spiegel_podman/pkg/spec
Daniel J Walsh b163640c61
Allow devs to set labels in container images for default capabilities.
This patch allows users to specify the list of capabilities required
to run their container image.

Setting a image/container label "io.containers.capabilities=setuid,setgid"
tells podman that the contained image should work fine with just these two
capabilties, instead of running with the default capabilities, podman will
launch the container with just these capabilties.

If the user or image specified capabilities that are not in the default set,
the container will print an error message and will continue to run with the
default capabilities.

Signed-off-by: Daniel J Walsh <dwalsh@redhat.com>
2020-03-02 16:37:32 -05:00
..
config_linux.go apiv2 container create using specgen 2020-02-19 15:20:15 -06:00
config_linux_cgo.go add pkg/seccomp 2020-02-12 17:10:18 +01:00
config_linux_nocgo.go Split up create config handling of namespaces and security 2019-11-07 21:23:23 -05:00
config_unsupported.go apiv2 container create using specgen 2020-02-19 15:20:15 -06:00
containerconfig.go remove libpod from main 2019-06-25 13:51:24 -05:00
createconfig.go Allow devs to set labels in container images for default capabilities. 2020-03-02 16:37:32 -05:00
namespaces.go spec: allow container alias name in lookup 2020-02-26 15:04:31 +01:00
parse.go apiv2 container create using specgen 2020-02-19 15:20:15 -06:00
ports.go Spell check strings and comments 2018-05-25 08:45:15 +00:00
security.go Allow devs to set labels in container images for default capabilities. 2020-03-02 16:37:32 -05:00
spec.go Allow devs to set labels in container images for default capabilities. 2020-03-02 16:37:32 -05:00
spec_test.go Split up create config handling of namespaces and security 2019-11-07 21:23:23 -05:00
storage.go Merge pull request #5222 from mheon/fix_5219 2020-02-20 18:16:52 -05:00
storage_test.go Use EqualValues instead of reflect equality 2019-05-01 10:19:05 -04:00