I think you and refi64 are right on. The suggestion to disable SELinux worked. Here is the info you requested:
Is the docker service started?
…yes.
What do the permissions + SELinux labels look like on the socket?
$ ls -laZ /var/run/docker.sock
srw-rw----. 1 root root system_u:object_r:container_var_run_t:s0 0 Aug 5 21:50 /var/run/docker.sock
Are there any errors in the journal about docker ?
Additionally, any SELinux denials?
Yes, this is the top error which includes avc denial:
Aug 10 09:32:41 mediabarn audit[13556]: AVC avc: denied { connectto } for pid=13556 comm=“docker-gen” path="/run/docker.sock" scontext=system_u:system_r:container_t:s0:c179,c1019 tcontext=system_u:system_r:container_runtime_t:s0 tclass=unix_stream_socket permissive=0