For a great comparison, see https://tin6150.github.io/psg/blogger_container_hpc.html
privileged user running support daemon
Docker images are comprised of multiple layers managed by the Docker system
The docker daemon making calls to containerd, which in turn calls runc.
- containerd is the new high-level daemon for image management