Docker特权控制 --privileged --cap-add --cap-drop
docker使用--privileged --cap-add --cap-drop来控制容器的权限,能控制哪些权限,是怎样实现的? 首先,caplist有两个基准范围: 默认Cap集合 ``` src/oci/default_linux.go s.Process.Capabilities = []string{ "CAP_CHOWN", "CAP_DAC_OVERRIDE", "CAP_FSETID", "CAP_FOWNER", "CAP_MKNOD", "CAP_NET_RAW", "CAP_SETGI...