StudyToCert

All certifications / CKAD / Lessons

Certified Kubernetes Application Developer CKAD (Kubernetes v1.35 curriculum) · Domain 4: Application Environment, Configuration and Security

Linux capabilities (add/drop) and Pod Security Admission levels (privileged, baseline, restricted)

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Traditionally on Linux, root could do everything and other users almost nothing. Capabilities split root's power into smaller named privileges, such as NET_BIND_SERVICE (bind to ports below 1024), NET_ADMIN (change network settings), CHOWN (change file ownership) and SYS_ADMIN (a very broad set of administrative actions). Container runtimes give containers a default subset of capabilities, and you can adjust it per container.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CKAD for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CKAD study plan