Docker: 'Permission Denied While Trying to Connect to the Docker Daemon Socket'

Your user can sudo but can't talk to the Docker daemon without it. That's the docker group — one command fixes it, but know what you're granting.

What you'll see

Root causes

User not in the docker group

The /var/run/docker.sock socket is owned by root:docker. Anyone in the docker group can talk to it; everyone else gets permission denied no matter what the command is.

Socket has non-standard permissions

Some hardened hosts tighten sock permissions (chmod 660 root:docker). Adding the user to docker alone may not be enough — check the socket's owner and mode.

Fix it

  1. Add your user to the docker group
    sudo usermod -aG docker $USER
  2. Activate the group without logging out
    newgrp docker   # or log out and back in
  3. Verify
    docker ps
  4. If still denied, check the socket itself
    ls -l /var/run/docker.sock   # expect srw-rw---- root docker

Field note

Membership in the docker group is root-equivalent: anyone in it can mount the host filesystem and escape the container boundary. On a shared box, prefer rootless Docker or limit who you add.

Common questions

Why does docker ps need sudo?

The docker socket is root-owned: /var/run/docker.sock grants full root-equivalent control of the host. Non-root users need group membership (usermod -aG docker $USER + re-login) — which is also why docker-group membership is treated as root access in security policies.

Is adding myself to the docker group safe?

It grants effective root: any docker-group member can mount the host filesystem into a container. Standard for a single-developer machine; on shared servers keep docker behind sudo and give CI runners narrowly scoped access instead.

Ship it right the first time

A production-shaped compose stack: healthchecks, resource limits, log rotation. Never debug a boot race again.

Docker Production Starter — $19 →

One-time. Yours to modify. Instant download from the NinjaOps template store.