A container may declare the capabilities it is granted (hq ADR 0169) #68

Merged
mesh-admin merged 1 commits from feat/the-firewall-seat-serves-its-verbs into main 2026-10-02 11:28:35 +00:00
Contributor

capabilities: ["NET_ADMIN"] on a container reaches the runtime as --cap-add, is part of the container's spec (a change recreates it), and a name that is not a capability's is refused; a privileged container stays undeclarable. For the packet filter seat's holder, whose runtime changes the machine's filter (ADR 0169). Full suite green. Merge and roll first: an older host refuses a declaration carrying the field, and the nftables module will carry it.

`capabilities: ["NET_ADMIN"]` on a container reaches the runtime as `--cap-add`, is part of the container's spec (a change recreates it), and a name that is not a capability's is refused; a privileged container stays undeclarable. For the packet filter seat's holder, whose runtime changes the machine's filter (ADR 0169). Full suite green. **Merge and roll first**: an older host refuses a declaration carrying the field, and the nftables module will carry it.
mesh-admin added 1 commit 2026-10-02 11:28:10 +00:00
Exactly the names declared reach the runtime, named in the spec so a change
recreates the container; a name that is not a capability's is refused and a
privileged container stays undeclarable. For a seat holder whose runtime
changes the machine's packet filter.
mesh-admin merged commit d3861f82d4 into main 2026-10-02 11:28:35 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-host#68