The parts that outlived the product: ten years of Docker, read from its own repositories
How Docker's architecture and its position in the stack changed between 2015 and 2026, reconstructed from the artefacts the changes were executed in: tag dates, commits per year across thirteen repositories, an abandoned release line, a security fix that took six years to reach a mainline release, and the adopter list of the component the company gave away.
A decade of one company's architecture told through the sequence every platform team eventually faces: bundle to win the workflow, extract components to cut the blast radius of your own releases, specify the boundary so others can implement it, then lose the layer to the consumer that standardised it. A reader leaves with a decision tree for whether a component should leave the product, the three seam classes that decomposition creates and the incidents each produced, and a set of git commands that turn any dependency's repository into the same kind of evidence.
The 2018 authorization fix that shipped in Engine 18.09.1 is not an ancestor of v19.03, v20.10, v23.0 or v27.1.0; the commit first appears in a tagged mainline release in February 2025, six years and three months later, because nothing in the process asked which tags contained it.
What you get out of it
- The components that survived the decade are the two that stopped changing: the OCI image specification went from 642 commits in 2016 to 8 in 2020 and waited six years and seven months for its next release, and that stillness is what let the implementations on both sides be replaced.
- Activity inverted: the engine fell from 10,133 commits in 2016 to 1,065 in 2021 while containerd, the piece it donated, held between 1,355 and 3,152 commits a year for ten years and now lists 26 production adopters, with the Docker engine as one entry among them.
- Decomposition relocates defects into seams, and the most expensive seam was procedural: a security fix that lived on one branch line for six years, verifiable with git tag --contains.
- Deferring a feature across a component boundary is a decision to drop it: checkpoint and restore was deferred to containerd in February 2016 and closed unmerged in March 2024, eight years and nine months later.
- The layer that kept its position is the one nobody found interesting: the registry, now metered at 100 pulls per six hours for anonymous users while single official images take over twenty million pulls a week.
Scope
Why this, now. The loop closed in 2025 and 2026: containerd became the engine's default image store in the v29 line, libnetwork was folded back into the daemon tree, an embedded containerd mode appeared, and the Go module path finally moved eight years after the repository did.
What it does not cover. Docker Desktop's internals, Windows containers, Kubernetes' own architecture and Docker Inc.'s finances; and, because the session's egress policy allowed only six hosts, it contains no engineering-blog, conference-talk or academic-paper evidence at all.
Other field guides
Boundaries without a network hop: ten years of Shopify, read from its own artefacts
Reconstructs a decade of one company's architecture from artefacts rather than announcements: repository archive notices, release notes of the langua…
30 sources · 8 organisations · 2 postmortemsYour singletons choose where you fail: ten years of GitLab's architecture
A decade of one company's platform evolution, reconstructed entirely from primary artefacts it publishes in Git repositories: 207 design documents, t…
28 sources · 2 organisations · 5 postmortemsWhen the internal fork wins: ten years of Netflix retiring its published platform libraries
Netflix published the reference implementation of the fat client library, then dismantled it in public over ten years, one dated commit at a time. Th…
22 sources · 6 organisations · 7 postmortems