nerdctl

containerd and nerdctl Without Docker

Under Docker Engine 514 sits containerd 234,762 (containerd and runc), a CNCF graduated project that pulls images, manages snapshots and supervises containers through runc 13,463 . Kubernetes 5,150 talks to containerd directly through the Container Runtime Interface, with no Docker 514 involved, as Kubernetes's kind nodes do. containerd's own ctr tool is a debugging aid; the friendly client is nerdctl 10,397 (github.com/containerd/nerdctl (https://github.com/containerd/nerdctl 10,397 ), Apache-2.0, a containerd subproject), which copies Docker's commands and adds containerd features such as lazy pulling of eStargz images and encrypted images. Point it at the containerd that Docker Engine already runs, read-only:

Docker's own containers and images, seen through containerdShell
R=https://github.com/containerd/nerdctl/releases/download/v2.4.0
curl -Ls $R/nerdctl-2.4.0-linux-amd64.tar.gz | tar xz nerdctl
sudo ./nerdctl namespace ls
sudo ./nerdctl -n moby ps --format '{{.ID}}  {{.Image}}' | grep registry
F='{{.Repository}}:{{.Tag}} {{.ID}}'
sudo ./nerdctl -n moby images --format "$F" | grep booknest-api:
docker image ls --format "$F" l3-booknest-api
docker info --format '{{.Driver}} {{.DriverStatus}}'
Output
NAME            CONTAINERS    IMAGES    VOLUMES    LABELS
moby            2             59        0
moby_history    0             0         0
ae7675b125e4  docker.io/library/registry:3
localhost:33500/booknest-api:1.3 ff7c8911a5d4
l3-booknest-api:latest ff7c8911a5d4
l3-booknest-api:1.2 9a6e373561e0
l3-booknest-api:1.0 5195d360d65d
l3-booknest-api:latest ff7c8911a5d4
l3-booknest-api:1.2 9a6e373561e0
l3-booknest-api:1.0 5195d360d65d
overlayfs [[driver-type io.containerd.snapshotter.v1]]

Docker Engine keeps its containers in containerd's moby namespace, so nerdctl lists the running l3-registry under the same short ID (the namespace also held another container, left out here), and both tools list the same BookNest images with the same IDs. Since Engine 29, new installations also use the containerd image store (the io.containerd.snapshotter.v1 driver type above), so Docker's images are containerd images too. On a host without Docker, the "full" nerdctl release bundles containerd, runc, the CNI plugins and BuildKit 10,294 , and nerdctl run, nerdctl build and nerdctl compose up work much as their Docker counterparts do; rootless mode comes from RootlessKit 1,304 , like rootless Docker (Rootless Mode). That setup is not run here, because a second containerd on this shared host would compete with Docker's.