When we use networking and remote api the whole network have access to dockes api. To protect and restric access to specific client s i've followed this howto https://docs.docker.com/engine/security/https/ that use tls certificate to allow just clients with credentials