Can anyone explain docker.sock

I am trying to understand the actual reason for mounting docker.sock in docker-compose.yml file. Is it for auto-discovery?

- /var/run/docker.sock:/var/run/docker.sock

  • How to communicate with Kafka server running inside a docker
  • Docker containers not using host DNS in boot2docker
  • Docker CMD doesn't see installed components
  • Docker - docker compose two branches - Updated
  • Docker containers communication without exposing ports
  • Local hostnames for Docker containers
  • Docker for Windows: Spinning up multiple docker containers locally with same port numbers
  • Is it better to build and test in a container?
  • Can't start or list docker Machines created on another partition
  • In fedora container systemctl gives Failed to get D-Bus connection
  • How to run Docker container and watch the logs in one single command
  • Docker with a Rails App-Workers not running
  • One Solution collect form web for “Can anyone explain docker.sock”

    docker.sock is the UNIX socket that Docker daemon is listening to. It’s the main entry point for Docker API. It also can be TCP socket but by default for security reasons Docker defaults to use UNIX socket.

    Docker cli client uses this socket to execute docker commands by default. You can override these settings as well.

    There might be different reasons why you may need to mount Docker socket inside a container. Like launching new containers from within another container. Or for auto service discovery and Logging purposes. This increases attack surface so you should be careful if you mount docker socket inside a container there are trusted codes running inside that container otherwise you can simply compromise your host that is running docker daemon, since Docker by default launches all containers as root.

    Docker socket has a docker group in most installation so users within that group can run docker commands against docker socket without root permission but actual docker containers still get root permission since docker daemon runs as root effectively (it needs root permission to access namespace and cgroups).

    I hope it answers your question.

    More info:

    Docker will be the best open platform for developers and sysadmins to build, ship, and run distributed applications.