Daemon and Socket

The Docker Daemon, the Unix Socket and the docker Group

dockerd runs as root under systemd 142,543 and serves a REST API on the Unix socket /var/run/docker.sock; the docker command is just an HTTP client for it. The socket is created by docker.socket (socket activation), so it exists before the daemon starts.

The daemon, its socket and the REST API behind the CLIShell
systemctl is-active docker.service docker.socket
ls -l /var/run/docker.sock
getent group docker
curl -s --unix-socket /var/run/docker.sock http://localhost/version |
  jq -c '{Version, ApiVersion, MinAPIVersion}'
Output
active
active
srw-rw---- 1 root docker 0 Sep 24 17:58 /var/run/docker.sock
docker:x:986:dev
{"Version":"29.8.1","ApiVersion":"1.56","MinAPIVersion":"1.40"}

Only root and the docker group can use the socket, and dev is a member; add yourself with sudo usermod -aG docker $USER, then log in again. The curl 3,008 call is what the CLI does: API 1.56 is the newest this daemon speaks, and it accepts clients back to 1.40.

Never publish the daemon on TCP without TLS; tcp://0.0.0.0:2375 is a root shell for the network. Reach remote hosts over SSH instead: docker context create build --docker host=ssh://dev@build.example.com.