docker normally runs as root but you can also run it #rootless
docker normally runs as root so has a very high attack surface but you can also run it #rootless
- https://docs.docker.com/engine/security/security/#docker-daemon-attack-surface
- https://docs.docker.com/engine/security/rootless/
- https://docs.docker.com/engine/security/rootless/#known-limitations
see also