]> git.ipfire.org Git - thirdparty/lxc.git/commitdiff
config: start with a full capability set
authorChristian Brauner <christian.brauner@ubuntu.com>
Thu, 1 Mar 2018 16:09:44 +0000 (17:09 +0100)
committerChristian Brauner <christian.brauner@ubuntu.com>
Thu, 23 Aug 2018 20:42:43 +0000 (22:42 +0200)
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
config/templates/userns.conf.in

index bde6f1db21e968daaa64c8c1d6f5d97de17d3da2..63d018964c478eb17b4a326b17ec669927e37a94 100644 (file)
@@ -2,5 +2,9 @@
 lxc.cgroup.devices.deny =
 lxc.cgroup.devices.allow =
 
+# Start with a full set of capabilities in user namespaces.
+lxc.cap.drop =
+lxc.cap.keep =
+
 # We can't move bind-mounts, so don't use /dev/lxc/
 lxc.devttydir =