# Rancher Desktop: containerd vs dockerd, nerdctl vs Docker CLI

> Choose the container engine of Rancher Desktop: containerd with nerdctl or dockerd with the docker CLI. Compare them, switch safely and compare with Docker Desktop.

- Source: https://www.itwonderlab.com/rancher-desktop-containerd-vs-dockerd/
- Published: 2026-10-06
- Updated: 2026-10-06
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

## Two engines, one at a time

Rancher Desktop can run its containers with one of two engines, and **only one works at a time**:

- **containerd** with the `nerdctl` command. containerd is the runtime underneath Docker and Kubernetes. `nerdctl` is a Docker-compatible CLI for it.
- **dockerd (moby)** with the `docker` command. This is the Docker Engine, the same one that Docker Desktop uses.

![Rancher Desktop container engines: containerd with nerdctl or dockerd with the docker CLI, only one active at a time, and images are not shared when you switch](https://www.itwonderlab.com/media/tutorials/Diagrams/ITWL-Container-Engines.svg "Choose one engine in Preferences > Container Engine")

You choose in **Preferences > Container Engine > General**, or from the command line (see [rdctl](https://www.itwonderlab.com/rancher-desktop-rdctl-automation/)). Rancher Desktop restarts to apply the change.

> [!WARNING]
> "Workloads and images that have been built or pulled using the current container runtime are not available on the container runtime being switched to." Switching does not delete them: they are there again when you switch back. Rebuild or pull what you need after switching.

## Which one should you choose

| | containerd + nerdctl | dockerd + docker |
|---|---|---|
| CLI | `nerdctl` (same flags as `docker` in most commands) | `docker`, `docker compose`, `docker buildx` |
| Docker socket for tools | No Docker API socket | Yes: IDEs, Testcontainers, Terraform Docker provider and others work |
| Kubernetes images | Images in the `k8s.io` namespace are visible to the cluster | Images built with `docker` are visible to the cluster |
| Builds | BuildKit | BuildKit |
| Closest to production | Kubernetes clusters use containerd | Developer workflows written for Docker |

A simple rule:

- Choose **dockerd** if you migrate from Docker Desktop, if your scripts or tools talk to the Docker API (`/var/run/docker.sock`), or if your team writes `docker` in every document. It is the least surprising option.
- Choose **containerd** if you want to run exactly what your Kubernetes nodes run, and you are happy to type `nerdctl`.

## The same commands in both

```shell
# containerd
$ nerdctl run -d -p 8000:80 nginx
$ nerdctl build -t foo .
$ nerdctl compose up -d

# dockerd
$ docker run -d -p 8000:80 nginx
$ docker build -t foo .
$ docker compose up -d
```

Both build with BuildKit. To export a build result to a local directory:

```shell
$ nerdctl build -o type=local,dest=. .
$ docker build -o type=local,dest=. .
```

If you use containerd but your muscle memory says `docker`, add an alias in your shell profile:

```shell
alias docker=nerdctl
```

## Kubernetes and namespaces with nerdctl

containerd separates images and containers into **namespaces**. `nerdctl` uses the `default` namespace, but the Kubernetes cluster of Rancher Desktop uses `k8s.io`. To build an image that Kubernetes can use without a registry, select that namespace:

```shell
$ nerdctl --namespace k8s.io build -t demo:latest .
$ nerdctl --namespace k8s.io images
```

With dockerd you do not need this: an image built with `docker build` is available to the cluster. The [Kubernetes tutorial](https://www.itwonderlab.com/rancher-desktop-kubernetes/) shows both flows.

## Expose a port you forgot

If you started a container without `-p`, you do not have to recreate it. Start a small proxy container that forwards traffic to its IP address:

```shell
$ nerdctl inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' my-container
10.4.0.5
$ nerdctl run --rm -p 8080:80 alpine/socat TCP-LISTEN:80,fork TCP-CONNECT:10.4.0.5:80
```

The same works with `docker`.

## WebAssembly note

If you use dockerd and enable the WebAssembly (Wasm) option, Rancher Desktop switches to a different image store. Your images are not lost, but you must rebuild or pull them again, and the old ones come back when you disable Wasm.

## Rancher Desktop vs Docker Desktop

| | Rancher Desktop | Docker Desktop |
|---|---|---|
| License | Apache 2.0, free for any use | Free for personal use, education, open source and small businesses (fewer than 250 employees and less than 10 million USD revenue); paid subscription above |
| Linux, macOS, Windows | Yes | Yes |
| Container engine | containerd or dockerd | dockerd (Docker Engine) |
| Kubernetes | K3s, with a selectable version | Kubernetes (kubeadm or kind) |
| `docker` and Compose | Yes (with dockerd) | Yes |
| Extras | `nerdctl`, `rdctl`, snapshots, Trivy | Docker Scout, Docker Build Cloud, Docker Hub integration |

Check the current terms of each product before deciding, because licensing conditions change. For the day-to-day workflows in this series (build, Compose, volumes, networks) both tools behave the same when Rancher Desktop uses dockerd.

## Next steps

Learn the commands you will use every day in the [Docker CLI cheat sheet](https://www.itwonderlab.com/docker-cli-commands-cheat-sheet/).
