Hitting Cannot connect to the Docker daemon in CodeBuild almost always means privileged mode is off. Turn it on in the project environment settings and start the daemon in your buildspec install phase before any docker command runs.

Context: From the official AWS CodeBuild troubleshooting docs. A build that touches Docker fails with Cannot connect to the Docker daemon when the project is not running in privileged mode, which is off by default. The docs walk through enabling it in the project environment settings and starting the Docker daemon in the install phase of the buildspec. Enabling the flag alone is not enough if nothing starts the daemon.