Install Docker on popular Linux distributions: a Linux Docker installation guide
Level: Intermediate
Estimated time: ~15 minutes
Goal: Configure a secure, decentralized environment by setting up Docker to self-host personal services like Nextcloud, Bitwarden, and Matrix.
Introduction
Hosting your own "Cloud" services guarantees privacy and complete data ownership. To deploy services like Nextcloud (for file storage), Bitwarden (for password management), or Matrix (for secure communication) without dealing with complex host-level dependencies, you need isolated environments. In this tutorial, we will cover how to install Docker on Linux to build a robust, reproducible self-hosting foundation. Whether you need a complete Docker setup on Linux for a single server or a fleet, every step below applies to Ubuntu, Debian, and RHEL-compatible distributions. By the end of this Linux Docker installation guide you will have a production-ready environment configured with best-practice security defaults.
Terminology
Before proceeding, ensure you understand these core concepts:
- Docker: A platform for developing, shipping, and running applications in isolated environments.
- Docker Engine: The core client-server technology that creates and runs containers.
- Container: A standardized, executable component combining application source code with the operating system libraries and dependencies required to run it.
- Image: A read-only template with instructions for creating a container.
- Docker daemon: The background service running on the host that manages building, running, and distributing containers.
- Docker CLI: The command-line interface used to interact with the daemon.
- Docker Hub: A public registry maintained by Docker for finding and sharing container images.
- Registry: A storage and distribution system for container images.
- Installation: The process of making programs ready for execution.
- Package manager: A software tool that automates installing, upgrading, configuring, and removing programs.
- Repository: A central location where software packages are stored and maintained.
- Official Docker repository: The trusted source maintained by Docker for obtaining stable software packages.
- Package: A compressed file archive containing all the files that come with a particular application.
- Dependency: A program or library required by another program to function correctly.
- Stable release: A software version that has been thoroughly tested and is considered reliable for production use.
- Version: A unique state of the software reflecting its specific features and fixes.
Prerequisites
Before you begin, make sure the following conditions are met:
- Operating system: Ubuntu 20.04/22.04/24.04 LTS, Debian 11/12/13, or RHEL-compatible (AlmaLinux, Rocky, RHEL) 8/9/10
- Access: sudo or root access to the server
- Required knowledge: confident use of the Linux command line
Step 1: Set up the Docker repository
To ensure you get the latest secure and stable release, always use the Official Docker repository rather than the default OS repositories.
For Ubuntu:
First, update your Linux package manager index and install required packages to allow apt to use a repository over HTTPS:
sudo apt update sudo apt install ca-certificates curl gnupg lsb-release
Add Docker's official GPG key:
sudo mkdir -m 0755 -p /etc/apt/keyrings curl -fsSL https://download.docker.com/linux/ubuntu/gpg | \ sudo gpg --dearmor -o /etc/apt/keyrings/docker.gpg
Set up the stable repository:
echo \ "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] \ https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | \ sudo tee /etc/apt/sources.list.d/docker.list > /dev/null
For Debian:
The steps to install Docker on Debian mirror the Ubuntu flow but point to the Debian-specific repository URL. First, update your Linux package manager index and install required packages:
sudo apt update sudo apt install ca-certificates curl gnupg lsb-release
Add Docker's official GPG key:
ssudo mkdir -m 0755 -p /etc/apt/keyrings curl -fsSL https://download.docker.com/linux/debian/gpg | \ sudo gpg --dearmor -o /etc/apt/keyrings/docker.gpg
Set up the stable repository:
echo \ "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] \ https://download.docker.com/linux/debian $(lsb_release -cs) stable" | \ sudo tee /etc/apt/sources.list.d/docker.list > /dev/null
For RHEL-compatible (AlmaLinux, Rocky, RHEL):
Install the yum-utils package and set up the stable repository:
sudo yum install -y yum-utils sudo yum-config-manager \ --add-repo \ https://download.docker.com/linux/centos/docker-ce.repo
Docker publishes packages for all RHEL-compatible distributions (including AlmaLinux and Rocky Linux) under the centos repository path. Using this URL is expected and fully supported.
Result: The Docker repository is now added to your system, enabling the package manager to fetch the latest Docker packages.
Step 2: Install Docker on Ubuntu and Debian
With the Docker repository configured, proceed to install Docker Engine on Ubuntu (or Debian - the commands are identical). This step applies to both distributions.
First, remove any conflicting packages provided by the OS repositories:
sudo apt remove docker.io podman-docker containerd runc
Update the apt package index again, and use the Linux package manager to install the required components:
sudo apt update sudo apt install docker-ce docker-ce-cli containerd.io docker-buildx-plugin \ docker-compose-plugin
Result: The command runs, fetching the packages and any required dependency from the Docker repository. You should see the package manager complete the installation of the Docker Engine without errors.
docker-ce refers to Docker Community Edition, which is the free version ideal for self-hosters.
Step 3: Install Docker on RHEL-compatible (AlmaLinux, Rocky, RHEL)
For RHEL-based systems, use yum to install the Docker Engine.
First, remove any conflicting packages provided by the OS repositories:
sudo yum remove docker docker-client docker-client-latest docker-common \ docker-latest docker-latest-logrotate docker-logrotate docker-engine \ podman runc
Run the following command:
sudo yum install docker-ce docker-ce-cli containerd.io docker-buildx-plugin \ docker-compose-plugin
Result: The package manager installs the necessary packages. You will be prompted to accept the GPG key (unless you pass the -y flag); confirm it. Once complete, you will see a success message.
Step 4: Docker Engine installation verification
After installation, the Docker daemon behavior varies by distribution. On Ubuntu and Debian, docker.service starts automatically upon installation. On RHEL-family distributions, it does not.
RHEL-family only: If the installation process updated the kernel (for example, via a kernel-core dependency), reboot the server before starting the Docker service:
sudo reboot
Skipping this step may cause systemctl start docker to fail with br_netfilter / addrtype errors because the running kernel no longer matches the installed modules.
Once the server is running on the current kernel, start and enable the service. The following commands are idempotent and safe to run on all systems:
sudo systemctl start docker sudo systemctl enable docker
Result: The Docker daemon starts, and the system creates a symlink to ensure it starts automatically on every reboot.
Verify that the Docker Engine installation is successful by running the hello-world image:
sudo docker run hello-world
Result: The Docker CLI contacts the Docker daemon, pulls the hello-world image from Docker Hub, and runs a container. You should see a message stating "Hello from Docker!" printed in your terminal.
Step 5: Post-install Docker steps
By default, running Docker commands requires sudo. To run Docker commands as a non-root user, you need to add your user to the docker group. These are essential post-install Docker steps for managing your self-hosted infrastructure comfortably.
Create the docker group (if it doesn't already exist):
getent group docker || sudo groupadd docker
Add your user to the docker group:
sudo usermod -aG docker $USER
Result: Your user is added to the group. For the changes to take effect, you must log out and log back in, or activate the new group membership in the current session:
newgrp docker
newgrp docker creates a new shell with the updated group membership. Any docker command you run afterward will work without sudo, but only inside this new shell. Opening another terminal still requires a full re-login.
Membership in the docker group grants privileges equivalent to root access on the host. For self-hosting environments prioritizing security, strongly consider running Docker rootless (see Step 6).
After running newgrp docker (or logging out and back in), test the configuration by running a command without sudo:
docker run hello-world
Result: You should see the "Hello from Docker!" message again, confirming that your post-install Docker steps were successful.
Alternative: Quick install via convenience script
For testing or development environments, Docker provides a convenience script.
This method is not recommended for production. It runs without version pinning, performs an unconditional upgrade if Docker is already installed, and pulls all dependencies without verification.
It is recommended to download the script and inspect it before execution:
curl -fsSL https://get.docker.com -o get-docker.sh sh get-docker.sh
Step 6 (Optional): Run Docker rootless
For self-hosting environments, running Docker rootless enhances security by executing the Docker daemon and containers as a non-root user.
6.1 Prerequisites
First, stop and disable the system-wide Docker service and socket, and remove the socket file:
sudo systemctl stop docker.service docker.socket sudo systemctl disable docker.service docker.socket sudo rm -f /var/run/docker.sock
Verify that your user has subuid and subgid configured (usually set up automatically):
cat /etc/subuid cat /etc/subgid
Enable lingering for your user so the daemon can start on boot:
sudo loginctl enable-linger $USER
6.2 Install additional packages
For Ubuntu/Debian:
sudo apt install docker-ce-rootless-extras uidmap dbus-user-session
For AlmaLinux/RHEL (shadow-utils provides uidmap and is usually pre-installed):
sudo yum install docker-ce-rootless-extras
6.3 Install the rootless daemon
Run the setup script from a full login session of the target user (not from sudo su or a non-login SSH shell). If you are in a non-login context, export the required variables first:
export XDG_RUNTIME_DIR=/run/user/$(id -u) export DBUS_SESSION_BUS_ADDRESS=unix:path=$XDG_RUNTIME_DIR/bus
Then run the setup script:
dockerd-rootless-setuptool.sh install
The first run of the setup script immediately after enabling linger might be unstable. If the daemon fails to start, simply run the installation script again.
6.4 Configure environment variables
Add the following variables to your shell configuration file (e.g., ~/.bashrc):
export PATH=/usr/bin:$PATH export DOCKER_HOST=unix:///run/user/$(id -u)/docker.sock
Source the file or restart your shell to apply.
6.5 Limitations of rootless mode
- Cannot publish ports < 1024 (Docker provides workarounds like
setcap,slirp4netnsport forwarding, or routing). - No
--net=hostsupport. - Swarm mode and overlay networks are not supported.
- AppArmor is not supported.
- The
--privilegedflag does not grant host-level root access. - Data is stored in
~/.local/share/docker(consider this for backups and quotas). - Requires cgroup v2.
- Uses the
overlayfsstorage driver instead ofoverlay2.
Rollback
If you need to revert the Docker installation on Linux - whether it is a standard Docker for Linux setup or a rootless configuration - follow the steps below in order.
1. Rootless rollback (skip if rootless was not configured):
If you configured rootless mode, revert those changes first, before removing packages:
dockerd-rootless-setuptool.sh uninstall rm -rf ~/.local/share/docker sudo loginctl disable-linger $USER
Running rootless uninstall after the packages have been purged will fail because the setup script is part of the docker-ce-rootless-extras package. Always uninstall rootless mode while the packages are still present.
2. Remove packages:
Debian/Ubuntu:
sudo apt purge docker-ce docker-ce-cli containerd.io docker-buildx-plugin \ docker-compose-plugin docker-ce-rootless-extras sudo rm -rf /var/lib/docker /var/lib/containerd sudo rm -f /etc/apt/sources.list.d/docker.list /etc/apt/keyrings/docker.gpg
AlmaLinux/Rocky/RHEL:
sudo yum remove docker-ce docker-ce-cli containerd.io docker-buildx-plugin \ docker-compose-plugin docker-ce-rootless-extras sudo rm -rf /var/lib/docker /var/lib/containerd sudo rm -f /etc/yum.repos.d/docker-ce.repo
3. Remove the group:
sudo groupdel docker || true
Removing the packages does not automatically remove images, containers, volumes, or customized configuration files. The rm -rf commands permanently delete these data directories.
Conclusion
Your Docker installation on Linux is complete and verified. The foundation is now set up securely. You can proceed to deploy containers for your self-hosted tools, ensuring complete control over your Nextcloud files, Bitwarden vaults, and Matrix communications.
Document Version: 1.0
Last Updated: May 2026
Owner: Technical Documentation Team