Skip to content

NoNewPrivileges support in docker  #20329

@mrunalp

Description

@mrunalp

NoNewPrivileges support was added to the OCI spec and is in the process of being added to runc. The purpose of this issue is to discuss options for integrating this into docker. There are two options:

  1. Add a flag to enable this setting optionally.
  2. Enable this setting by default for all containers.

Any thoughts?

@crosbymichael @LK4D4 @rhatdan

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/featureFunctionality or other elements that the project doesn't currently have. Features are new and shiny

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions