# Install nerdctl with Homebrew, apk, Nix, pacman, zypper, scoop

ContaiNERD CTL - Docker-compatible CLI for containerd. Version 2.3.5 via Homebrew; verified 2026-07-26. Also installable with nix: nix profile install nixpkgs#nerdctl.

## Install

```sh
sudo av install brew:nerdctl
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install nerdctl
```

  Evidence: local Homebrew formula metadata

### Linux

- apk (92%):

```sh
sudo apk add nerdctl
```

  Evidence: Alpine Linux edge package indexes: nerdctl from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz

- Nix (92%):

```sh
nix profile install nixpkgs#nerdctl
```

  Evidence: nixpkgs package indexes: pkgs/by-name/ne/nerdctl/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

- pacman (92%):

```sh
sudo pacman -S nerdctl
```

  Evidence: Arch Linux sync databases: nerdctl from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz

- zypper (92%):

```sh
sudo zypper install nerdctl
```

  Evidence: openSUSE Tumbleweed package metadata: nerdctl from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

### Windows

- Scoop (92%):

```sh
scoop install main/nerdctl
```

  Evidence: Scoop official bucket manifest trees: bucket/nerdctl.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

## Package facts

- **Package key:** brew:nerdctl
- **Package manager:** Homebrew
- **Version:** 2.3.5
- **Source summary:** ContaiNERD CTL - Docker-compatible CLI for containerd
- **Homepage:** <https://github.com/containerd/nerdctl>
- **Repository:** <https://github.com/containerd/nerdctl>
- **Last updated:** 2026-07-26T19:43:14+02:00
- **Generated:** 2026-08-03T19:37:03+00:00

## Executables

- containerd-rootless-setuptool.sh (alias)
- containerd-rootless.sh (alias)
- nerdctl (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 2.3.5
## Project history and usage

nerdctl is the Docker-compatible command-line client for containerd. It was created under the containerd organization in December 2020, shipped its first GitHub release v0.0.1 on 2020-12-09, and is explicitly described by the project as a non-core containerd subproject. Its practical niche is not to replace Docker as a product, but to expose containerd directly through familiar Docker-like commands while also surfacing containerd features that Docker historically did not expose.

### Project history

The project grew out of the containerd ecosystem after containerd had become a common runtime substrate for Kubernetes and local developer environments. The README describes the tool as supporting Docker-like UX, Compose, rootless operation, lazy pulling through eStargz/Nydus/OverlayBD, encrypted images through ocicrypt, IPFS-based distribution, and image signing and verification. Release artifacts are split into minimal archives containing nerdctl itself and full archives bundling dependencies such as containerd, runc, CNI, and BuildKit.

GitHub metadata retrieved on 2026-07-01 showed the repository created on 2020-12-04, written in Go, with about 10.2k stars and 795 forks. GitHub releases showed 94 releases through v2.3.4, published on 2026-06-29, with compatibility notes for containerd v1.7 and v2.0 through v2.3.

### Adoption history

nerdctl became important because containerd itself is a runtime API, not a friendly end-user container workflow. Tools such as Rancher Desktop and Lima document nerdctl as the CLI users run when they select or start a containerd-backed environment. Rancher Desktop documentation says nerdctl is Docker-compatible and is for experimenting with containerd features not present in Docker, while Lima documents built-in containerd and nerdctl integration and shows `lima nerdctl run` as its container example.

Package-manager adoption is broad for a container tool: Homebrew, Alpine, Nix, Arch, Scoop, and openSUSE entries are present in the av.db source record. The Homebrew formula API reported stable version 2.3.4 and 259 install-on-request events in the prior 30 days when checked on 2026-07-01.

### How it is used

Package nerds use nerdctl when they want Docker-shaped commands against containerd: `nerdctl run`, `nerdctl build`, `nerdctl compose up`, image inspection, registry operations, and rootless containerd setup. It is also common as the terminal face of Lima, Rancher Desktop's containerd mode, and other Docker Desktop replacement stacks.

Its more specialized value is for containerd-native experiments: lazy-pulled images, encrypted images, rootless containerd, image signing verification, and debugging containerd behavior without going through dockerd.

### Why package nerds care

nerdctl is a high-signal package because it sits at the boundary between everyday Docker muscle memory and lower-level OCI/containerd infrastructure. If a package collection wants to represent modern container workflows, nerdctl is one of the few CLIs that explains how containerd is actually used by humans.

### Timeline

- 2020-12-04: GitHub repository created under containerd.
- 2020-12-09: v0.0.1 release published.
- 2026-06-29: v2.3.4 release published, with release notes listing containerd compatibility through v2.3 and minimal/full binary distributions.

### Related projects

- containerd
- Docker
- BuildKit
- Rancher Desktop
- Lima
- RootlessKit
- eStargz
- Nydus
- ocicrypt

### Sources

- <https://api.github.com/repos/containerd/nerdctl>
- <https://api.github.com/repos/containerd/nerdctl/releases?per_page=100>
- <https://docs.rancherdesktop.io/tutorials/working-with-containers/>
- <https://formulae.brew.sh/api/formula/nerdctl.json>
- <https://github.com/containerd/nerdctl>
- <https://github.com/containerd/nerdctl/releases>
- <https://lima-vm.io/docs/examples/containers/containerd/>


## Security Notes

infrastructure mutation or orchestration signal.

- **Geiger risk:** orange / medium
- infrastructure mutation or orchestration signal


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: /etc/nerdctl/nerdctl.toml, ~/.config/nerdctl/nerdctl.toml

## Credential files

- Unix: ~/.docker/config.json
## Other Package-Manager Records

- Nix - nerdctl: normalized package name match | nixpkgs package indexes: pkgs/by-name/ne/nerdctl/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- apk - nerdctl - 2.3.4-r0: normalized package name match | Alpine Linux edge package indexes: nerdctl from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz | Docker-compatible CLI for containerd | https://github.com/containerd/nerdctl/
- apk - nerdctl-bash-completion - 2.3.4-r0: normalized package name match | Alpine Linux edge package indexes: nerdctl-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz | Bash completions for nerdctl | https://github.com/containerd/nerdctl/
- apk - nerdctl-doc - 2.3.4-r0: normalized package name match | Alpine Linux edge package indexes: nerdctl-doc from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz | Docker-compatible CLI for containerd (documentation) | https://github.com/containerd/nerdctl/
- apk - nerdctl-fish-completion - 2.3.4-r0: normalized package name match | Alpine Linux edge package indexes: nerdctl-fish-completion from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz | Fish completions for nerdctl | https://github.com/containerd/nerdctl/
- apk - nerdctl-zsh-completion - 2.3.4-r0: normalized package name match | Alpine Linux edge package indexes: nerdctl-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz | Zsh completions for nerdctl | https://github.com/containerd/nerdctl/
- pacman - nerdctl - 2.3.5-1: normalized package name match | Arch Linux sync databases: nerdctl from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz | Docker-compatible CLI for containerd | https://github.com/containerd/nerdctl
- zypper - nerdctl - 2.3.5-1.2: normalized package name match | openSUSE Tumbleweed package metadata: nerdctl from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Docker-compatible CLI for containerd | https://github.com/containerd/nerdctl
- Scoop - main/nerdctl: normalized package name match | Scoop official bucket manifest trees: bucket/nerdctl.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1


## Combined YAML source

View the package source record on GitHub. [combined/nerdctl.yml](https://github.com/mxcl/pkgdb/blob/main/combined/nerdctl.yml)


## Sources

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
