diff --git a/docs/containers.conf.5.md b/docs/containers.conf.5.md index 530f7a711..6df649e62 100644 --- a/docs/containers.conf.5.md +++ b/docs/containers.conf.5.md @@ -102,9 +102,9 @@ default_capabilities = [ ``` Note, by default container engines using containers.conf, run with less -capabilities then Docker. Docker runs additionally with "AUDIT_WRITE", "MKNOD", +capabilities than Docker. Docker runs additionally with "AUDIT_WRITE", "MKNOD", "NET_RAW", "CHROOT". If you need to add one of these capabilities for a -particular container, you can use the --cap-add option. +particular container, you can use the --cap-add option or edit your system's containers.conf. **default_sysctls**=[]