Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Only drop capabilities that are not added
It appears that containerd (or k8s 1.24?) have changed the behavior around adding/dropping linux capabilities and added caps no longer take precedence over dropped ones
- Loading branch information