metadata.yaml 1.3 KB

123456789101112131415161718192021222324252627282930313233343536373839
  1. runAsContext:
  2. - userName: cool
  3. groupName: cool
  4. gid: 104
  5. uid: 106
  6. description: Collabora runs as non-root user.
  7. - userName: root
  8. groupName: root
  9. gid: 0
  10. uid: 0
  11. description: Nginx runs as root user.
  12. capabilities:
  13. - name: CHOWN
  14. description: Collabora and Nginx are able to chown files.
  15. - name: FOWNER
  16. description: Collabora and Nginx are able to bypass permission checks for it's sub-processes.
  17. - name: SYS_CHROOT
  18. description: Collabora and Nginx are able to use chroot.
  19. - name: MKNOD
  20. description: Collabora and Nginx are able to create device nodes.
  21. - name: DAC_OVERRIDE
  22. description: Nginx is able to bypass permission checks.
  23. - name: SETGID
  24. description: Nginx is able to set group ID for it's sub-processes.
  25. - name: SETUID
  26. description: Nginx is able to set user ID for it's sub-processes.
  27. - name: FSETID
  28. description: Nginx is able to set file capabilities.
  29. - name: KILL
  30. description: Nginx is able to kill processes.
  31. - name: SETPCAP
  32. description: Nginx is able to set process capabilities.
  33. - name: NET_BIND_SERVICE
  34. description: Nginx is able to bind to privileged ports.
  35. - name: NET_RAW
  36. description: Nginx is able to use raw sockets.
  37. - name: AUDIT_WRITE
  38. description: Nginx is able to write to audit log.
  39. hostMounts: []