summaryrefslogtreecommitdiff
path: root/docs/source/markdown/podman-exec.1.md
diff options
context:
space:
mode:
authorMark Stosberg <mark@rideamigos.com>2020-01-10 22:02:08 -0500
committerMark Stosberg <mark@rideamigos.com>2020-01-12 23:28:12 -0500
commit9c8e2822cb95679106a26fd4eb92f8323148a619 (patch)
tree76df9806af8fdb5912e6461ec863e3271f755330 /docs/source/markdown/podman-exec.1.md
parent0e9c208d3f9fc6f160f7e7746119ddf99ae6f220 (diff)
downloadpodman-9c8e2822cb95679106a26fd4eb92f8323148a619.tar.gz
podman-9c8e2822cb95679106a26fd4eb92f8323148a619.tar.bz2
podman-9c8e2822cb95679106a26fd4eb92f8323148a619.zip
docs: --privileged docs completeness, consistency
As discussed in https://github.com/containers/libpod/issues/4840 Signed-off-by: Mark Stosberg <mark@rideamigos.com>
Diffstat (limited to 'docs/source/markdown/podman-exec.1.md')
-rw-r--r--docs/source/markdown/podman-exec.1.md14
1 files changed, 13 insertions, 1 deletions
diff --git a/docs/source/markdown/podman-exec.1.md b/docs/source/markdown/podman-exec.1.md
index d46427c91..fc67211d1 100644
--- a/docs/source/markdown/podman-exec.1.md
+++ b/docs/source/markdown/podman-exec.1.md
@@ -43,7 +43,19 @@ Pass down to the process N additional file descriptors (in addition to 0, 1, 2).
**--privileged**
-Give the process extended Linux capabilities when running the command in container.
+Give extended privileges to this container. The default is *false*.
+
+By default, Podman containers are
+"unprivileged" and cannot, for example, modify parts of the operating system.
+This is because by default a container is only allowed limited access to devices.
+A "privileged" container is given the same access to devices as the user launching the container.
+
+A privileged container turns off the security features that isolate the
+container from the host. Dropped Capabilities, limited devices, read/only mount
+points, Apparmor/SELinux separation, and Seccomp filters are all disabled.
+
+Rootless containers cannot have more privileges than the account that launched them.
+
**--tty**, **-t**