In Fedora Rawhide, I have eliminated some CAPABILITIES from the default list to make containers more secure. The containers.conf should be listed here as well. The default list in code is still the Docker defaults, but I have eliminated three from the default list AUDIT_WRITE, MKNOD, NET_RAW In Fedora 33 we have eliminated just MKNOD and NET_RAW. Signed-off-by: Daniel J Walsh <dwalsh@redhat.com> |
||
|---|---|---|
| common | ||