Are the container wars back again? CoreOS and Docker roll out container security offerings
It might seem like a lifetime ago, but it was only last December when Silicon Valley startup CoreOS dropped a bit of a bombshell with a full-frontal assault on Linux container kingpin Docker's hegemony.
Context & Ripple Effects
The security launches land five months after CoreOS and Docker patched over their public fight by joining Google, Amazon, Microsoft, and VMware in the Open Container Project under the Linux Foundation — a truce that followed CoreOS's earlier move to spin its App Container project into an independent foundation. With the runtime format question settled by committee, the two rivals are now competing on what sits above the standard.
The timing matters for CoreOS specifically: its Kubernetes-based Tectonic platform only just reached general availability in early November, so a security offering gives it an enterprise-grade wedge against Docker's dominant runtime just as it needs one.
First-order effects
- Enterprise teams evaluating containers now face two competing security stacks layered on top of a shared runtime standard — the purchase decision shifts from 'which format' to 'which vendor secures and manages my containers.'
- CoreOS gets an enterprise selling point to pair with Tectonic's GA, while Docker defends its installed base against the challenger it fought all year.
Second-order effects
- Cloud vendors and Linux distributors backing the Open Container Project — Google, Amazon, Microsoft, VMware, Red Hat among them — face pressure to bundle or certify security tooling rather than leave that margin to Docker and CoreOS.
- If security becomes the differentiator, expect the rivals' roadmaps to converge on management and orchestration features, the path Docker later formalized when it debuted its Enterprise Edition with bundled security.
Third-order effects
- The pattern points to container infrastructure commoditizing at the base layer — runtimes standardized via the OCP, and Docker eventually open-sourcing containerd with cloud vendors signing on — leaving vendors to compete up the stack on security, orchestration, and support.
- That structure favors whoever controls the operational relationship with enterprises, which is why the security layer, not the runtime, becomes the durable battleground.
The trend: Container competition is migrating from format wars, settled by industry-standardization bodies, to up-stack differentiation around security and enterprise management.