capabilities
netrw
Filled is granted to every invocation; the rest need --cap at the point of use.
default
The syscall filter applied to this tool's entry point.
Tools sharing an image do not share a tier.
dotfiles mapped in
read-only unless noted
- ~/.config/pypoetry · writable
- ~/.cache/pypoetry · writable
- ~/.local/share/pypoetry · writable
env passed through
28 forwarded
CURL_CA_BUNDLEHTTPS_PROXYHTTP_PROXYNO_PROXYPOETRY_HTTP_BASIC_*POETRY_INSTALLER_BUILD_CONFIG_SETTINGS_*POETRY_INSTALLER_MAX_WORKERSPOETRY_INSTALLER_NO_BINARYPOETRY_INSTALLER_ONLY_BINARYPOETRY_INSTALLER_PARALLELPOETRY_INSTALLER_RE_RESOLVEPOETRY_KEYRING_ENABLEDPOETRY_NO_INTERACTIONPOETRY_PYPI_TOKEN_*POETRY_REPOSITORIES_*POETRY_REQUESTS_MAX_RETRIESPOETRY_SOLVER_LAZY_WHEELPOETRY_SOLVER_MIN_RELEASE_AGEPOETRY_SYSTEM_GIT_CLIENTPOETRY_VIRTUALENVS_CREATEPOETRY_VIRTUALENVS_IN_PROJECTPOETRY_VIRTUALENVS_OPTIONS_ALWAYS_COPYPOETRY_VIRTUALENVS_OPTIONS_NO_PIPPOETRY_VIRTUALENVS_OPTIONS_SYSTEM_SITE_PACKAGESREQUESTS_CA_BUNDLEhttp_proxyhttps_proxyno_proxy
Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.
per-subcommand
no overrides
Every invocation gets the same boundary. Where a tool
needs more for one subcommand only, kapsl scopes it there
rather than granting it everywhere.