Explorar o código

Allow ping within a container. Issue #91

Allow the net_raw capability
Guillaume J. Charmes %!s(int64=12) %!d(string=hai) anos
pai
achega
9ff6dd767a
Modificáronse 1 ficheiros con 1 adicións e 1 borrados
  1. 1 1
      lxc_template.go

+ 1 - 1
lxc_template.go

@@ -82,7 +82,7 @@ lxc.mount.entry = /etc/resolv.conf {{$ROOTFS}}/etc/resolv.conf none bind,ro 0 0
 
 
 # drop linux capabilities (apply mainly to the user root in the container)
-lxc.cap.drop = audit_control audit_write mac_admin mac_override mknod net_raw setfcap setpcap sys_admin sys_boot sys_module sys_nice sys_pacct sys_rawio sys_resource sys_time sys_tty_config
+lxc.cap.drop = audit_control audit_write mac_admin mac_override mknod setfcap setpcap sys_admin sys_boot sys_module sys_nice sys_pacct sys_rawio sys_resource sys_time sys_tty_config
 
 # limits
 {{if .Config.Memory}}