Files
ols-nos/rules
Mai Bui ff7c993060 [docker-p4rt limit privileged flag for p4rt container (#17796)
### Why I did it
HLD implementation: Container Hardening (https://github.com/sonic-net/SONiC/pull/1364)
##### Work item tracking
- Microsoft ADO **(number only)**: 14807420
#### How I did it
Reduce linux capabilities in privileged flag

#### How to verify it
Check container's settings: Privileged is false and container only has default Linux caps, does not have extended caps.
```
admin@vlab-01:~$ docker inspect p4rt | grep Privi
            "Privileged": false,


admin@vlab-01:~$ docker exec -it p4rt bash
root@vlab-01:/# capsh --print
Current: cap_chown,cap_dac_override,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_net_bind_service,cap_net_raw,cap_sys_chroot,cap_mknod,cap_audit_write,cap_setfcap=ep
```
2024-01-23 11:02:54 -08:00
..
2023-04-02 14:02:33 -07:00
2023-11-21 18:53:15 -08:00
2022-05-24 14:47:09 -07:00
2023-11-21 18:53:15 -08:00
2021-11-10 15:27:22 -08:00
2016-12-08 09:24:48 -08:00
2023-08-11 09:00:46 -07:00
2021-11-10 15:27:22 -08:00
2021-11-10 15:27:22 -08:00
2021-11-10 15:27:22 -08:00
2021-11-10 15:27:22 -08:00
2021-11-10 15:27:22 -08:00
2023-08-11 09:00:46 -07:00