Rootless Setup

Installing and Testing Rootless Docker

Rootless Docker 514 needs newuidmap (package uidmap), pasta (package passt), subordinate ID ranges and the docker-ce-rootless-extras package from Official Apt Repository. Normally you run the setup as yourself; because the setup script switches the CLI's default context and this machine's dev account is shared, the demonstration uses a dedicated user, l3rootless, with lingering enabled so its systemd 142,543 user services run without a login:

Prerequisites and a dedicated user for the rootless daemonShell
sudo DEBIAN_FRONTEND=noninteractive apt-get install -y uidmap passt >/dev/null
sudo useradd -m -s /bin/bash l3rootless
sudo loginctl enable-linger l3rootless
grep l3rootless /etc/subuid
Output
l3rootless:165536:65536

useradd allocated 65,536 subordinate UIDs after dev's range. The next listings run in a shell as l3rootless, opened with sudo -u plus XDG_RUNTIME_DIR=/run/user/1001 and the matching DBUS_SESSION_BUS_ADDRESS, so that systemctl --user reaches the user's systemd instance (an SSH login also works; a plain su does not).

Installing the rootless daemon (as l3rootless)Shell
dockerd-rootless-setuptool.sh install
Output
[INFO] Creating /home/l3rootless/.config/systemd/user/docker.service
...
     Active: active (running) since Fri 2026-09-25 16:26:28 +08; 3s ago
...
 rootlesskit:
  Version:          3.1.0
  ApiVersion:       1.1.2
  NetworkDriver:    pasta
...
[INFO] Installed docker.service successfully.
...
[INFO] Using CLI context "rootless"
Current context is now "rootless"
...

The script wrote and started a user unit, printed docker version with an extra rootlesskit section (network driver pasta), and created and selected a rootless CLI context. Now test it:

A rootless container: root inside, an ordinary user outside (as l3rootless)Shell
docker context ls
docker info --format '{{.SecurityOptions}}'
docker pull -q alpine:3
docker run -d --name l3-rl alpine:3 sleep 600 >/dev/null
docker exec l3-rl cat /proc/self/uid_map
pgrep -u l3rootless -a sleep
Output
NAME         DESCRIPTION                               DOCKER ENDPOINT
  ERROR
default      Current DOCKER_HOST based configuration   unix:///var/run/docker.sock
rootless *   Rootless mode                             unix:///run/user/1001/docker.sock
[name=seccomp,profile=builtin name=rootless name=cgroupns]
docker.io/library/alpine:3
         0       1001          1
         1     165536      65536
383622 sleep 600

The rootless security option confirms the mode, and the daemon's own image store (~/.local/share/docker) pulled alpine:3 again. Container root maps to UID 1001 and the rest into the subordinate range, and on the host pgrep finds the sleep owned by l3rootless. To remove the setup, run dockerd-rootless-setuptool.sh uninstall and rootlesskit rm -rf ~/.local/share/docker as the user, then sudo loginctl disable-linger for it.