mirror of
https://github.com/podman-container-tools/podman.git
synced 2026-08-14 04:39:33 +00:00
This commit does the following: - Splits the podman-systemd.unit.5.md into multiple files - one for each quadlet file type. - Adds the podman-quadlet-basic-usage.7.md for quadlet examples. - Majority of the text in the new files is copied from the podman-systemd.unit.5.md - Adds support for very simple condditional in the markdown_preprocess. - Uses new logic in markdown_preprocess in options/*.md to use a single .md file for both podman subcommands man-pages and quadlet man-pages. This deduplicates the Quadlet man-pages a lot. - Adds new `@@option quadlet:source.md`` preprocess command to import such .md files from options directory. Signed-off-by: Jan Kaluza <jkaluza@redhat.com>
23 lines
945 B
Markdown
23 lines
945 B
Markdown
####> This option file is used in:
|
||
####> podman podman-container.unit.5.md.in, create, run
|
||
####> If file is edited, make sure the changes
|
||
####> are applicable to all of those.
|
||
<< if is_quadlet >>
|
||
### `AddCapability=capability`
|
||
<< else >>
|
||
#### **--cap-add**=*capability*
|
||
<< endif >>
|
||
|
||
Add Linux capabilities.
|
||
|
||
Granting additional capabilities increases the privileges of the
|
||
processes running inside the container and potentially allow it to
|
||
break out of confinement. Capabilities like `CAP_SYS_ADMIN`,
|
||
`CAP_SYS_PTRACE`, `CAP_MKNOD` and `CAP_SYS_MODULE` are particularly
|
||
dangerous when they are not used within a user namespace. Please
|
||
refer to **user_namespaces(7)** for a more detailed explanation of the
|
||
interaction between user namespaces and capabilities.
|
||
|
||
Before adding any capability, review its security implications and
|
||
ensure it is really necessary for the container’s functionality. See
|
||
**capabilities(7)** for more information.
|