🛡️ Security

Linux Capabilities

Fine-grained privileges (such as CAP_NET_ADMIN for network configuration) that split the traditional all-or-nothing root power into separate units a process can hold. Container runtimes and network daemons are often granted individual capabilities that expose kernel attack surface.