Blog
3 min read

Docker "Permission Denied While Trying to Connect to the Docker Daemon Socket": Fix

Your user isn't allowed to talk to Docker's socket at /var/run/docker.sock. The quick fix (add yourself to the docker group), why that's effectively root access, the safer rootless alternative, and the other causes: Docker not running, Docker Desktop, WSL and CI.

permission denied while trying to connect to the Docker daemon socket at
unix:///var/run/docker.sock: Get "http://%2Fvar%2Frun%2Fdocker.sock/v1.47/containers/json":
dial unix /var/run/docker.sock: connect: permission denied

The docker command you type is just a client. It sends instructions to the Docker daemon (a background service) through a socket file, /var/run/docker.sock. That file is owned by root and the docker group. If your user is in neither, you get permission denied. (What is Docker?)

The common fix: join the docker group

sudo usermod -aG docker $USER

Then log out and back in (or run newgrp docker in the current terminal) — group changes only apply to new sessions. Check:

groups          # should include docker
docker ps       # should work without sudo

If the docker group doesn't exist yet: sudo groupadd docker first.

Know what this gives away

Being in the docker group is equivalent to root access on that machine. Anyone in it can start a container that mounts the whole filesystem and do anything. That's fine on your own laptop or a single-user server. On a shared machine, think twice. (Principle of least privilege)

The safer alternative: rootless Docker

Rootless mode runs the Docker daemon as your own user, with no root privileges at all. Containers can't gain more power than you have.

dockerd-rootless-setuptool.sh install

There are some limitations (privileged ports below 1024, some networking and storage drivers), so check Docker's rootless documentation. (Rootless containers and user namespaces)

Podman is another option: a Docker-compatible tool that runs rootless by default.

Other causes

Docker isn't running

A slightly different message — Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running? — means the service is stopped:

sudo systemctl start docker
sudo systemctl enable docker   # start on boot

On Mac and Windows, start Docker Desktop.

Docker Desktop and contexts

With Docker Desktop, the CLI may be pointing at the wrong place. List and switch contexts:

docker context ls
docker context use desktop-linux

WSL on Windows

Enable WSL integration for your distro in Docker Desktop → Settings → Resources → WSL Integration. (What is WSL?)

CI runners and dev containers

Inside a container that needs to run Docker, the socket must be mounted in and the user inside the container must have permission. Mounting the host's socket into a container gives that container control of the host's Docker — treat it as host root.

Don't do these

  • sudo chmod 666 /var/run/docker.sock — makes Docker (and therefore root) available to every user and process on the machine. It also resets on restart.
  • Running everything with sudo docker permanently — files created in mounted folders end up owned by root, causing more permission problems later. (Linux file permissions)

EasySpawn runs your apps on a managed server where containers and their permissions are set up for you, and each account's workloads are isolated in their own VM. See how it works or join the waitlist.

Related: What Is Docker? · Docker Commands Cheat Sheet · Rootless Containers and User Namespaces · Docker vs Linux Users

Keep reading