Rootless Docker 514 needs newuidmap (package uidmap), pasta (package passt), subordinate ID ranges and the docker-ce-rootless-extras package from Official Apt Repository. Normally you run the setup as yourself; because the setup script switches the CLI's default context and this machine's dev account is shared, the demonstration uses a dedicated user, l3rootless, with lingering enabled so its systemd 142,543 user services run without a login:
sudo DEBIAN_FRONTEND=noninteractive apt-get install -y uidmap passt >/dev/null
sudo useradd -m -s /bin/bash l3rootless
sudo loginctl enable-linger l3rootless
grep l3rootless /etc/subuidl3rootless:165536:65536
useradd allocated 65,536 subordinate UIDs after dev's range. The next listings run in a shell as l3rootless, opened with sudo -u plus XDG_RUNTIME_DIR=/run/user/1001 and the matching DBUS_SESSION_BUS_ADDRESS, so that systemctl --user reaches the user's systemd instance (an SSH login also works; a plain su does not).
dockerd-rootless-setuptool.sh install[INFO] Creating /home/l3rootless/.config/systemd/user/docker.service
...
Active: active (running) since Fri 2026-09-25 16:26:28 +08; 3s ago
...
rootlesskit:
Version: 3.1.0
ApiVersion: 1.1.2
NetworkDriver: pasta
...
[INFO] Installed docker.service successfully.
...
[INFO] Using CLI context "rootless"
Current context is now "rootless"
...The script wrote and started a user unit, printed docker version with an extra rootlesskit section (network driver pasta), and created and selected a rootless CLI context. Now test it:
docker context ls
docker info --format '{{.SecurityOptions}}'
docker pull -q alpine:3
docker run -d --name l3-rl alpine:3 sleep 600 >/dev/null
docker exec l3-rl cat /proc/self/uid_map
pgrep -u l3rootless -a sleepNAME DESCRIPTION DOCKER ENDPOINT
ERROR
default Current DOCKER_HOST based configuration unix:///var/run/docker.sock
rootless * Rootless mode unix:///run/user/1001/docker.sock
[name=seccomp,profile=builtin name=rootless name=cgroupns]
docker.io/library/alpine:3
0 1001 1
1 165536 65536
383622 sleep 600The rootless security option confirms the mode, and the daemon's own image store (~/.local/share/docker) pulled alpine:3 again. Container root maps to UID 1001 and the rest into the subordinate range, and on the host pgrep finds the sleep owned by l3rootless. To remove the setup, run dockerd-rootless-setuptool.sh uninstall and rootlesskit rm -rf ~/.local/share/docker as the user, then sudo loginctl disable-linger for it.