1 Repo
Controls which Linux capabilities are inheritable by non-root users inside containers to mitigate privilege escalation.
Distinct from Root Capability Constraints: Distinct from Root Capability Constraints: focuses on restricting capabilities for non-root users, not root-granted processes.
Explore 1 awesome GitHub repository matching web development · Non-Root User Capability Restrictions. Refine with filters or upvote what's useful.
CRI-O is an open-source container runtime that implements the Kubernetes Container Runtime Interface (CRI) to manage container images, pods, and containers on cluster nodes using OCI-compatible runtimes. It serves as a node-level container manager that handles image pulling, container lifecycle, and resource monitoring for Kubernetes clusters, running containers according to the Open Container Initiative specifications. The runtime distinguishes itself through live configuration reloading that applies changes to runtime definitions, registry mirrors, and TLS certificates without restarting th
Controls which Linux capabilities are inheritable by non-root users inside containers to mitigate privilege escalation.