Core Idea
The Docker socket is the daemon’s API door, usually
/var/run/docker.sock: anything that can reach it effectively controls Docker, so locking down access is the whole security story.
- Key concepts of Docker sockets and what listens on them.
- Practical examples of using the socket.
- Socket security, especially restricting access to it.
Transclude of unix-socket#unix-sockets-aka-unix-domain-socket
Docker Socket
The Docker socket (/var/run/docker.sock) is a Unix domain socket used by the Docker daemon (dockerd) to enable communication between the Docker CLI and the Docker daemon. 👉 02. Docker Engine > Daemon
It provides a way for processes to issue commands and receive responses from Docker.
Key Concepts of Docker Sockets
- What is it?
- It is a special file (
/var/run/docker.sock) that acts as an endpoint for inter-process communication. - Instead of a traditional network interface, Docker uses a Unix socket for local IPC.
- It is a special file (
- How does it work?
- The Docker CLI, Docker Compose, and other tools use this socket to send HTTP-based API requests to the Docker daemon.
- It supports Docker’s REST API, allowing tools to manage containers, images, networks, and volumes.
- Why use a Unix socket?
- A Unix socket is faster than using network sockets (like TCP) because it operates locally without the overhead of network communication.
- It is secured by file permissions, allowing only specific users or processes to interact with the Docker daemon.(
srw-rw----)
Examples of Using the Docker Socket
curl --unix-socket /var/run/docker.sock http:/api/containers/jsonapi versioning: Docker Engine API v1.45 reference
Socket Security
The Docker socket provides privileged access to the Docker daemon, which essentially gives access to the entire host system. Anyone with access to the Docker socket can:
- Start/stop containers.
- Mount host directories.
- Execute commands on the host system.
Restricting Access:
- Limit file permissions:
srw-rw---- 1 root docker 0 Dec 16 10:30 /var/run/docker.sockOnly root and members of the docker group can access it.
- Avoid mounting the Docker socket in containers unless necessary. If mounted, a container can control the entire Docker daemon:
-v /var/run/docker.sock:/var/run/docker.sock- Use a reverse proxy or authentication layer (e.g.,Â
docker-proxy) if exposing Docker over HTTP.
Warning
If the Docker socket is misconfigured or exposed (e.g., on a public-facing server), it creates a significant security risk because it can allow attackers to execute arbitrary commands on the host system.
01103 - Docker Socket