Iptables-legacy vs iptables-nft

I read somewhere that Docker uses netfilter, which nftables or iptables sit on top of, and nft or ipt just “interpret” the entries.