github.com/khulnasoft-lab/defsec@v1.0.5-0.20230827010352-5e9f46893d95/avd_docs/kubernetes/general/AVD-KSV-0106/docs.md (about) 1 2 Containers must drop ALL capabilities, and are only permitted to add back the NET_BIND_SERVICE capability. 3 4 ### Impact 5 <!-- Add Impact here --> 6 7 <!-- DO NOT CHANGE --> 8 {{ remediationActions }} 9 10 ### Links 11 - https://kubernetes.io/docs/concepts/security/pod-security-standards/#restricted 12 13