Skip to content
Snippets Groups Projects
Commit 21ee6c22 authored by kaiyou's avatar kaiyou
Browse files

Add missing capabilities for Cilium BPF

parent 25dd14bc
No related branches found
No related tags found
No related merge requests found
...@@ -29,9 +29,9 @@ func main() { ...@@ -29,9 +29,9 @@ func main() {
// mount with very simple very formatted arguments in that order: // mount with very simple very formatted arguments in that order:
// mount -t tmpfs -o size=1234 /src /dst // mount -t tmpfs -o size=1234 /src /dst
err = unix.Mount(os.Args[5], os.Args[6], os.Args[2], 0, os.Args[4]) err = unix.Mount(os.Args[5], os.Args[6], os.Args[2], 0, os.Args[4])
} else if bin == "umount" { } else if bin == "umount" {
// Same for umount // Same for umount
err = unix.Unmount(os.Args[1], 0) err = unix.Unmount(os.Args[1], 0)
} else if bin == "containerd" || (len(os.Args) > 1 && os.Args[1] == "publish") { } else if bin == "containerd" || (len(os.Args) > 1 && os.Args[1] == "publish") {
// Containerd is also available under hepto name, guess based on // Containerd is also available under hepto name, guess based on
// call arguments // call arguments
......
...@@ -37,7 +37,9 @@ var additionalCapabilities = []string{ ...@@ -37,7 +37,9 @@ var additionalCapabilities = []string{
"CAP_MKNOD", "CAP_MKNOD",
"CAP_AUDIT_WRITE", "CAP_AUDIT_WRITE",
"CAP_SETFCAP", "CAP_SETFCAP",
"CAP_FSETID", // Required for some services including Cilium
"CAP_IPC_LOCK",
"CAP_SYS_MODULE",
} }
// Required devices for kubernetes // Required devices for kubernetes
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment