Showing posts with the label CAP_SYS_ADMIN

Stop Kubernetes Container Escapes: Drop Linux Capabilities

Most Kubernetes pods run with significantly more power than they actually need to function. By default, the container runtime grants a subset of po…
Stop Kubernetes Container Escapes: Drop Linux Capabilities
OlderHomeNewest