The only privilege NUT needs is access to the USB device nodes. Using a device CGroup rule to allow this is significantly better than disabling all restrictions. Especially since I discovered that `--privileged` implies `--security-opt label=disable`, effectively disabling SELinux confinement of the container. |
||
---|---|---|
.. | ||
nut-server.container | ||
nut.sysusers | ||
ups.conf | ||
upsd.conf | ||
upsd.users |