Skip to content

Add support for "no new privileges" #38417

@timstclair

Description

@timstclair

Support for setting NO_NEW_PRIVS was added in docker 1.11 (moby/moby#20329). This feature will be much more useful once user namespace support is added (#34569), but I believe it is also relevant when paired with seccomp or LSM (SELinux or AppArmor).

/cc @mrunalp @kubernetes/sig-node

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/securitysig/nodeCategorizes an issue or PR as relevant to SIG Node.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions