Permissions

Control the container's system permissions.

Properties

Extended privileges

Disables isolation from the host.

  • Data type: boolean
  • Default: false
  • Configuration

CLI: (cli)> config compute container <key> permission privileged

Allow binding to privileged ports

Linux capability CAP_NET_BIND_SERVICE.

  • Data type: boolean
  • Default: false
  • Configuration

CLI: (cli)> config compute container <key> permission net-bind-service

Allow network administration

Linux capability CAP_NET_ADMIN.

  • Data type: boolean
  • Default: false
  • Configuration

CLI: (cli)> config compute container <key> permission net-admin

Allow raw network sockets

Linux capability CAP_NET_RAW.

  • Data type: boolean
  • Default: false
  • Configuration

CLI: (cli)> config compute container <key> permission net-raw

Allow overriding file discretionary access control

Linux capability CAP_DAC_OVERRIDE.

  • Data type: boolean
  • Default: false
  • Configuration

CLI: (cli)> config compute container <key> permission dac-override