"Capabilities are鈥攁t least in theory鈥攁 nice idea: divide the privileges of root into small pieces so that a process can be granted just enough power to perform specific privileged tasks. "
"The key point from the beginning of this article is small pieces, and it's here that the Linux capabilities implementation has gone astray."
"Capabilities are鈥攁t least in theory鈥攁 nice idea: divide the privileges of root into small pieces so that a process can be granted just enough power to perform specific privileged tasks. "
"The key point from the beginning of this article is small pieces, and it's here that the Linux capabilities implementation has gone astray."
"All that hard work paid off. With the help of a video, the album went like hotcakes! They sold a quarter million copies!"
"Here is the math that will explain just how fucked they are:"
"All that hard work paid off. With the help of a video, the album went like hotcakes! They sold a quarter million copies!"
"Here is the math that will explain just how fucked they are:"
systemd has a socket proxy 
found a good blog post explaining how to use systemd socket units and systemd socket proxy to start a podman quadlet container on first connection and stop after some idle period
found a good blog post explaining how to use systemd socket units and systemd socket proxy to start a podman quadlet container on first connection and stop after some idle period