Port 2376: Docker TLS

Port 2376 is the Docker Engine API secured with TLS client certificates, the safer counterpart to the unencrypted API on port 2375. It is the port Docker's own documentation recommends when the API needs to be reachable remotely.

TCPInfrastructure & orchestration Encrypted
Port number2376
ServiceDocker daemon API (TLS)
ProtocolTCP
CategoryInfrastructure & orchestration
Default encryptionYes (TLS/SSH)

Frequently asked questions

What is port 2376 used for?

Port 2376 is the Docker Engine API secured with TLS client certificates, the safer counterpart to the unencrypted API on port 2375. It is the port Docker's own documentation recommends when the API needs to be reachable remotely.

Is port 2376 TCP or UDP?

Port 2376 (Docker TLS) uses TCP.

Is port 2376 secure?

Yes. Port 2376 carries encrypted traffic by default, so data in transit is protected.

Should I open port 2376 on my firewall?

Only if you specifically need Docker TLS. Expose it to the smallest set of trusted sources, and never open database or Windows-service ports to the whole internet.