshotter); upgraded hosts keep overlay2

Overview

Docker introduced the modern container workflow in 2013: a Dockerfile describes an image, the image is pushed to a registry, and any host with a compatible runtime can run it. The image and runtime formats were standardized by the Open Container Initiative (OCI), so images built with Docker run on Kubernetes (via containerd or CRI-O), Podman, and cloud container services.

"Docker" names several distinct things:

  • Docker Engine / Moby: the open-source daemon and CLI you install on Linux servers.
  • Docker Desktop: the proprietary desktop app for macOS, Windows, and Linux that runs the Engine in a VM.
  • Docker Hub: the default public registry, now joined by dhi.io for Docker Hardened Images.
  • Docker Compose, Buildx, Scout, Build Cloud, Testcontainers Cloud, Offload: tools and services layered on top, several of them bundled into the Docker subscription plans.

Architecture at a Glance

This diagram shows the Engine component chain; the detailed version is in Explanation.

flowchart LR
    CLI["docker CLI<br/>+ buildx, compose"] -->|"Engine REST API"| D["dockerd"]
    D --> BK["BuildKit<br/>(builds)"]
    D --> NET["libnetwork<br/>(iptables / nftables)"]
    D -->|"gRPC"| C["containerd 2.x<br/>(content store + snapshotter)"]
    C --> S["containerd-shim-runc-v2"]
    S --> R["runc"]
    R --> K["Linux kernel<br/>namespaces, cgroups v2, seccomp"]
    C <-->|"pull / push"| REG[("Docker Hub / dhi.io /<br/>private registry")]

Evaluation

Why teams choose it: Docker has the most familiar developer workflow and the largest public image ecosystem (Docker Hub, Docker Official Images, and free Hardened Images since 2025-12). OCI-standard images run everywhere. BuildKit and Buildx provide fast, cacheable, multi-platform builds with SBOM and provenance attestations, and Compose makes multi-container development a one-file affair.

When it fits:

  • Local development and testing (Compose, Desktop, Testcontainers)
  • CI/CD image building (Buildx, registry cache, Build Cloud)
  • Single-host deployments and small edge nodes
  • Application packaging and distribution
  • Swarm mode for simple multi-host clusters where Kubernetes is overkill

When it does not fit:

  • Large multi-host orchestration: use Kubernetes (which runs OCI images via containerd, not dockerd)
  • Daemonless or rootless-by-default requirements: consider Podman
  • Strict multi-tenant isolation: add VM-based runtimes (Kata, gVisor) or use VMs
Pros Cons
Ubiquitous and well documented Docker Desktop license costs for larger enterprises
Massive image ecosystem (Docker Hub, DHI) Not a full orchestrator; Swarm is maintained but a niche next to Kubernetes
OCI-standard, portable images Daemon-based architecture, rootful by default
BuildKit: parallel, cached, multi-platform builds Daemon socket is root-equivalent; a large attack surface if exposed
Compose v5 for multi-service apps, now also a Go SDK Upstream maintains only the latest major; frequent breaking changes at majors (v29)
Free Hardened Images (Apache 2.0) since 2025-12 Docker Hub pull limits for anonymous and Personal users

Recent Developments (2025-2026)

Date Change Source
2025-02-12 Don Johnson (ex-Oracle Cloud Infrastructure) becomes CEO of Docker, Inc. Docker press release
2025-02-19 Engine 28.0.0: image mounts, gateway priority, hardened bridge port publishing v28 notes
2025-04 Planned stricter Docker Hub pull limits postponed; 100/200 pulls per 6 h remain Docker blog
2025-11-10 Engine 29.0.0: containerd image store default for fresh installs, experimental nftables, DCT removed, cgroup v1 deprecated, API min v1.44 v29 notes
2025-12-02 Compose v5.0.0: official Go SDK; internal builder removed, builds delegated to Bake docker/compose v5.0.0
2025-12-16 Desktop 4.55.0 announces deprecation of Wasm workloads Desktop notes
2025-12-17 Docker Hardened Images made free and open source (Apache 2.0), more than 1,000 images Docker press release
2026-03 to 2026-07 Security releases for AuthZ bypass, docker cp escapes, BuildKit frontends, kernel "Copy Fail" hardening Reference: advisories
2026-05-14 Engine 29.5.0: gvisor-tap-vsock becomes default rootless network driver; container time namespaces v29 notes
2026-07-30 Engine 29.7.0: --mount type=image GA; experimental embedded containerd; default-stop-timeout v29 notes
2026-09-03 Engine 29.8.0: --umask, BuildKit v0.33.0, runc v1.5.1, configurable AppArmor template v29 notes

Licensing and Pricing

The Engine is free under Apache 2.0 for any use. Docker Desktop is free for personal use, education, non-commercial open source, and companies with fewer than 250 employees and less than $10M annual revenue; otherwise it needs a paid seat. Plans since 2024-12-10: Personal $0, Pro $11/mo ($9 annual), Team $16/mo ($15 annual), Business $24/user/mo. Docker Hub pull limits, Build Cloud minutes, Scout, and Testcontainers Cloud are bundled into these plans. Full tables: Subscription Pricing, Desktop License Terms, and Docker Hub Pull Limits.

Key Features

Feature Detail
Container Engine Build, run, stop, remove containers; restart policies, health checks
Image Building Dockerfile + BuildKit (multi-stage, cache and secret mounts, attestations)
Buildx / Bake Multi-platform builds, remote builders, cache export, declarative build groups
Docker Compose v5 YAML multi-service apps, watch for live sync, Go SDK
Docker Hub Default public registry; Official Images; pull limits for free users
Docker Hardened Images Free (Apache 2.0) minimal images with SBOM, VEX, SLSA L3 provenance; paid FIPS/STIG and SLA tiers
Networking bridge, host, overlay, macvlan, ipvlan, none; iptables or experimental nftables
Storage containerd image store or overlay2; volumes, bind mounts, tmpfs, image mounts
Docker Scout CVE analysis, base-image recommendations, policy evaluation
Docker Init / Debug Generate Dockerfile and Compose files; debug shells in slim containers
Desktop AI tooling Model Runner, MCP Toolkit, Ask Gordon, Docker Offload (Desktop only)
Wasm workloads Desktop-only, experimental, deprecated in Desktop 4.55.0

Compatibility

Engine packages exist for Ubuntu, Debian, Fedora, RHEL, and CentOS on amd64 and arm64 (plus ppc64le, s390x, and 32-bit ARMv7 on some distributions), and as static binaries. cgroup v2 is recommended (v1 is deprecated), and containerd 2.x with runc is the default runtime. See the Platform Support and Compatibility Matrix tables.

Alternatives

Alternative Relationship to Docker Choose it when
Podman (+ Buildah) Daemonless, rootless-first, Docker CLI compatible, Red Hat-backed You want no central daemon, or you target RHEL / systemd Quadlets
containerd + nerdctl Same lower layer Docker uses, with a Docker-like CLI You want containerd directly (for example on Kubernetes nodes)
Kubernetes Orchestrates OCI containers across clusters; uses containerd or CRI-O, not dockerd Multi-host production scheduling and self-healing
Rancher Desktop, OrbStack, Colima Desktop alternatives to Docker Desktop You need a Desktop replacement due to licensing or performance

Migration and Lock-in

Lock-in is low at the artifact level: images are OCI and portable, Compose files follow an open specification, and Dockerfiles build with BuildKit, Buildah, or Kaniko. Lock-in is higher for Docker-specific services (Docker Hub organizations and automated builds, Scout policies, Build Cloud, Desktop admin settings) and for Swarm stacks, which need translation to Kubernetes manifests.

Topic Map

  • How-to Guides: install and upgrade, containerd image store migration, nftables, rootless mode, builds, signing, Compose, networking, troubleshooting
  • Reference: versions, support policy, pricing, pull limits, DHI tiers, daemon keys, capabilities, advisories, deprecations
  • Explanation: component architecture, image storage, layers, lifecycle, BuildKit, networking, security model, Desktop architecture

Sources

Source URL
Docker Engine docs https://docs.docker.com/engine/
Engine v29 release notes https://docs.docker.com/engine/release-notes/29/
Engine v28 release notes https://docs.docker.com/engine/release-notes/28/
Docker Desktop release notes https://docs.docker.com/desktop/release-notes/
Moby branches and support status https://github.com/moby/moby/blob/master/project/BRANCHES-AND-TAGS.md
Moby project https://github.com/moby/moby
Docker CLI deprecated features https://docs.docker.com/engine/deprecated/
containerd image store https://docs.docker.com/engine/storage/containerd/
Docker with nftables https://docs.docker.com/engine/network/firewall-nftables/
Docker Hub usage and limits https://docs.docker.com/docker-hub/usage/
Docker Hub policy update (2025) https://www.docker.com/blog/revisiting-docker-hub-policies-prioritizing-developer-experience/
Docker pricing https://www.docker.com/pricing/
Pricing change coverage (2024-12) https://www.techtarget.com/searchsoftwarequality/news/366610229/Docker-pricing-changes-hike-midtier-costs
Docker Hardened Images docs https://docs.docker.com/dhi/
DHI free announcement https://www.docker.com/press-release/docker-makes-hardened-images-free-open-and-transparent-for-everyone/
Compose v5.0.0 release https://github.com/docker/compose/releases/tag/v5.0.0
BuildKit https://github.com/moby/buildkit
containerd https://github.com/containerd/containerd
runc https://github.com/opencontainers/runc
OCI specifications https://opencontainers.org
Compose Specification https://compose-spec.io
Docker CEO announcement https://www.docker.com/press-release/docker-announces-don-johnson-as-new-ceo-succeeding-scott-johnston/

Questions

Open Questions

  • When will Engine 30.0 ship, and will it remove the --pause option on docker commit and the legacy-links escape hatch as planned? (No 30.x release or RC found as of 2026-09-25.)
  • When will the nftables firewall backend leave experimental status and support Swarm overlay networks?
  • When will Docker Desktop actually remove Wasm workloads (deprecated in 4.55.0)?
  • Will Docker re-attempt tighter Docker Hub pull limits? Docker promised at least 6 months' notice.

Answered Questions

  • What is the production readiness of Docker's Wasm runtime support? Wasm workloads were only ever a Docker Desktop feature (containerd shims such as wasmtime and WasmEdge, requiring the containerd image store). Desktop 4.55.0 (2025-12-16) announced their deprecation and future removal, so do not build production plans on them.
  • What is Docker Scout's detection rate vs Trivy/Grype? No independent, reproducible benchmark was found. All three draw on overlapping advisory sources (GitHub Advisory Database, NVD, distro feeds). Scout's advantage is the Docker-native workflow (Desktop, Hub, base-image recommendations); Trivy and Grype are common standalone CI choices.
  • How does the experimental nftables support compare to iptables in Docker v29? It is enabled with "firewall-backend": "nftables" (since 29.0.0). It uses Docker-owned docker-bridges tables instead of fixed iptables chains, does not enable IP forwarding itself, ignores DOCKER-USER, and does not support Swarm overlay networks. Docker has published no throughput benchmarks, and it is still experimental as of 29.8.1. See Explanation.
  • Is Docker Swarm deprecated? No. Swarm mode is still maintained in Engine 29.x (29.8.0 shipped several Swarm networking fixes), but Kubernetes is the dominant orchestrator. Only "classic Swarm" with external key-value stores was removed (v23.0).
  • Does Docker support rootless mode? Yes, GA since Engine 20.10. Since 29.5.0 it defaults to the gvisor-tap-vsock network driver.
  • What is containerd vs Docker? containerd is the CNCF-graduated runtime that Docker uses underneath for image content, snapshots, and container supervision. Docker adds the API, CLI, BuildKit builds, networking, volumes, and Compose. See Explanation.
  • Which Engine versions get security fixes? Upstream maintains only docker-29.x, plus the vendor-sponsored 25.0 branch (Mirantis and Amazon) until 2026-12-04. See Support Policy.