mirror of
https://github.com/containers/podman.git
synced 2025-10-25 02:04:43 +08:00
quadlet: Use same default capability set as podman run
Signed-off-by: Alexander Larsson <alexl@redhat.com>
This commit is contained in:
@ -312,10 +312,7 @@ func ConvertContainer(container *parser.UnitFile, isUser bool) (*parser.UnitFile
|
||||
podman.add("--security-opt", fmt.Sprintf("seccomp=%s", seccompProfile))
|
||||
}
|
||||
|
||||
dropCaps := []string{"all"} // Default
|
||||
if container.HasKey(ContainerGroup, KeyDropCapability) {
|
||||
dropCaps = container.LookupAllStrv(ContainerGroup, KeyDropCapability)
|
||||
}
|
||||
dropCaps := container.LookupAllStrv(ContainerGroup, KeyDropCapability)
|
||||
|
||||
for _, caps := range dropCaps {
|
||||
podman.addf("--cap-drop=%s", strings.ToLower(caps))
|
||||
|
||||
Reference in New Issue
Block a user