"sudo usermod -aG docker $USER" is convenient.
But also gives every process in your login session access to the Docker socket
It's not widely known but THERE IS a different way to make rootful Docker access more granular:
Why the hell is music industry still doing this ugly "final_final_v2_2026.mp3" thing
Stop polluting the names in my favourite metal album!!
mfs, use metadata for that, combine it under one album, and just allow to pick a specific mix with a dropdown
🐳 Happy to announce that we've just released Docker Engine 29.8.0!
Plenty of good stuff there:
- docker run --umask ...
- Support for "pesto" rootless network driver
- Security hardening for AF_VSOCK
- Swarm DNS and gossip fixes
and many more, see: