Skip to content

Commit

Permalink
config: start with a full capability set
Browse files Browse the repository at this point in the history
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
  • Loading branch information
Christian Brauner committed Mar 1, 2018
1 parent 4cb5384 commit 5c0d54c
Showing 1 changed file with 4 additions and 0 deletions.
4 changes: 4 additions & 0 deletions config/templates/userns.conf.in
Expand Up @@ -2,5 +2,9 @@
lxc.cgroup.devices.deny =
lxc.cgroup.devices.allow =

# Start with a full set of capabilities in user namespaces.
lxc.cap.drop =
lxc.cap.keep =

# We can't move bind-mounts, so don't use /dev/lxc/
lxc.tty.dir =

0 comments on commit 5c0d54c

Please sign in to comment.