singularity-capability-drop - Remove capabilities from a user or group (requires root)
Contents
Description
Remove Linux capabilities from a user/group. NOTE: This command requires root
to run.
The capabilities argument must be separated by commas and is not case
sensitive.
To see available capabilities, type "singularity capability avail" or refer to
capabilities manual "man 7 capabilities"
Example
$ sudo singularity capability drop --user nobody AUDIT_READ,CHOWN
$ sudo singularity capability drop --group nobody audit_write
To drop all capabilities for a user:
$ sudo singularity capability drop --user nobody all
History
27-Feb-2025 Auto generated by spf13/cobra
Auto generated by spf13/cobra Feb 2025 singularity(1)
Name
singularity-capability-drop - Remove capabilities from a user or group (requires root)
Options
-g, --group="" manage capabilities for a group
-h, --help[=false] help for drop
-u, --user="" manage capabilities for a user
See Also
singularity-capability(1)Synopsis
singularitycapabilitydrop[dropoptions...]
