Add the rest of the caps so that they are retained in privilged mode
Docker-DCO-1.1-Signed-off-by: Michael Crosby <michael@crosbymichael.com> (github: crosbymichael)
This commit is contained in:
parent
58ba10aa54
commit
3e097e5052
1 changed files with 17 additions and 0 deletions
|
@ -61,6 +61,23 @@ var (
|
||||||
{Key: "NET_RAW", Value: capability.CAP_NET_RAW},
|
{Key: "NET_RAW", Value: capability.CAP_NET_RAW},
|
||||||
{Key: "DAC_OVERRIDE", Value: capability.CAP_DAC_OVERRIDE},
|
{Key: "DAC_OVERRIDE", Value: capability.CAP_DAC_OVERRIDE},
|
||||||
{Key: "FOWNER", Value: capability.CAP_FOWNER},
|
{Key: "FOWNER", Value: capability.CAP_FOWNER},
|
||||||
|
{Key: "DAC_READ_SEARCH", Value: capability.CAP_DAC_READ_SEARCH},
|
||||||
|
{Key: "FSETID", Value: capability.CAP_FSETID},
|
||||||
|
{Key: "KILL", Value: capability.CAP_KILL},
|
||||||
|
{Key: "SETGID", Value: capability.CAP_SETGID},
|
||||||
|
{Key: "SETUID", Value: capability.CAP_SETUID},
|
||||||
|
{Key: "LINUX_IMMUTABLE", Value: capability.CAP_LINUX_IMMUTABLE},
|
||||||
|
{Key: "NET_BIND_SERVICE", Value: capability.CAP_NET_BIND_SERVICE},
|
||||||
|
{Key: "NET_BROADCAST", Value: capability.CAP_NET_BROADCAST},
|
||||||
|
{Key: "IPC_LOCK", Value: capability.CAP_IPC_LOCK},
|
||||||
|
{Key: "IPC_OWNER", Value: capability.CAP_IPC_OWNER},
|
||||||
|
{Key: "SYS_CHROOT", Value: capability.CAP_SYS_CHROOT},
|
||||||
|
{Key: "SYS_PTRACE", Value: capability.CAP_SYS_PTRACE},
|
||||||
|
{Key: "SYS_BOOT", Value: capability.CAP_SYS_BOOT},
|
||||||
|
{Key: "LEASE", Value: capability.CAP_LEASE},
|
||||||
|
{Key: "SETFCAP", Value: capability.CAP_SETFCAP},
|
||||||
|
{Key: "WAKE_ALARM", Value: capability.CAP_WAKE_ALARM},
|
||||||
|
{Key: "BLOCK_SUSPEND", Value: capability.CAP_BLOCK_SUSPEND},
|
||||||
}
|
}
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
Loading…
Reference in a new issue