Docker: Sys_Admin Cap Reason? #988
Replies: 3 comments 2 replies
-
I'd like to know this too. I'm curious to know what part of the bot requires (almost) root access to the host. |
Beta Was this translation helpful? Give feedback.
-
I haven't ran this in docker but I suspect it for those mac users who want to receive external calls to play sounds and open browsers. |
Beta Was this translation helpful? Give feedback.
-
I agree! I would really not like to have this run as privileged mode. Unfortunately, Chromium doesn't like running without these priveledges. Take a look here.
If you find anything in there and do some testing, I'd love to not have this requirement! Otherwise, it is a side effect with running in Docker. |
Beta Was this translation helpful? Give feedback.
-
Description
Hey,
Can I run the docker container without the SYS_ADMIN cap? I usually like to run my containers in unprivileged mode, since it otherwise defeats the whole purpose of sandboxing with containerization.
If not, I suspect there must be a specific reason for the privileged mode. Sorry if I'm missing something obvious. It's late around here...
Thanks
Beta Was this translation helpful? Give feedback.
All reactions