capabilities: ["NET_ADMIN"] on a container reaches the runtime as --cap-add, is part of the container's spec (a change recreates it), and a name that is not a capability's is refused; a privileged container stays undeclarable. For the packet filter seat's holder, whose runtime changes the machine's filter (ADR 0169). Full suite green. Merge and roll first: an older host refuses a declaration carrying the field, and the nftables module will carry it.
`capabilities: ["NET_ADMIN"]` on a container reaches the runtime as `--cap-add`, is part of the container's spec (a change recreates it), and a name that is not a capability's is refused; a privileged container stays undeclarable. For the packet filter seat's holder, whose runtime changes the machine's filter (ADR 0169). Full suite green. **Merge and roll first**: an older host refuses a declaration carrying the field, and the nftables module will carry it.
Exactly the names declared reach the runtime, named in the spec so a change
recreates the container; a name that is not a capability's is refused and a
privileged container stays undeclarable. For a seat holder whose runtime
changes the machine's packet filter.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
capabilities: ["NET_ADMIN"]on a container reaches the runtime as--cap-add, is part of the container's spec (a change recreates it), and a name that is not a capability's is refused; a privileged container stays undeclarable. For the packet filter seat's holder, whose runtime changes the machine's filter (ADR 0169). Full suite green. Merge and roll first: an older host refuses a declaration carrying the field, and the nftables module will carry it.