| title | GitLab DinD β Cannot Connect to the Docker Daemon | |||||
|---|---|---|---|---|---|---|
| slug | gitlab-cannot-connect-to-docker-daemon-dind | |||||
| technologies |
|
|||||
| severity | high | |||||
| tags |
|
|||||
| related |
|
|||||
| last_reviewed | 2026-06-27 |
$ docker info
Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
ERROR: Job failed: exit code 1
error during connect: Get "http://docker:2375/v1.24/info": dial tcp: lookup docker on 10.0.0.10:53: no such host
This error appears in jobs that run docker build/docker push using the
Docker-in-Docker (DinD) pattern. The Docker client in the job cannot reach a
Docker daemon. Either no docker:dind service was started, the
DOCKER_HOST/TLS settings are wrong, or the client is looking at a local
unix:///var/run/docker.sock that does not exist inside the container. DinD
requires a services: daemon plus correct host/TLS variables wired between client
and daemon.
- gitlab (GitLab Runner, Docker executor, DinD service)
high β image build/push jobs fail entirely, blocking any pipeline that packages containers for release.
- The
docker:dindservice is not declared underservices:, so there is no daemon to connect to. DOCKER_HOST/DOCKER_TLS_CERTDIRmismatch β TLS enabled on one side but not the other (the classictcp://docker:2375vs2376+ certs confusion).- The runner is not configured with
privileged = true(DinD needs it) or lacks the host/certsvolume. - The job assumes
unix:///var/run/docker.sockbut no socket is mounted. - DNS for the
dockerservice alias is unavailable (custom network / FF off).
In DinD, GitLab starts a sidecar container from the docker:dind image that runs
dockerd and is reachable at the network alias docker. The job's docker CLI
must point at that daemon via DOCKER_HOST=tcp://docker:2376 with TLS, or
tcp://docker:2375 without. Modern docker:dind enables TLS by default and
publishes certs under DOCKER_TLS_CERTDIR=/certs; if the client doesn't mount
/certs/client and use port 2376, the handshake fails. If services: is missing
entirely, there is simply no daemon and the client falls back to the non-existent
local socket β hence "Cannot connect β¦ unix:///var/run/docker.sock." DinD also
requires the runner to run the helper container privileged.
# Confirm the job declares the dind service and the TLS/host variables
grep -nE 'services:|docker:dind|DOCKER_HOST|DOCKER_TLS_CERTDIR|DOCKER_DRIVER' .gitlab-ci.yml
# Confirm the runner runs containers privileged (required for DinD)
grep -nE 'privileged|volumes|\[runners.docker\]' /etc/gitlab-runner/config.toml
# From a debug session inside the job: is the daemon reachable?
docker info # client/daemon versions if connected
getent hosts docker # the dind service alias should resolve
ls -la /certs/client 2>/dev/null # TLS certs present when TLS is on
# Runner-side logs for the service container
journalctl -u gitlab-runner --since "15 min ago" --no-pager | grep -i dind# Broken (no service / wrong host):
Cannot connect to the Docker daemon at unix:///var/run/docker.sock
# Healthy:
$ docker info
Server Version: 25.x
$ getent hosts docker
10.0.x.x docker
-
Declare the DinD service and wire TLS correctly:
build-image: image: docker:25 services: [docker:25-dind] variables: DOCKER_HOST: tcp://docker:2376 DOCKER_TLS_CERTDIR: "/certs" DOCKER_CERT_PATH: "/certs/client" DOCKER_TLS_VERIFY: "1" script: - docker info - docker build -t "$CI_REGISTRY_IMAGE:$CI_COMMIT_SHA" .
To disable TLS instead, set
DOCKER_TLS_CERTDIR: ""andDOCKER_HOST: tcp://docker:2375(less secure). -
Configure the runner with
privileged = true:[runners.docker] privileged = true volumes = ["/certs/client", "/cache"]
then
sudo systemctl restart gitlab-runner. -
Match client major version to the dind image to avoid API-version skew.
docker info # inside the job: prints both Client and Server sections, exit 0
docker build . # proceeds past the daemon connection step- Keep a shared CI template for image builds with the DinD/TLS variables baked in.
- Pin
dockeranddocker:*-dindto the same major version. - Where the security model allows, prefer rootless builders (BuildKit/Kaniko) to avoid privileged DinD entirely.
gitlab Β· ci Β· docker Β· dind Β· production