![]() curl -unix-socket /var/run/docker.sock | jq The server does not care about the hostname, just the Also, as this server is local (remember, the file system), weĬan pass any hostname in the URL (or stick to the localhost, that will Since Docker Server API is exposed as REST, we’d need to send commands over The Docker daemon can listen for Docker Engine API requests via three different types of Socket: unix, tcp, and fd.īy default, a unix domain socket (or IPC socket) is created at /var/run/docker.sockĭocker Server uses this socket to listen to the REST API, and the clients use the socket to send API requests to the server.Ĭurl can talk to a Unix Socket via the -unix-socket flag. Unix Sockets use the local filesystem for communication, while IP Sockets use the network. ![]() They’re also called Unix Domain Sockets ( UDS). These are the ones that are bound to a port (and address), we send TCP requests to, and get responses from.Īnother type of Socket is a Unix Socket, these sockets are used for IPC (Interprocess Communication). The term Sockets commonly refers to IP Sockets. I know it bit late but I hope my answer will give so many insights This increases attack surface so you should be careful if you mount docker socket inside a container there are trusted codes running inside that container otherwise you can simply compromise your host that is running docker daemon, since Docker by default launches all containers as root.ĭocker socket has a docker group in most installation so users within that group can run docker commands against docker socket without root permission but actual docker containers still get root permission since docker daemon runs as root effectively (it needs root permission to access namespace and cgroups). ![]() Or for auto service discovery and Logging purposes. ![]() Like launching new containers from within another container. There might be different reasons why you may need to mount Docker socket inside a container. It also can be TCP socket but by default for security reasons Docker defaults to use UNIX socket.ĭocker cli client uses this socket to execute docker commands by default. ![]() It's the main entry point for Docker API. Docker.sock is the UNIX socket that Docker daemon is listening to. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |