Open
Description
We currently start the jailer
as the superuser (i.e. using sudo
), and rely on the fact the process will deprivilege itself before exec
-ing into Firecracker. It would be interesting to know if we can run the jailer
using a more restricted set of capabilities instead of full superuser mode.