Traditionally on Linux, root could do everything and other users almost nothing. Capabilities split root's power into smaller named privileges, such as NET_BIND_SERVICE (bind to ports below 1024), NET_ADMIN (change network settings), CHOWN (change file ownership) and SYS_ADMIN (a very broad set of administrative actions). Container runtimes give containers a default subset of capabilities, and you can adjust it per container.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.