Page MenuHomeVyOS Platform

Allow CAP_SYS_MODULE to be set on containers
Closed, ResolvedPublicFEATURE REQUEST

Description

This is particularly useful for the tailscale container outside of user-space.

https://man7.org/linux/man-pages/man7/capabilities.7.html

Details

Version
-
Is it a breaking change?
Perfectly compatible

Event Timeline

According to https://man7.org/linux/man-pages/man7/capabilities.7.html this capability can load, unload AND delete kernel modules.

I think a security warning or such for the tabcompletion should exist for that setting.

That is whatever you now run as container might not be as isolated as you think if you enable this capability.

syncer triaged this task as Low priority.Sep 3 2023, 5:44 PM
Viacheslav claimed this task.
Viacheslav moved this task from Open to Finished on the VyOS 1.4 Sagitta board.
Viacheslav subscribed.

@