Root-Owned Runtime Files and Non-Root Containers Need an Explicit Contract
Dropping container privileges is only safe when mounts, ownership and startup scripts are designed for the new identity.
Dropping container privileges is only safe when mounts, ownership and startup scripts are designed for the new identity.