TL;DR: Your user cannot read the docker socket. Run `sudo usermod -aG docker $USER`, then log out and back in (or `newgrp docker` in the current shell), and `docker ps` will work without sudo. The socket is owned by root:docker, so non-group users get permission denied even though the daemon is fine.

## The error

```text
Got permission denied while trying to connect to the Docker daemon socket at unix:///var/run/docker.sock: dial unix /var/run/docker.sock: connect: permission denied
```

## Fix it

1. Confirm the daemon is actually up (this rules out the not-running case):
   `sudo docker ps`
   Expected: works fine under sudo.
2. Check the socket ownership:
   `ls -l /var/run/docker.sock`
   Expected: `srw-rw---- 1 root docker ...` and `groups` does not list `docker`.
3. Add your user to the docker group:
   `sudo usermod -aG docker $USER`
   Expected: no output.
4. Apply the group change. Either log out and back in, or in the current shell:
   `newgrp docker`
   Expected: `groups` now lists `docker`.
5. Verify without sudo:
   `docker ps`
   Expected: container list, no permission error.

## When this applies
- `sudo docker ...` works but plain `docker ...` gives permission denied
- Right after installing Docker Engine on Linux

## When this does NOT apply
- Error is "Cannot connect to the Docker daemon" with no permission mention (daemon is down)
- Docker Desktop for Mac/Windows (no docker group concept; check the Desktop app is running)
- Rootless docker (socket lives under your home dir; check DOCKER_HOST instead)

## Versions
All Docker Engine versions on Linux. Same on WSL2 distros running the engine directly.

## Why it happens
The daemon listens on a unix socket with group `docker` and mode 660. Your shell session picked up its group list at login, so the new membership only takes effect after re-login or `newgrp`.

## Edge cases
- `newgrp docker` starts a subshell; your env tweaks in the parent shell are not carried over. A full logout/login is cleaner.
- Security note: the docker group is effectively root-equivalent (any member can mount the host rootfs into a container). Only add trusted users.
- On some distros the socket is at /run/docker.sock with /var/run a symlink; same fix.
