Q: Your engineering organization migrated all Kubernetes nodes from Docker daemon (`dockershim`) to containerd. During on-call incidents, newly onboarded SREs repeatedly attempt to run familiar commands like `docker ps`, `docker logs`, `docker exec`, and `docker images`, which fail on containerd nodes. You must author a comprehensive operational command translation matrix and operational troubleshooting guide mapping Docker commands to `crictl`, `nerdctl`, and `ctr`.
Master the command-line mapping between standard Docker CLI commands and containerd debugging utilities: `crictl` for Kubernetes, `nerdctl` for Docker parity, and `ctr` for low-level runtime triage.
Want to master this scenario in a live sandbox? KodeKloud's Docker Certified Associate (DCA) Hands-On Lab Course covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Understand the Purpose of Each Tool in the containerd Stack
Differentiate tool scopes: `docker` manages the Docker daemon. `crictl` communicates through Kubernetes Container Runtime Interface (CRI) and understands Pod sandboxes. `nerdctl` provides full Docker CLI syntax compatibility for containerd. `ctr` interacts directly with containerd's internal gRPC APIs for low-level debugging.
<!-- CLI Hierarchy -->
Docker CLI ───> dockerd ───> containerd ───> containerd-shim ───> runc
crictl ───> CRI Plugin (inside containerd, k8s.io namespace)
nerdctl ───> containerd (Docker CLI drop-in)
ctr ───> containerd (Raw internal API)
Master the Core Operational Command Translation Matrix
Map standard daily operational commands across the four CLI tools.
# Task: List Running Containers
# Docker: docker ps
# crictl: crictl ps
# nerdctl: nerdctl -n k8s.io ps
# ctr: ctr -n k8s.io tasks list
# Task: View Container Logs
# Docker: docker logs <id>
# crictl: crictl logs <id>
# nerdctl: nerdctl -n k8s.io logs <id>
# ctr: (Not natively supported; logs must be read from /var/log/pods/)
# Task: Execute Interactive Shell
# Docker: docker exec -it <id> sh
# crictl: crictl exec -it <id> sh
# nerdctl: nerdctl -n k8s.io exec -it <id> sh
# ctr: ctr -n k8s.io tasks exec --exec-id test -t <id> sh
# Task: List Images
# Docker: docker images
# crictl: crictl images
# nerdctl: nerdctl -n k8s.io images
# ctr: ctr -n k8s.io images list
Utilize Pod Sandbox Inspection Commands Unique to crictl
Unlike Docker, `crictl` understands Kubernetes Pod Sandboxes (the pause container boundary). Use `crictl pods` and `crictl inspectp` to inspect pod-level networking, cgroup configurations, and annotations.
# List all pod sandboxes on the node
crictl pods
# Inspect pod sandbox network details
crictl inspectp <POD_ID> | jq .status.network.ip
# Stop and remove an entire pod sandbox directly
crictl stopp <POD_ID>
crictl rmp <POD_ID>
Use nerdctl for Image Building and Rootless Containers
When developers need Docker-like functionality on containerd hosts (e.g., building images or running Compose stacks), use `nerdctl` which leverages BuildKit and compose specifications natively.
# Build image directly in containerd
nerdctl build -t my-app:v1 .
# Run compose stack on containerd
nerdctl compose up -d
- W
- h
- e
- n
- o
- u
- r
- n
- o
- d
- e
- s
- t
- r
- a
- n
- s
- i
- t
- i
- o
- n
- e
- d
- f
- r
- o
- m
- D
- o
- c
- k
- e
- r
- t
- o
- c
- o
- n
- t
- a
- i
- n
- e
- r
- d
- ,
- w
- e
- p
- r
- o
- v
- i
- d
- e
- d
- o
- u
- r
- S
- R
- E
- s
- w
- i
- t
- h
- a
- c
- l
- e
- a
- r
- C
- L
- I
- m
- a
- p
- p
- i
- n
- g
- g
- u
- i
- d
- e
- .
- F
- o
- r
- p
- o
- d
- -
- l
- e
- v
- e
- l
- t
- r
- o
- u
- b
- l
- e
- s
- h
- o
- o
- t
- i
- n
- g
- ,
- t
- h
- e
- y
- u
- s
- e
- `
- c
- r
- i
- c
- t
- l
- `
- w
- h
- i
- c
- h
- n
- a
- t
- i
- v
- e
- l
- y
- u
- n
- d
- e
- r
- s
- t
- a
- n
- d
- s
- p
- o
- d
- s
- a
- n
- d
- b
- o
- x
- e
- s
- .
- F
- o
- r
- D
- o
- c
- k
- e
- r
- c
- o
- m
- m
- a
- n
- d
- p
- a
- r
- i
- t
- y
- a
- n
- d
- l
- o
- c
- a
- l
- b
- u
- i
- l
- d
- s
- ,
- t
- h
- e
- y
- u
- s
- e
- `
- n
- e
- r
- d
- c
- t
- l
- `
- ,
- e
- n
- s
- u
- r
- i
- n
- g
- s
- e
- a
- m
- l
- e
- s
- s
- i
- n
- c
- i
- d
- e
- n
- t
- t
- r
- i
- a
- g
- e
- w
- i
- t
- h
- o
- u
- t
- c
- o
- n
- f
- u
- s
- i
- o
- n
- .