@Stability(value=Stable)
public static interface CfnTaskDefinition.KernelCapabilitiesProperty
extends software.amazon.jsii.JsiiSerializable
For more information on the default capabilities and the non-default available capabilities, see Runtime privilege and Linux capabilities in the Docker run reference . For more detailed information on these Linux capabilities, see the capabilities(7) Linux manual page.
Example:
// The code below shows an example of how to instantiate this type.
// The values are placeholders you should change.
import software.amazon.awscdk.services.ecs.*;
KernelCapabilitiesProperty kernelCapabilitiesProperty = KernelCapabilitiesProperty.builder()
.add(List.of("add"))
.drop(List.of("drop"))
.build();
| Modifier and Type | Interface and Description |
|---|---|
static class |
CfnTaskDefinition.KernelCapabilitiesProperty.Builder
A builder for
CfnTaskDefinition.KernelCapabilitiesProperty |
static class |
CfnTaskDefinition.KernelCapabilitiesProperty.Jsii$Proxy
An implementation for
CfnTaskDefinition.KernelCapabilitiesProperty |
| Modifier and Type | Method and Description |
|---|---|
static CfnTaskDefinition.KernelCapabilitiesProperty.Builder |
builder() |
default List<String> |
getAdd()
The Linux capabilities for the container that have been added to the default configuration provided by Docker.
|
default List<String> |
getDrop()
The Linux capabilities for the container that have been removed from the default configuration provided by Docker.
|
@Stability(value=Stable) @Nullable default List<String> getAdd()
This parameter maps to CapAdd in the Create a container section of the Docker Remote API and the --cap-add option to docker run .
Tasks launched on AWS Fargate only support adding the
SYS_PTRACEkernel capability.
Valid values: "ALL" | "AUDIT_CONTROL" | "AUDIT_WRITE" | "BLOCK_SUSPEND" | "CHOWN" | "DAC_OVERRIDE" | "DAC_READ_SEARCH" | "FOWNER" | "FSETID" | "IPC_LOCK" | "IPC_OWNER" | "KILL" | "LEASE" | "LINUX_IMMUTABLE" | "MAC_ADMIN" | "MAC_OVERRIDE" | "MKNOD" | "NET_ADMIN" | "NET_BIND_SERVICE" | "NET_BROADCAST" | "NET_RAW" | "SETFCAP" | "SETGID" | "SETPCAP" | "SETUID" | "SYS_ADMIN" | "SYS_BOOT" | "SYS_CHROOT" | "SYS_MODULE" | "SYS_NICE" | "SYS_PACCT" | "SYS_PTRACE" | "SYS_RAWIO" | "SYS_RESOURCE" | "SYS_TIME" | "SYS_TTY_CONFIG" | "SYSLOG" | "WAKE_ALARM"
@Stability(value=Stable) @Nullable default List<String> getDrop()
This parameter maps to CapDrop in the Create a container section of the Docker Remote API and the --cap-drop option to docker run .
Valid values: "ALL" | "AUDIT_CONTROL" | "AUDIT_WRITE" | "BLOCK_SUSPEND" | "CHOWN" | "DAC_OVERRIDE" | "DAC_READ_SEARCH" | "FOWNER" | "FSETID" | "IPC_LOCK" | "IPC_OWNER" | "KILL" | "LEASE" | "LINUX_IMMUTABLE" | "MAC_ADMIN" | "MAC_OVERRIDE" | "MKNOD" | "NET_ADMIN" | "NET_BIND_SERVICE" | "NET_BROADCAST" | "NET_RAW" | "SETFCAP" | "SETGID" | "SETPCAP" | "SETUID" | "SYS_ADMIN" | "SYS_BOOT" | "SYS_CHROOT" | "SYS_MODULE" | "SYS_NICE" | "SYS_PACCT" | "SYS_PTRACE" | "SYS_RAWIO" | "SYS_RESOURCE" | "SYS_TIME" | "SYS_TTY_CONFIG" | "SYSLOG" | "WAKE_ALARM"
@Stability(value=Stable) static CfnTaskDefinition.KernelCapabilitiesProperty.Builder builder()
Copyright © 2022. All rights reserved.