⇤ ← Revision 1 as of 2021-10-23 09:20:01
298
Comment:
|
299
|
Deletions are marked like this. | Additions are marked like this. |
Line 1: | Line 1: |
= k8s/StudyNotes/ Security Docker= | = k8s/StudyNotes/ Security Docker = |
k8s/StudyNotes/ Security Docker
- Docker uses Namespace on linux does isolation, process still visible on host.
- /usr/include/linux/capability.h
- can limit capability's.
- /usr/include/linux/capability.h
On Docker can add capabilities
docker run --cap-add MAC_ADMIN or --cap-drop or --privileged