I think the answer is in the image description on Docker Hub
http://hub.docker.com/_/docker
TLS
Starting in 18.09+, the
dindvariants of this image will automatically generate TLS certificates in the directory specified by theDOCKER_TLS_CERTDIRenvironment variable.
…
…
To disable this image behavior, simply override the container command or entrypoint to rundockerddirectly (... docker:dind dockerd ...or... --entrypoint dockerd docker:dind ...).