fedora: don't drop the sys_nice capability to support running ctdb
This commit is contained in:
parent
6bfbe0e8d7
commit
d3705133a9
1 changed files with 3 additions and 1 deletions
|
@ -36,7 +36,9 @@ lxc.hook.clone = /usr/share/lxc/hooks/clonehostname
|
||||||
#
|
#
|
||||||
lxc.cap.drop = mac_admin mac_override
|
lxc.cap.drop = mac_admin mac_override
|
||||||
lxc.cap.drop = setfcap
|
lxc.cap.drop = setfcap
|
||||||
lxc.cap.drop = sys_module sys_nice sys_pacct
|
lxc.cap.drop = sys_module sys_pacct
|
||||||
|
# sys_nice: needed to run CTDB
|
||||||
|
#lxc.cap.drop = sys_nice sys_pacct
|
||||||
lxc.cap.drop = sys_rawio sys_time
|
lxc.cap.drop = sys_rawio sys_time
|
||||||
|
|
||||||
# Control Group devices: all denied except those whitelisted
|
# Control Group devices: all denied except those whitelisted
|
||||||
|
|
Loading…
Reference in a new issue