Docker Compose Tip #89: What cap_drop actually takes away from root
Run this from a container whose process is uid 0: services: hardened: image: alpine cap_drop: - ALL command: sh -c "touch /tmp/f && chown 2000:2000 /tmp/f && echo OK" docker compose run --rm hardened chown: /tmp/f: Operation not permitted Tip #29 listed which cap_add values pair with which workload. This is the part worth sitting with: cap_drop: ALL just took a privilege away from uid 0, not from some non-root user it was supposedly protecting against. ...