Got permission denied while trying to connect to the Docker daemon socket at unix:///var/run/docker.sock
Fixes docker 'permission denied' socket errors by adding the user to the docker group and re-logging in. Use when docker commands fail with 'dial unix /var/run/docker.sock: connect: permission denied' but sudo docker works. Not for daemon-not-running errors or remote-host connection failures.
TL;DR: Your user cannot read the docker socket. Run sudo usermod -aG docker $USER, then log out and back in (or newgrp docker in the current shell), and docker ps will work without sudo. The socket is owned by root:docker, so non-group users get permission denied even though the daemon is fine.
The error
Got permission denied while trying to connect to the Docker daemon socket at unix:///var/run/docker.sock: dial unix /var/run/docker.sock: connect: permission deniedFix it
- Confirm the daemon is actually up (this rules out the not-running case):
sudo docker ps Expected: works fine under sudo.
- Check the socket ownership:
ls -l /var/run/docker.sock Expected: srw-rw---- 1 root docker ... and groups does not list docker.
- Add your user to the docker group:
sudo usermod -aG docker $USER Expected: no output.
- Apply the group change. Either log out and back in, or in the current shell:
newgrp docker Expected: groups now lists docker.
- Verify without sudo:
docker ps Expected: container list, no permission error.
When this applies
sudo docker ...works but plaindocker ...gives permission denied- Right after installing Docker Engine on Linux
When this does NOT apply
- Error is "Cannot connect to the Docker daemon" with no permission mention (daemon is down)
- Docker Desktop for Mac/Windows (no docker group concept; check the Desktop app is running)
- Rootless docker (socket lives under your home dir; check DOCKER_HOST instead)
Versions
All Docker Engine versions on Linux. Same on WSL2 distros running the engine directly.
Why it happens
The daemon listens on a unix socket with group docker and mode 660. Your shell session picked up its group list at login, so the new membership only takes effect after re-login or newgrp.
Edge cases
newgrp dockerstarts a subshell; your env tweaks in the parent shell are not carried over. A full logout/login is cleaner.- Security note: the docker group is effectively root-equivalent (any member can mount the host rootfs into a container). Only add trusted users.
- On some distros the socket is at /run/docker.sock with /var/run a symlink; same fix.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.