Exposed daemon API

The Docker daemon API is root on the host by design: anyone who can talk to it can start a privileged container that mounts the host. It listens on a local socket by default, but operators frequently expose it on TCP, on 2375 in plaintext or 2376 with TLS, for remote management and CI. Any reachable daemon API is game over for the host.

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more