The docker socket at /var/run/docker.sock can be exposed to containers and it will be able to manage the Docker infrastructure.

  • by default, the container with that permission is able to access everything

Docker Socket Proxy