Hacker News new | ask | show | jobs
by cats4256 2006 days ago
In traditional Docker installs, you (can) run as real UID 0 (and many containers do) with CAP_KILL [https://docs.docker.com/engine/reference/run/].