$ grep Cap /proc/$container_pid/status
setcap
getcap
CAP_SYS_PTRACE
/proc/sys/kernel/yama/ptrace_scope
docker run --cap-add
Index