AWS::ECS::TaskDefinition KernelCapabilities
The Linux capabilities to add or remove from the default Docker configuration for a container defined in the task definition. For more information about the default capabilities
and the non-default available capabilities, see Runtime privilege and Linux capabilities
Syntax
To declare this entity in your Amazon CloudFormation template, use the following syntax:
Properties
Add
-
The Linux capabilities for the container that have been added to the default configuration provided by Docker. This parameter maps to
CapAdd
in the Create a containersection of the Docker Remote API and the --cap-add
option to docker run. Note
Tasks launched on Amazon Fargate only support adding the
SYS_PTRACE
kernel capability.Valid values:
"ALL" | "AUDIT_CONTROL" | "AUDIT_WRITE" | "BLOCK_SUSPEND" | "CHOWN" | "DAC_OVERRIDE" | "DAC_READ_SEARCH" | "FOWNER" | "FSETID" | "IPC_LOCK" | "IPC_OWNER" | "KILL" | "LEASE" | "LINUX_IMMUTABLE" | "MAC_ADMIN" | "MAC_OVERRIDE" | "MKNOD" | "NET_ADMIN" | "NET_BIND_SERVICE" | "NET_BROADCAST" | "NET_RAW" | "SETFCAP" | "SETGID" | "SETPCAP" | "SETUID" | "SYS_ADMIN" | "SYS_BOOT" | "SYS_CHROOT" | "SYS_MODULE" | "SYS_NICE" | "SYS_PACCT" | "SYS_PTRACE" | "SYS_RAWIO" | "SYS_RESOURCE" | "SYS_TIME" | "SYS_TTY_CONFIG" | "SYSLOG" | "WAKE_ALARM"
Required: No
Type: Array of String
Update requires: Replacement
Drop
-
The Linux capabilities for the container that have been removed from the default configuration provided by Docker. This parameter maps to
CapDrop
in the Create a containersection of the Docker Remote API and the --cap-drop
option to docker run. Valid values:
"ALL" | "AUDIT_CONTROL" | "AUDIT_WRITE" | "BLOCK_SUSPEND" | "CHOWN" | "DAC_OVERRIDE" | "DAC_READ_SEARCH" | "FOWNER" | "FSETID" | "IPC_LOCK" | "IPC_OWNER" | "KILL" | "LEASE" | "LINUX_IMMUTABLE" | "MAC_ADMIN" | "MAC_OVERRIDE" | "MKNOD" | "NET_ADMIN" | "NET_BIND_SERVICE" | "NET_BROADCAST" | "NET_RAW" | "SETFCAP" | "SETGID" | "SETPCAP" | "SETUID" | "SYS_ADMIN" | "SYS_BOOT" | "SYS_CHROOT" | "SYS_MODULE" | "SYS_NICE" | "SYS_PACCT" | "SYS_PTRACE" | "SYS_RAWIO" | "SYS_RESOURCE" | "SYS_TIME" | "SYS_TTY_CONFIG" | "SYSLOG" | "WAKE_ALARM"
Required: No
Type: Array of String
Update requires: Replacement