Under Docker Engine 514 sits containerd 234,762 (containerd and runc), a CNCF graduated project that pulls images, manages snapshots and supervises containers through runc 13,463 . Kubernetes 5,150 talks to containerd directly through the Container Runtime Interface, with no Docker 514 involved, as Kubernetes's kind nodes do. containerd's own ctr tool is a debugging aid; the friendly client is nerdctl 10,397 (github.com/containerd/nerdctl (https://github.com/containerd/nerdctl 10,397 ), Apache-2.0, a containerd subproject), which copies Docker's commands and adds containerd features such as lazy pulling of eStargz images and encrypted images. Point it at the containerd that Docker Engine already runs, read-only:
R=https://github.com/containerd/nerdctl/releases/download/v2.4.0
curl -Ls $R/nerdctl-2.4.0-linux-amd64.tar.gz | tar xz nerdctl
sudo ./nerdctl namespace ls
sudo ./nerdctl -n moby ps --format '{{.ID}} {{.Image}}' | grep registry
F='{{.Repository}}:{{.Tag}} {{.ID}}'
sudo ./nerdctl -n moby images --format "$F" | grep booknest-api:
docker image ls --format "$F" l3-booknest-api
docker info --format '{{.Driver}} {{.DriverStatus}}'NAME CONTAINERS IMAGES VOLUMES LABELS moby 2 59 0 moby_history 0 0 0 ae7675b125e4 docker.io/library/registry:3 localhost:33500/booknest-api:1.3 ff7c8911a5d4 l3-booknest-api:latest ff7c8911a5d4 l3-booknest-api:1.2 9a6e373561e0 l3-booknest-api:1.0 5195d360d65d l3-booknest-api:latest ff7c8911a5d4 l3-booknest-api:1.2 9a6e373561e0 l3-booknest-api:1.0 5195d360d65d overlayfs [[driver-type io.containerd.snapshotter.v1]]
Docker Engine keeps its containers in containerd's moby namespace, so nerdctl lists the running l3-registry under the same short ID (the namespace also held another container, left out here), and both tools list the same BookNest images with the same IDs. Since Engine 29, new installations also use the containerd image store (the io.containerd.snapshotter.v1 driver type above), so Docker's images are containerd images too. On a host without Docker, the "full" nerdctl release bundles containerd, runc, the CNI plugins and BuildKit 10,294 , and nerdctl run, nerdctl build and nerdctl compose up work much as their Docker counterparts do; rootless mode comes from RootlessKit 1,304 , like rootless Docker (Rootless Mode). That setup is not run here, because a second containerd on this shared host would compete with Docker's.