dockerd runs as root under systemd 142,543 and serves a REST API on the Unix socket /var/run/docker.sock; the docker command is just an HTTP client for it. The socket is created by docker.socket (socket activation), so it exists before the daemon starts.
systemctl is-active docker.service docker.socket
ls -l /var/run/docker.sock
getent group docker
curl -s --unix-socket /var/run/docker.sock http://localhost/version |
jq -c '{Version, ApiVersion, MinAPIVersion}'active
active
srw-rw---- 1 root docker 0 Sep 24 17:58 /var/run/docker.sock
docker:x:986:dev
{"Version":"29.8.1","ApiVersion":"1.56","MinAPIVersion":"1.40"}Only root and the docker group can use the socket, and dev is a member; add yourself with sudo usermod -aG docker $USER, then log in again. The curl 3,008 call is what the CLI does: API 1.56 is the newest this daemon speaks, and it accepts clients back to 1.40.
Never publish the daemon on TCP without TLS; tcp://0.0.0.0:2375 is a root shell for the network. Reach remote hosts over SSH instead: docker context create build --docker host=ssh://dev@build.example.com.