@kasperd For all the reasons you've described, I've avoided #Docker in any new deployment of mine. But my choice of Nerdctl seems hamstrung by limited parity with Docker features, and also mainly only supporting Legacy IP without substantial acrobatics.
I wanted to use Docker/Nerdctl Compose for smaller deployments, but I'm beginning to think that #k3s might be the way to go, as #k8s harbors no baggage that prevents #IPv6only operation and uses CNI plugins and Linux network primitives sanely.