You should be able to specify --cap-add=all --cap-drop=cap_perfmon And end up with all capabilties except cap_perfmon. You should not be allowed to specify --cap-add all --cap-drop all The outcome would be undefined. Signed-off-by: Daniel J Walsh <dwalsh@redhat.com> |
||
|---|---|---|
| .. | ||
| capabilities.go | ||
| capabilities_test.go | ||