aboutsummaryrefslogtreecommitdiff
path: root/docs/source/markdown/options/privileged.md
blob: 8d9746d6b12028885ce91e7c979b1dfa473cef01 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
#### **--privileged**

Give extended privileges to this container. The default is **false**.

By default, Podman containers are unprivileged (**=false**) and cannot, for
example, modify parts of the operating system. This is because by default a
container is only allowed limited access to devices. A "privileged" container
is given the same access to devices as the user launching the container.

A privileged container turns off the security features that isolate the
container from the host. Dropped Capabilities, limited devices, read-only mount
points, Apparmor/SELinux separation, and Seccomp filters are all disabled.

Rootless containers cannot have more privileges than the account that launched them.