Allow CAP_SYS_MODULE to be set on containers
Closed, ResolvedPublicFEATURE REQUEST


This is particularly useful for the tailscale container outside of user-space.


Difficulty level
Unknown (require assessment)
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Perfectly compatible
Issue type
Improvement (missing useful functionality)

Event Timeline

According to this capability can load, unload AND delete kernel modules.

I think a security warning or such for the tabcompletion should exist for that setting.

That is whatever you now run as container might not be as isolated as you think if you enable this capability.

