-
Notifications
You must be signed in to change notification settings - Fork 12
Open
Description
Considering that --privileged effectively gives the programs inside the container root privileges on the host(by means of access to the disk and memory devices, even without /dev), are there ways to avoid that? There seem to be ways to allow only a subset of devices to be passed through(gpus, ttys).
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels