Skip to content
BotServBotServ
DockerRootlessSecurityContainerPermissions

Running Rootless Docker

Run Docker without root privileges. Benefits, installation, limitations, and GPU passthrough in rootless mode.

S

schutzgeist

3 min read
Running Rootless Docker

Running Docker Rootless

What this article covers

  • What Rootless Docker is.
  • Why it reduces security risk.
  • How to install and configure it.
  • Limitations and compatibility.
  • GPU passthrough and common issues.

Introduction: Running Docker Rootless

By default, the Docker daemon runs as root. If a container escapes or a vulnerability is exploited, an attacker potentially gains root access to the host. Rootless Docker shifts the daemon into a user context. A successful attack then only grants the privileges of an unprivileged user, significantly reducing the attack surface.

This article explains how Rootless Docker works, how to set it up, and when it makes sense.

Key concepts

  • Rootless: Running without root privileges.
  • User Namespace: Isolation of user IDs within a container.
  • Rootlesskit: Tool that enables rootless functionality.
  • Daemon: Background process that manages containers.
  • OverlayFS: Filesystem that supports rootless operation.
  • Cgroups: Resource management in Linux.
  • Privileged Ports: Ports below 1024 that previously required root.
  • Docker Context: Environment configuration for Docker.

Benefits of Rootless Docker

  • Container breakout does not grant root privileges.
  • Daemon runs in user context.
  • Reduced attack surface on the host.
  • Better isolation between user and system processes.
  • Safer for multi-user environments.

Requirements

  • Linux with kernel support for user namespaces.
  • newuidmap and newgidmap installed.
  • Docker package with rootless support.
  • Overlay2 or compatible filesystem.

Installation

sudo apt-get update
sudo apt-get install -y uidmap

dockerd-rootless-setuptool.sh install

After installation, pay attention to the environment variable note:

export DOCKER_HOST=unix:///run/user/$UID/docker.sock

Or add it to .bashrc or .zshrc.

Starting Rootless Docker

systemctl --user start docker
systemctl --user enable docker

Verify:

docker info
docker context ls

Differences from standard Docker

  • docker commands run in user context.
  • Containers are visible to the user, not system-wide.
  • Ports below 1024 require additional configuration.
  • Systemd services run under --user.
  • Volumes reside in the user’s home directory.

Privileged ports

Ports below 1024 normally require root privileges. Rootless cannot bind them directly. Solutions include:

  • Use a port above 1024, for example 8080 instead of 80.
  • Set sysctl net.ipv4.ip_unprivileged_port_start=0 to allow all ports for the user.
  • Place a reverse proxy with root privileges in front.

GPU passthrough in rootless mode

GPU passthrough is more complex because GPU device files require special permissions:

  • The user must belong to the video or render group.
  • udev rules must make the devices accessible.
  • The Nvidia Container Toolkit cannot work with rootless without additional setup.

For GPU workloads, Rootless Docker is often not the first choice. Rootfull Docker or alternative solutions are typically simpler.

Compose with Rootless

Compose works in rootless mode as long as the environment is configured correctly:

docker compose up -d

Volumes are then located under ~/.local/share/docker/volumes/.

Logs and debugging

journalctl --user -u docker
docker logs containername

Missing permissions or incorrect contexts are common sources of errors.

Security

  • Rootless reduces, but does not eliminate all risks.
  • The user ID inside the container should not be root.
  • Continue to restrict capabilities.
  • Do not mount sensitive directories into containers.
  • Keep secrets out of the home directory.

When is Rootless worth it?

  • Multi-user systems.
  • Shared hosting.
  • Development environments.
  • Sensitive servers without GPU dependencies.
  • Environments where root should be minimized.

For AI workloads with GPU, Rootless is often harder because drivers and device access are more complex.

Common pitfalls

  • DOCKER_HOST not set: Docker commands fail.
  • uidmap missing: Installation aborts.
  • Systemd not enabled for user: Daemon does not start automatically.
  • Port 80 unavailable: Port mapping fails.
  • GPU unreachable: Permissions or toolkit missing.
  • Volumes in wrong location: Data appears lost.
  • Images not visible: Rootless and system Docker are separate.

FAQ: Rootless Docker

Is Rootless Docker slower? Barely. OverlayFS and networking can behave slightly differently.

Can I use Rootless with Compose? Yes, Compose works in rootless mode.

Why won’t my daemon start? Often DOCKER_HOST is missing or the user service is not enabled.

Can I use ports below 1024? Only with additional configuration or a reverse proxy.

Is Rootless Docker suitable for servers? Yes, provided no complex hardware integrations are needed.

References and further reading

Summary: Running Docker Rootless

Rootless Docker improves security by running the daemon in user context. This significantly reduces the impact of a container breakout. Setup and operation are straightforward on modern Linux systems, but come with limitations on ports below 1024, systemd integration, and GPU passthrough. For multi-user environments, development machines, and security-critical setups, Rootless is a sensible choice, while GPU-based AI workloads often run more smoothly in standard mode.

Back to Blog
Share:

Related Posts