What Is Docker? Containers vs Virtual Machines
Docker packages applications as containers that run the same way everywhere. Images, Dockerfiles, Kubernetes and container security explained.

Short answer: Docker is an open platform for packaging and running applications as isolated units called containers. An application goes into an image together with everything it needs to run; a container started from that image works the same way on a developer's laptop, in a data center or in the cloud. Containers are lighter than virtual machines because they do not carry their own operating system and share the host's kernel instead. To manage many containers across several servers, you use an orchestration platform such as Kubernetes.
What is Docker?
Docker's documentation describes Docker as an open platform for developing, shipping and running applications, one that separates applications from infrastructure so software can be delivered quickly. In Docker's own account, Solomon Hykes revealed Docker to the world for the first time on stage at PyCon 2013.
Docker's basic unit is the container: in Docker's description, a unit that carries everything it needs to function, with no reliance on dependencies pre-installed on the host. Docker is written in Go and takes advantage of Linux kernel features; what turns a container into an isolated workspace is the kernel's namespaces feature. Each aspect of a container runs in a separate namespace, so processes in one container cannot see processes in another.
How does Docker work?
Docker uses a client-server architecture. When you type a command such as docker run, the client sends it to the Docker daemon (dockerd), which carries it out. The daemon listens for Docker API requests and manages Docker objects such as images, containers, networks and volumes; the client can talk to a daemon on the same machine or on a remote one.
Key concepts: image, container, Dockerfile, registry
- Image: A read-only template with instructions for creating a container.
- Container: A runnable instance of an image.
- Dockerfile: A text file containing all the commands a user could call on the command line to assemble an image. Every Dockerfile begins with a
FROMinstruction naming the base image, and each instruction in the file creates a layer in the image. - Registry: Where images are stored. Docker Hub is a public registry anyone can use, and Docker looks for images there by default.
This example from Docker's getting-started guide starts a container in the background from an image on Docker Hub:
docker run -d -p 8080:80 docker/welcome-to-docker-d runs the container in the background, and -p 8080:80 binds port 8080 on the host to port 80 in the container. Once it is running, the app opens in a browser at http://localhost:8080. We explain ports in our port article.
Containers vs virtual machines
In Docker's comparison, a virtual machine is an entire operating system with its own kernel, hardware drivers, programs and applications, while a container is simply an isolated process with all the files it needs to run. Because containers share the same kernel, the same infrastructure can run more applications; the trade-off is that isolation is not as strong as in a virtual machine. We make the full comparison in our virtual machine article.
OCI: the shared standard for containers
The container format did not stay Docker's alone. The Open Container Initiative (OCI) was launched on June 22, 2015 by Docker, CoreOS and other companies in the container industry, under the Linux Foundation, to create open industry standards for container formats and runtimes. Docker donated its container format and its runtime, runC, to the initiative.
The OCI now has three specifications: the Runtime Specification, which describes how to run a container from a filesystem bundle on disk; the Image Specification, which defines the image format; and the Distribution Specification, which standardizes the API for distributing images. Thanks to these standards, the tool that builds an image and the tool that runs it can be different.
Docker and Kubernetes
Docker makes it easy to build and run containers on a single machine; managing many containers spread across several servers is a job for orchestration. Kubernetes is defined in its documentation as a portable, extensible, open source platform for managing containerized workloads and services; Google open-sourced the project in 2014. Kubernetes restarts containers that fail, exposes containers through a DNS name or IP address, and rolls out new versions at a controlled rate. It does not build your application: a tool such as Docker produces the image, and Kubernetes runs it.
The relationship has one turning point. Kubernetes releases before v1.24 included a direct integration with Docker Engine through a component called dockershim; that integration is no longer part of Kubernetes. Kubernetes now requires a runtime that conforms to the Container Runtime Interface (CRI): containerd, CRI-O, or Docker Engine through the cri-dockerd adapter. In the Kubernetes team's words, Docker-produced images continue to work with all runtimes, as they always have.
We cover how to verify that a pod is really ready to take traffic in Reliability Friday 02, and where internal platform teams stand in 2026 in our platform engineering article.
Docker security: good practices
Container isolation alone does not amount to security. The core recommendations in Docker's documentation:
- Start from a trusted image: Docker recommends making sure an image is built from a trusted source and keeping it small; Docker Official Images are a curated, regularly updated collection.
- Pin versions: Image tags are mutable, so a publisher can point the same tag at a new image. To secure supply chain integrity, you can pin the image version to a specific digest.
- Rebuild regularly: Docker images are immutable; to stay up to date and secure, they need to be rebuilt regularly with updated dependencies.
- Don't install unnecessary packages: According to Docker, skipping them reduces image complexity, dependencies, file size and build time.
- Don't grant unnecessary privileges: If a service can run without privileges, use
USERto switch to a non-root user. According to Docker's Engine security documentation, the daemon requires root privileges unless you opt in to rootless mode, so only trusted users should control it. Containers should keep only the Linux capabilities they really need.
The --privileged flag deserves extra caution. According to Docker's command reference, it enables all Linux kernel capabilities and disables the default seccomp and AppArmor profiles; a container in this mode can get a root shell on the host and take control of the system. We describe running container platforms on our cloud-native platforms page, and CI/CD and container orchestration on our DevOps solutions page.
Docker Desktop, Docker Engine and licensing
Before rolling Docker out across an organization, check the licensing too. According to Docker's license page, Docker Desktop is free for small businesses (fewer than 250 employees and less than $10 million in annual revenue), personal use, education and non-commercial open source projects. Professional use in larger organizations and use by government entities require a paid subscription, while the licensing and distribution terms of open source projects such as Docker Engine are not changing.
Frequently asked questions
What does Docker mean? Docker is the name of an open platform for packaging and running applications as isolated units called containers.
What is Docker used for? It packages an application with everything it needs so that it runs the same way on a developer's laptop, on a test server and in production.
What is the difference between Docker and a virtual machine? A virtual machine runs a complete operating system with its own kernel and drivers. A Docker container is an isolated process that shares the host's kernel; it is lighter, but its isolation is not as strong as a virtual machine's.
What is the difference between Docker and Kubernetes? Docker builds images and runs containers on a single machine. Kubernetes manages many containers across several servers: it restarts the ones that fail, exposes them and handles version rollouts.
Is Docker free? Docker Engine is open source. Docker Desktop is free for small businesses, personal use, education and non-commercial open source projects; larger organizations need a paid subscription.
Sources
- Docker Docs, What is Docker?: definition, architecture and key concepts
- Docker, 11 Years of Docker: Docker's debut at PyCon 2013 (March 21, 2024)
- Docker Docs, Dockerfile reference: Dockerfiles and the FROM instruction
- Docker Docs, What is a container?: example command, containers vs virtual machines
- Docker Docs, docker container run:
-d,-pand--privileged - OCI, About the Open Container Initiative: founding (June 22, 2015) and specifications
- Kubernetes, Overview: definition and capabilities of Kubernetes
- Kubernetes, Container Runtimes: dockershim, CRI and cri-dockerd
- Kubernetes Blog, Don't Panic: Kubernetes and Docker: compatibility of Docker-built images (December 2, 2020)
- Docker Docs, Building best practices: image security recommendations
- Docker Docs, Docker Engine security: isolation and privileges
- Docker Docs, Docker Desktop license agreement: Docker Desktop licensing terms
- How we run this layer: cloud-native platforms