Docker has several capabilities enabled by default and some not. It seems natural to follow this distinction in --cap-add and --cap-drop. Signed-off-by: Harald Albers <github@albersweb.de> Upstream-commit: 36d8b66cb9aab26bd2552083b786b7a11272d9b9 Component: engine