⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All Docker & Containers Interview Questions Scenario 145 of 158 in Docker & Containers
Senior DevOps Engineer Docker Container Runtime & Systems Engineering Production Scenario

Q: Your engineering organization migrated all Kubernetes nodes from Docker daemon (`dockershim`) to containerd. During on-call incidents, newly onboarded SREs repeatedly attempt to run familiar commands like `docker ps`, `docker logs`, `docker exec`, and `docker images`, which fail on containerd nodes. You must author a comprehensive operational command translation matrix and operational troubleshooting guide mapping Docker commands to `crictl`, `nerdctl`, and `ctr`.

Master the command-line mapping between standard Docker CLI commands and containerd debugging utilities: `crictl` for Kubernetes, `nerdctl` for Docker parity, and `ctr` for low-level runtime triage.

#Docker #containerd #crictl #nerdctl #Cheatsheet
🎙️ Candidate Opening & Architectural Context
"Master the command-line mapping between standard Docker CLI commands and containerd debugging utilities: `crictl` for Kubernetes, `nerdctl` for Docker parity, and `ctr` for low-level runtime triage."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's Docker Certified Associate (DCA) Hands-On Lab Course covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

Step 1

Understand the Purpose of Each Tool in the containerd Stack

Differentiate tool scopes: `docker` manages the Docker daemon. `crictl` communicates through Kubernetes Container Runtime Interface (CRI) and understands Pod sandboxes. `nerdctl` provides full Docker CLI syntax compatibility for containerd. `ctr` interacts directly with containerd's internal gRPC APIs for low-level debugging.

<!-- CLI Hierarchy -->
Docker CLI   ───> dockerd ───> containerd ───> containerd-shim ───> runc
crictl       ───> CRI Plugin (inside containerd, k8s.io namespace)
nerdctl      ───> containerd (Docker CLI drop-in)
ctr          ───> containerd (Raw internal API)
Pro Tip: Understand the Purpose of Each Tool in the containerd Stack
Step 2

Master the Core Operational Command Translation Matrix

Map standard daily operational commands across the four CLI tools.

# Task: List Running Containers
# Docker:   docker ps
# crictl:   crictl ps
# nerdctl:  nerdctl -n k8s.io ps
# ctr:      ctr -n k8s.io tasks list

# Task: View Container Logs
# Docker:   docker logs <id>
# crictl:   crictl logs <id>
# nerdctl:  nerdctl -n k8s.io logs <id>
# ctr:      (Not natively supported; logs must be read from /var/log/pods/)

# Task: Execute Interactive Shell
# Docker:   docker exec -it <id> sh
# crictl:   crictl exec -it <id> sh
# nerdctl:  nerdctl -n k8s.io exec -it <id> sh
# ctr:      ctr -n k8s.io tasks exec --exec-id test -t <id> sh

# Task: List Images
# Docker:   docker images
# crictl:   crictl images
# nerdctl:  nerdctl -n k8s.io images
# ctr:      ctr -n k8s.io images list
Pro Tip: Master the Core Operational Command Translation Matrix
Advertisement
Step 3

Utilize Pod Sandbox Inspection Commands Unique to crictl

Unlike Docker, `crictl` understands Kubernetes Pod Sandboxes (the pause container boundary). Use `crictl pods` and `crictl inspectp` to inspect pod-level networking, cgroup configurations, and annotations.

# List all pod sandboxes on the node
crictl pods

# Inspect pod sandbox network details
crictl inspectp <POD_ID> | jq .status.network.ip

# Stop and remove an entire pod sandbox directly
crictl stopp <POD_ID>
crictl rmp <POD_ID>
Pro Tip: Utilize Pod Sandbox Inspection Commands Unique to crictl
Step 4

Use nerdctl for Image Building and Rootless Containers

When developers need Docker-like functionality on containerd hosts (e.g., building images or running Compose stacks), use `nerdctl` which leverages BuildKit and compose specifications natively.

# Build image directly in containerd
nerdctl build -t my-app:v1 .

# Run compose stack on containerd
nerdctl compose up -d
Pro Tip: Use nerdctl for Image Building and Rootless Containers
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"On Kubernetes containerd nodes, `crictl` is the primary tool for container and pod sandbox triage, `nerdctl` provides a drop-in replacement for the Docker CLI experience, and `ctr` provides raw daemon diagnostics when the CRI socket is unresponsive."
⚡ 60-Second Elevator Pitch Talking Points
  • W
  • h
  • e
  • n
  • o
  • u
  • r
  • n
  • o
  • d
  • e
  • s
  • t
  • r
  • a
  • n
  • s
  • i
  • t
  • i
  • o
  • n
  • e
  • d
  • f
  • r
  • o
  • m
  • D
  • o
  • c
  • k
  • e
  • r
  • t
  • o
  • c
  • o
  • n
  • t
  • a
  • i
  • n
  • e
  • r
  • d
  • ,
  • w
  • e
  • p
  • r
  • o
  • v
  • i
  • d
  • e
  • d
  • o
  • u
  • r
  • S
  • R
  • E
  • s
  • w
  • i
  • t
  • h
  • a
  • c
  • l
  • e
  • a
  • r
  • C
  • L
  • I
  • m
  • a
  • p
  • p
  • i
  • n
  • g
  • g
  • u
  • i
  • d
  • e
  • .
  • F
  • o
  • r
  • p
  • o
  • d
  • -
  • l
  • e
  • v
  • e
  • l
  • t
  • r
  • o
  • u
  • b
  • l
  • e
  • s
  • h
  • o
  • o
  • t
  • i
  • n
  • g
  • ,
  • t
  • h
  • e
  • y
  • u
  • s
  • e
  • `
  • c
  • r
  • i
  • c
  • t
  • l
  • `
  • w
  • h
  • i
  • c
  • h
  • n
  • a
  • t
  • i
  • v
  • e
  • l
  • y
  • u
  • n
  • d
  • e
  • r
  • s
  • t
  • a
  • n
  • d
  • s
  • p
  • o
  • d
  • s
  • a
  • n
  • d
  • b
  • o
  • x
  • e
  • s
  • .
  • F
  • o
  • r
  • D
  • o
  • c
  • k
  • e
  • r
  • c
  • o
  • m
  • m
  • a
  • n
  • d
  • p
  • a
  • r
  • i
  • t
  • y
  • a
  • n
  • d
  • l
  • o
  • c
  • a
  • l
  • b
  • u
  • i
  • l
  • d
  • s
  • ,
  • t
  • h
  • e
  • y
  • u
  • s
  • e
  • `
  • n
  • e
  • r
  • d
  • c
  • t
  • l
  • `
  • ,
  • e
  • n
  • s
  • u
  • r
  • i
  • n
  • g
  • s
  • e
  • a
  • m
  • l
  • e
  • s
  • s
  • i
  • n
  • c
  • i
  • d
  • e
  • n
  • t
  • t
  • r
  • i
  • a
  • g
  • e
  • w
  • i
  • t
  • h
  • o
  • u
  • t
  • c
  • o
  • n
  • f
  • u
  • s
  • i
  • o
  • n
  • .
Advertisement
Want more Docker & Containers scenarios?
Explore our complete collection of scenario-based Docker & Containers interview runbooks.
Browse All Docker & Containers Questions →