From 12f1e22e3f095a786d1b04cd298433bc6a643352 Mon Sep 17 00:00:00 2001 From: Tommy Date: Sun, 25 Sep 2022 16:10:31 -0400 Subject: [PATCH] Fix capabilities Signed-off-by: Tommy --- docker-compose.yml | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/docker-compose.yml b/docker-compose.yml index ab42d52..61ca33e 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -18,6 +18,8 @@ services: cap_add: - CAP_NET_BIND_SERVICE - CHOWN + - SETUID + - SETGID nginx-relay: build: ./nginx-relay/ restart: unless-stopped @@ -28,6 +30,9 @@ services: - no-new-privileges:true cap_drop: - ALL + cap_add: + - SETUID + - SETGID certbot: image: certbot/certbot restart: unless-stopped @@ -39,5 +44,3 @@ services: - no-new-privileges:true cap_drop: - ALL - cap_add: - - CAP_NET_BIND_SERVICE