{"id":3761,"date":"2025-06-03T13:39:00","date_gmt":"2025-06-03T10:09:00","guid":{"rendered":"https:\/\/parsdev.com/blog\/?p=3761"},"modified":"2025-07-28T08:51:52","modified_gmt":"2025-07-28T05:21:52","slug":"what-is-linux-capabilities","status":"publish","type":"post","link":"https:\/\/parsdev.com/blog\/what-is-linux-capabilities\/","title":{"rendered":"\u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633 (Linux Capabilities) \u062f\u0631 \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631\u0647\u0627 \u0648 \u06a9\u0648\u0628\u0631\u0646\u062a\u06cc\u0632"},"content":{"rendered":"<p>\u0644\u06cc\u0646\u0648\u06a9\u0633 \u0628\u0627 \u0628\u0647\u0631\u0647\u200c\u06af\u06cc\u0631\u06cc \u0627\u0632 \u0648\u06cc\u0698\u06af\u06cc\u200c\u0647\u0627\u06cc\u06cc \u0645\u0627\u0646\u0646\u062f Namespaces\u060c cgroups \u0648 \u0641\u0627\u06cc\u0644\u200c\u0633\u06cc\u0633\u062a\u0645\u200c\u0647\u0627\u06cc \u062a\u0631\u06a9\u06cc\u0628\u06cc\u060c \u0632\u06cc\u0631\u0633\u0627\u062e\u062a \u0627\u0635\u0644\u06cc \u0627\u062c\u0631\u0627\u06cc \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631\u0647\u0627 \u0648 \u06a9\u0648\u0628\u0631\u0646\u062a\u06cc\u0632 \u0631\u0627 \u0641\u0631\u0627\u0647\u0645 \u0645\u06cc\u200c\u06a9\u0646\u062f. \u0627\u06cc\u0646 \u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633 (Linux Capabilities) \u0627\u0645\u06a9\u0627\u0646 \u0627\u06cc\u0632\u0648\u0644\u0647\u200c\u0633\u0627\u0632\u06cc\u060c \u06a9\u0646\u062a\u0631\u0644 \u0645\u0646\u0627\u0628\u0639 \u0648 \u0627\u0645\u0646\u06cc\u062a \u0631\u0627 \u062f\u0631 \u0645\u062d\u06cc\u0637\u200c\u0647\u0627\u06cc \u0627\u0628\u0631\u06cc \u0641\u0631\u0627\u0647\u0645 \u06a9\u0631\u062f\u0647 \u0648 \u0644\u06cc\u0646\u0648\u06a9\u0633 \u0631\u0627 \u0628\u0647 \u067e\u0627\u06cc\u0647\u200c\u0627\u06cc \u0645\u0637\u0645\u0626\u0646 \u0628\u0631\u0627\u06cc \u062a\u0648\u0633\u0639\u0647 \u0648 \u0627\u0633\u062a\u0642\u0631\u0627\u0631 \u0646\u0631\u0645\u200c\u0627\u0641\u0632\u0627\u0631\u0647\u0627\u06cc \u0645\u062f\u0631\u0646 \u062a\u0628\u062f\u06cc\u0644 \u06a9\u0631\u062f\u0647\u200c\u0627\u0646\u062f.<\/p>\n<p><!--more--><\/p>\n<p>\u062f\u0631 \u0627\u06cc\u0646 \u0645\u0637\u0644\u0628\u060c \u06a9\u0645\u06cc \u0639\u0645\u06cc\u0642\u200c\u062a\u0631 \u0628\u0647 \u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633 \u062e\u0648\u0627\u0647\u06cc\u0645 \u067e\u0631\u062f\u0627\u062e\u062a \u062a\u0627 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0645\u062b\u0627\u0644\u200c\u0647\u0627\u06cc \u0639\u0645\u0644\u06cc\u060c \u0627\u0631\u062a\u0628\u0627\u0637 \u0622\u0646\u0647\u0627 \u0628\u0627 \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631\u0647\u0627 \u0648 \u06a9\u0648\u0628\u0631\u0646\u062a\u06cc\u0632 \u0631\u0627 \u062f\u0631\u06a9 \u06a9\u0646\u06cc\u0645.<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_79_2 ez-toc-wrap-center counter-hierarchy ez-toc-counter-rtl ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<span class=\"ez-toc-title\" style=\"cursor:inherit\">\u0622\u0646\u0686\u0647 \u062f\u0631 \u0627\u06cc\u0646 \u0645\u0637\u0644\u0628 \u062e\u0648\u0627\u0647\u06cc\u062f \u062e\u0648\u0627\u0646\u062f<\/span>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #473ba7;color:#473ba7\" xmlns=\"https:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #473ba7;color:#473ba7\" class=\"arrow-unsorted-368013\" xmlns=\"https:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/parsdev.com/blog\/what-is-linux-capabilities\/#%d9%82%d8%a7%d8%a8%d9%84%db%8c%d8%aa%e2%80%8c%d9%87%d8%a7%db%8c_%d9%84%db%8c%d9%86%d9%88%da%a9%d8%b3_linux_capabilities_%da%86%db%8c%d8%b3%d8%aa%d8%9f\" >\u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633 (Linux Capabilities) \u0686\u06cc\u0633\u062a\u061f<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/parsdev.com/blog\/what-is-linux-capabilities\/#%d9%82%d8%a7%d8%a8%d9%84%db%8c%d8%aa%e2%80%8c%d9%87%d8%a7%db%8c_%d9%84%db%8c%d9%86%d9%88%da%a9%d8%b3_%d9%88_%da%a9%d8%a7%d9%86%d8%aa%db%8c%d9%86%d8%b1%d9%87%d8%a7\" >\u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633 \u0648 \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631\u0647\u0627<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/parsdev.com/blog\/what-is-linux-capabilities\/#%da%a9%d9%88%d8%a8%d8%b1%d9%86%d8%aa%db%8c%d8%b2_%d9%88_%d9%82%d8%a7%d8%a8%d9%84%db%8c%d8%aa%e2%80%8c%d9%87%d8%a7%db%8c_%d9%84%db%8c%d9%86%d9%88%da%a9%d8%b3\" >\u06a9\u0648\u0628\u0631\u0646\u062a\u06cc\u0632 \u0648 \u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/parsdev.com/blog\/what-is-linux-capabilities\/#%d8%aa%d8%ad%d9%84%db%8c%d9%84_%d9%82%d8%a7%d8%a8%d9%84%db%8c%d8%aa%e2%80%8c%d9%87%d8%a7_%d8%a8%d8%a7_systemd\" >\u062a\u062d\u0644\u06cc\u0644 \u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627 \u0628\u0627 Systemd<\/a><ul class='ez-toc-list-level-4' ><li class='ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/parsdev.com/blog\/what-is-linux-capabilities\/#%d8%ac%d9%85%d8%b9_%d8%a8%d9%86%d8%af%db%8c\" >\u062c\u0645\u0639 \u0628\u0646\u062f\u06cc<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n<h3><span class=\"ez-toc-section\" id=\"%d9%82%d8%a7%d8%a8%d9%84%db%8c%d8%aa%e2%80%8c%d9%87%d8%a7%db%8c_%d9%84%db%8c%d9%86%d9%88%da%a9%d8%b3_linux_capabilities_%da%86%db%8c%d8%b3%d8%aa%d8%9f\"><\/span>\u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633 (Linux Capabilities) \u0686\u06cc\u0633\u062a\u061f<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>\u062f\u0631 \u0644\u06cc\u0646\u0648\u06a9\u0633 \u0633\u0646\u062a\u06cc\u060c \u06cc\u06a9 \u0641\u0631\u0622\u06cc\u0646\u062f \u06cc\u0627 root (\u06a9\u0627\u0631\u0628\u0631 \u0627\u0631\u0634\u062f) \u0627\u0633\u062a \u06cc\u0627 non-root (\u0645\u062d\u062f\u0648\u062f)\u061b \u0645\u0641\u0647\u0648\u0645\u06cc \u06a9\u0647 \u0647\u0645\u0647 \u0634\u0645\u0627 \u0645\u06cc\u200c\u062f\u0627\u0646\u06cc\u062f.<br \/>\n\u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633 \u062f\u0631 \u06a9\u0631\u0646\u0644 \u06f2.\u06f2 \u0645\u0639\u0631\u0641\u06cc \u0634\u062f. \u0642\u0628\u0644 \u0627\u0632 \u0622\u0646\u060c<\/p>\n<ul>\n<li>\u0641\u0631\u0622\u06cc\u0646\u062f\u0647\u0627 \u06cc\u0627 \u0627\u0645\u062a\u06cc\u0627\u0632\u0627\u062a root \u062f\u0627\u0634\u062a\u0646\u062f (Privileged processes (UID=0): Full root access.)<\/li>\n<li>\u0627\u0645\u062a\u06cc\u0627\u0632\u0627\u062a \u06a9\u0627\u0631\u0628\u0631 \u0645\u0639\u0645\u0648\u0644\u06cc (Non-privileged processes (UID\u2260\u06f0): Limited permissions.)<\/li>\n<\/ul>\n<p>\u0645\u0634\u06a9\u0644 \u0627\u06cc\u0646 \u0631\u0648\u06cc\u06a9\u0631\u062f \u0627\u06cc\u0646 \u0628\u0648\u062f \u06a9\u0647 \u0627\u06af\u0631 \u06cc\u06a9 \u0628\u0631\u0646\u0627\u0645\u0647 \u06a9\u0627\u0631\u0628\u0631 non-root \u0646\u06cc\u0627\u0632 \u0628\u0647 \u0627\u062c\u0631\u0627\u06cc \u06cc\u06a9 \u0639\u0645\u0644\u06cc\u0627\u062a privileged \u062f\u0627\u0634\u062a\u060c \u0628\u0627\u06cc\u062f \u0628\u0627 \u062f\u0633\u062a\u0631\u0633\u06cc \u06a9\u0627\u0645\u0644 root \u0627\u062c\u0631\u0627 \u0645\u06cc\u200c\u0634\u062f. \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0645\u062b\u0627\u0644\u060c \u0627\u062a\u0635\u0627\u0644 \u0628\u0647 \u067e\u0648\u0631\u062a\u200c\u0647\u0627\u06cc \u0632\u06cc\u0631 \u06f1\u06f0\u06f2\u06f4 \u06a9\u0647 \u0646\u06cc\u0627\u0632 \u0628\u0647 \u0627\u0645\u062a\u06cc\u0627\u0632\u0627\u062a root \u062f\u0627\u0631\u0646\u062f.<\/p>\n<p>\u0627\u06af\u0631 \u0645\u06a9\u0627\u0646\u06cc\u0633\u0645\u06cc \u0648\u062c\u0648\u062f \u062f\u0627\u0634\u062a\u0647 \u0628\u0627\u0634\u062f \u06a9\u0647 \u0628\u0647 \u06cc\u06a9 \u06a9\u0627\u0631\u0628\u0631 non-root \u0628\u062a\u0648\u0627\u0646 \u062f\u0633\u062a\u0631\u0633\u06cc privileged \u0628\u0647 \u0622\u0646 \u0639\u0645\u0644\u06cc\u0627\u062a \u0631\u0627 \u0627\u0631\u0627\u0626\u0647 \u062f\u0627\u062f\u060c \u0686\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f\u061f<\/p>\n<p>\u0627\u06cc\u0646 \u0686\u06cc\u0632\u06cc \u0627\u0633\u062a \u06a9\u0647 \u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633 (Linux Capabilities) \u062d\u0644 \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/p>\n<p>\u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633 \u0627\u06cc\u0646 \u0645\u0634\u06a9\u0644 \u0631\u0627 \u0628\u0627 \u062a\u0641\u06a9\u06cc\u06a9 \u0627\u0645\u062a\u06cc\u0627\u0632\u0627\u062a root \u0628\u0647 \u0648\u0627\u062d\u062f\u0647\u0627\u06cc \u062c\u062f\u0627\u06af\u0627\u0646\u0647\u200c\u0627\u06cc \u06a9\u0647 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u0646\u062f \u0628\u0647 \u0635\u0648\u0631\u062a \u062c\u062f\u0627\u06af\u0627\u0646\u0647 \u062f\u0633\u062a\u0631\u0633\u06cc \u062f\u0627\u062f\u0647 \u0634\u0648\u0646\u062f\u060c \u062d\u0644 \u0645\u06cc\u200c\u06a9\u0646\u0646\u062f.<\/p>\n<p>\u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0645\u062b\u0627\u0644\u060c<\/p>\n<ol>\n<li><strong>CAP_NET_BIND_SERVICE<\/strong>: \u0628\u0631\u0627\u06cc \u0627\u0639\u0637\u0627\u06cc \u0645\u062c\u0648\u0632 \u0627\u062a\u0635\u0627\u0644 \u0628\u0647 \u067e\u0648\u0631\u062a\u200c\u0647\u0627\u06cc privileged .<\/li>\n<li><strong>CAP_NET_ADMIN<\/strong>: \u0627\u0645\u06a9\u0627\u0646 \u062a\u063a\u06cc\u06cc\u0631 \u0631\u0627\u0628\u0637\u200c\u0647\u0627\u06cc \u0634\u0628\u06a9\u0647\u060c \u062c\u062f\u0627\u0648\u0644 \u0645\u0633\u06cc\u0631\u06cc\u0627\u0628\u06cc \u0648 \u0633\u0627\u06cc\u0631 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc\u200c\u0647\u0627\u06cc \u0634\u0628\u06a9\u0647 \u0631\u0627 \u0641\u0631\u0627\u0647\u0645 \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/li>\n<li><strong>CAP_SYS_TIM<\/strong>: \u0628\u0631\u0627\u06cc \u062a\u063a\u06cc\u06cc\u0631 \u0633\u0627\u0639\u062a \u0633\u06cc\u0633\u062a\u0645.<\/li>\n<li><strong>CAP_DAC_OVERRIDE<\/strong>: \u06a9\u0646\u062a\u0631\u0644 \u062f\u0633\u062a\u0631\u0633\u06cc \u0627\u062e\u062a\u06cc\u0627\u0631\u06cc (DAC) \u0631\u0627 \u062f\u0648\u0631 \u0645\u06cc\u200c\u0632\u0646\u062f \u0648 \u0628\u0647 \u06cc\u06a9 \u0641\u0631\u0622\u06cc\u0646\u062f \u0627\u062c\u0627\u0632\u0647 \u0645\u06cc\u200c\u062f\u0647\u062f \u062a\u0627 \u0628\u0631\u0631\u0633\u06cc\u200c\u0647\u0627\u06cc \u0645\u062c\u0648\u0632 \u0641\u0627\u06cc\u0644 \u0631\u0627 \u0646\u0627\u062f\u06cc\u062f\u0647 \u0628\u06af\u06cc\u0631\u062f.<\/li>\n<li><strong>CAP_CHOWN<\/strong>: \u0627\u0645\u06a9\u0627\u0646 \u062a\u063a\u06cc\u06cc\u0631 \u0645\u0627\u0644\u06a9\u06cc\u062a \u0641\u0627\u06cc\u0644\u200c\u0647\u0627 \u0631\u0627 \u0641\u0631\u0627\u0647\u0645 \u0645\u06cc\u200c\u06a9\u0646\u062f \u0648 \u0645\u062d\u062f\u0648\u062f\u06cc\u062a\u200c\u0647\u0627\u06cc \u0645\u0639\u0645\u0648\u0644 \u06a9\u0627\u0631\u0628\u0631 \u0631\u0627 \u062f\u0648\u0631 \u0645\u06cc\u200c\u0632\u0646\u062f.<\/li>\n<li><strong>CAP_NET_RAW<\/strong>: \u0627\u0645\u06a9\u0627\u0646 \u0627\u0631\u0633\u0627\u0644 \u0648 \u062f\u0631\u06cc\u0627\u0641\u062a \u0628\u0633\u062a\u0647\u200c\u0647\u0627\u06cc \u062e\u0627\u0645 (\u0645\u062b\u0644\u0627 \u0633\u0627\u062e\u062a \u0628\u0633\u062a\u0647\u200c\u0647\u0627\u06cc \u0634\u0628\u06a9\u0647 \u0633\u0641\u0627\u0631\u0634\u06cc) \u0631\u0627 \u0641\u0631\u0627\u0647\u0645 \u0645\u06cc\u200c\u06a9\u0646\u062f. \u062f\u0631 \u0627\u0628\u0632\u0627\u0631\u0647\u0627\u06cc\u06cc \u0645\u0627\u0646\u0646\u062f ping \u0648 tcpdump \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f.<\/li>\n<\/ol>\n<p>\u0628\u0627 \u0627\u06cc\u0646 \u06a9\u0627\u0631\u060c \u0628\u0647 \u06cc\u06a9 \u06a9\u0627\u0631\u0628\u0631 \u063a\u06cc\u0631 \u0631\u0648\u062a \u0641\u0642\u0637 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646 CAP_NET_BIND_SERVICE \u0627\u0639\u0637\u0627 \u06a9\u0631\u062f \u062a\u0627 \u0628\u0647 \u06cc\u06a9 \u067e\u0648\u0631\u062a privileged\u00a0\u0645\u062a\u0635\u0644 \u0634\u0648\u062f \u0648 \u062f\u0631 \u0639\u06cc\u0646 \u062d\u0627\u0644 \u062a\u0645\u0627\u0645 \u062f\u0633\u062a\u0631\u0633\u06cc\u200c\u0647\u0627\u06cc \u062f\u06cc\u06af\u0631 \u0645\u0631\u0628\u0648\u0637 \u0628\u0647 root \u0631\u0627 \u0645\u0633\u062f\u0648\u062f \u06a9\u0646\u062f.<\/p>\n<p>\u0641\u0642\u0637 \u062f\u0633\u062a\u0648\u0631 \u0632\u06cc\u0631 \u0631\u0627 \u0627\u062c\u0631\u0627 \u06a9\u0646\u06cc\u062f \u062a\u0627 \u062a\u0645\u0627\u0645 \u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u067e\u0634\u062a\u06cc\u0628\u0627\u0646\u06cc \u0634\u062f\u0647 \u062f\u0631 \u0644\u06cc\u0646\u0648\u06a9\u0633 \u0631\u0627 \u0641\u0647\u0631\u0633\u062a \u06a9\u0646\u06cc\u062f.<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\r\nman capabilities\r\n<\/pre>\n<p>\u06f4\u06f7 \u0642\u0627\u0628\u0644\u06cc\u062a \u0645\u062e\u062a\u0644\u0641 \u062f\u0631 \u06a9\u0631\u0646\u0644 \u0644\u06cc\u0646\u0648\u06a9\u0633 \u0627\u0645\u0631\u0648\u0632\u06cc \u0648\u062c\u0648\u062f \u062f\u0627\u0631\u062f (\u0645\u0646 \u0627\u06cc\u0646 \u0631\u0627 \u0631\u0648\u06cc \u06cc\u06a9 \u0633\u0631\u0648\u0631 Ubunty 24 \u0622\u0632\u0645\u0627\u06cc\u0634 \u06a9\u0631\u062f\u0645).<\/p>\n<p style=\"text-align: center\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3862\" src=\"https:\/\/parsdev.com/blog\/wp-content\/uploads\/2025\/06\/linux-capabilities01.png\" alt=\"\u0642\u0627\u0628\u0644\u06cc\u062a\u0647\u0627\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633\" width=\"818\" height=\"399\" srcset=\"https:\/\/parsdev.com/blog\/wp-content\/uploads\/2025\/06\/linux-capabilities01.png 818w, https:\/\/parsdev.com/blog\/wp-content\/uploads\/2025\/06\/linux-capabilities01-226x110.png 226w, https:\/\/parsdev.com/blog\/wp-content\/uploads\/2025\/06\/linux-capabilities01-768x375.png 768w, https:\/\/parsdev.com/blog\/wp-content\/uploads\/2025\/06\/linux-capabilities01-600x293.png 600w, https:\/\/parsdev.com/blog\/wp-content\/uploads\/2025\/06\/linux-capabilities01-200x98.png 200w, https:\/\/parsdev.com/blog\/wp-content\/uploads\/2025\/06\/linux-capabilities01-400x195.png 400w, https:\/\/parsdev.com/blog\/wp-content\/uploads\/2025\/06\/linux-capabilities01-800x390.png 800w\" sizes=\"auto, (max-width: 818px) 100vw, 818px\" \/><\/p>\n<p>\u062d\u0627\u0644\u0627 \u06a9\u0647 \u0628\u0627 \u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633 \u0622\u0634\u0646\u0627 \u0634\u062f\u06cc\u0645\u060c \u0628\u06cc\u0627\u06cc\u06cc\u062f \u0628\u0641\u0647\u0645\u06cc\u0645 \u06a9\u0647 \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631\u0647\u0627 \u0648 \u06a9\u0648\u0628\u0631\u0646\u062a\u06cc\u0632 \u0686\u06af\u0648\u0646\u0647 \u0627\u0632 \u0622\u0646\u0647\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u0646\u062f.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"%d9%82%d8%a7%d8%a8%d9%84%db%8c%d8%aa%e2%80%8c%d9%87%d8%a7%db%8c_%d9%84%db%8c%d9%86%d9%88%da%a9%d8%b3_%d9%88_%da%a9%d8%a7%d9%86%d8%aa%db%8c%d9%86%d8%b1%d9%87%d8%a7\"><\/span>\u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633 \u0648 \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631\u0647\u0627<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>\u0628\u0647 \u0637\u0648\u0631 \u067e\u06cc\u0634\u200c\u0641\u0631\u0636\u060c \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631\u0647\u0627 \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 root \u0627\u062c\u0631\u0627 \u0645\u06cc\u200c\u0634\u0648\u0646\u062f (\u0645\u06af\u0631 \u0627\u06cc\u0646\u06a9\u0647 \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 non-root \u0627\u062c\u0631\u0627 \u06a9\u0646\u06cc\u062f).<br \/>\n\u0627\u0645\u0627 \u0627\u06cc\u0646 \u0628\u062f\u0627\u0646 \u0645\u0639\u0646\u0627 \u0646\u06cc\u0633\u062a \u06a9\u0647 \u0622\u0646\u0647\u0627 \u0627\u0632 \u0627\u0645\u062a\u06cc\u0627\u0632\u0627\u062a \u06a9\u0627\u0645\u0644 root \u062f\u0631 \u0645\u06cc\u0632\u0628\u0627\u0646 \u0628\u0631\u062e\u0648\u0631\u062f\u0627\u0631\u0646\u062f.<\/p>\n<p>\u062f\u0627\u06a9\u0631 \u0648 \u0633\u0627\u06cc\u0631 \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631 \u0631\u0627\u0646\u200c\u062a\u0627\u06cc\u0645\u200c\u0647\u0627 \u0627\u0632 \u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633 \u0628\u0631\u0627\u06cc \u0645\u062d\u062f\u0648\u062f \u06a9\u0631\u062f\u0646 \u0645\u062c\u0648\u0632\u0647\u0627\u06cc \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631 \u0628\u0631\u0627\u06cc \u0627\u0641\u0632\u0627\u06cc\u0634 \u0627\u0645\u0646\u06cc\u062a \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u0646\u062f. \u0627\u06cc\u0646 \u0627\u0645\u0631 \u0645\u062d\u06cc\u0637 \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631 \u0631\u0627 \u0627\u0645\u0646\u200c\u062a\u0631 \u0645\u06cc\u200c\u06a9\u0646\u062f\u060c \u062d\u062a\u06cc \u0627\u06af\u0631 \u0634\u0646\u0627\u0633\u0647 \u06a9\u0627\u0631\u0628\u0631\u06cc (UID 0) \u062f\u0631 \u062f\u0627\u062e\u0644 \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631 \u0648 \u0631\u0648\u06cc \u0645\u06cc\u0632\u0628\u0627\u0646 \u06cc\u06a9\u0633\u0627\u0646 \u0628\u0627\u0642\u06cc \u0628\u0645\u0627\u0646\u062f.<\/p>\n<p>\u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0645\u062b\u0627\u0644\u060c \u062f\u0627\u06a9\u0631 \u0628\u0633\u06cc\u0627\u0631\u06cc \u0627\u0632 \u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627 \u0631\u0627 \u0628\u0647 \u0637\u0648\u0631 \u067e\u06cc\u0634\u200c\u0641\u0631\u0636 \u062d\u0630\u0641 \u0645\u06cc\u200c\u06a9\u0646\u062f \u0648 \u0641\u0642\u0637 \u0627\u0632 \u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0645\u0648\u0631\u062f \u0646\u06cc\u0627\u0632 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u062f.<br \/>\n\u06a9\u062f \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631 \u0627\u06cc\u0646 \u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u067e\u06cc\u0634\u200c\u0641\u0631\u0636 \u0645\u062c\u0627\u0632 \u0631\u0627 \u0646\u0634\u0627\u0646 \u0645\u06cc\u200c\u062f\u0647\u062f.<\/p>\n<p>CRIO \u067e\u06cc\u0634\u200c\u0641\u0631\u0636\u200c\u0647\u0627\u06cc \u0632\u06cc\u0631 \u0631\u0627 \u062f\u0627\u0631\u062f.<\/p>\n<p>\u0628\u06cc\u0627\u06cc\u06cc\u062f \u0628\u0647 \u06cc\u06a9 \u0645\u062b\u0627\u0644 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u062f\u0627\u06a9\u0631 \u0646\u06af\u0627\u0647\u06cc \u0628\u06cc\u0646\u062f\u0627\u0632\u06cc\u0645.<\/p>\n<p>\u0628\u06cc\u0627\u06cc\u06cc\u062f \u0633\u0639\u06cc \u06a9\u0646\u06cc\u0645 \u06cc\u06a9 \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631 BusyBox \u0628\u0631\u0627\u06cc \u0627\u06cc\u062c\u0627\u062f \u06cc\u06a9 \u0631\u0627\u0628\u0637 \u0634\u0628\u06a9\u0647 \u0633\u0627\u062e\u062a\u06af\u06cc \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u0645.<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\r\n\r\n$ docker run --rm -it \\\r\n--name test_no_cap busybox sh\r\n\r\n\/ # ip link add dummy0 type dummy\r\nip: RTNETLINK answers: Operation not permitted\r\n<\/pre>\n<p>&nbsp;<\/p>\n<p style=\"text-align: right\">\u0647\u0645\u0627\u0646\u0637\u0648\u0631 \u06a9\u0647 \u0645\u06cc\u200c\u0628\u06cc\u0646\u06cc\u062f\u060c \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631 \u0641\u0627\u0642\u062f CAP_NET_ADMIN \u0627\u0633\u062a\u060c \u0628\u0646\u0627\u0628\u0631\u0627\u06cc\u0646 \u0646\u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0631\u0627\u0628\u0637\u200c\u0647\u0627\u06cc \u0634\u0628\u06a9\u0647 \u0631\u0627 \u062a\u063a\u06cc\u06cc\u0631 \u062f\u0647\u062f.<\/p>\n<p>\u0627\u0632 &#8211;cap-add \u0628\u0631\u0627\u06cc \u0627\u0639\u0637\u0627\u06cc \u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0627\u0636\u0627\u0641\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633 \u0628\u0647 \u06cc\u06a9 \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f.<br \/>\n\u0627\u06a9\u0646\u0648\u0646\u060c \u0647\u0645\u0627\u0646 \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631 \u0631\u0627 \u0628\u0627 \u0642\u0627\u0628\u0644\u06cc\u062a \u0645\u0648\u0631\u062f \u0646\u06cc\u0627\u0632 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u067e\u0631\u0686\u0645 &#8211;cap-add=NET_ADMIN \u0627\u062c\u0631\u0627 \u06a9\u0646\u06cc\u062f.<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\r\n\r\n$ docker run --rm -it --cap-add=NET_ADMIN \\\r\n--name test_with_cap busybox sh\r\n\r\n\/ # ip link add dummy0 type dummy\r\n\/ # ip link show dummy0\r\n\u06f2: dummy0: &amp;lt;BROADCAST,NOARP&amp;gt; mtu 1500 qdisc noop qlen 1000\r\nlink\/ether 0a:0c:31:af:1e:0b brd ff:ff:ff:ff:ff:ff\r\n<\/pre>\n<p>\u0627\u0632 \u0622\u0646\u062c\u0627\u06cc\u06cc \u06a9\u0647 \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631 \u062f\u0627\u0631\u0627\u06cc CAP_NET_ADMIN \u0627\u0633\u062a\u060c \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0631\u0627\u0628\u0637\u200c\u0647\u0627\u06cc \u0634\u0628\u06a9\u0647 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u062f.<\/p>\n<blockquote>\n<p style=\"text-align: center\"><a href=\"https:\/\/parsdev.com\/vps\" target=\"_blank\" rel=\"noopener\">\u062e\u0631\u06cc\u062f VPS<\/a> \u0644\u06cc\u0646\u0648\u06a9\u0633 \u0628\u0627 \u062f\u0633\u062a\u0631\u0633\u06cc \u06a9\u0627\u0645\u0644 SSH \u0648 \u0645\u0646\u0627\u0628\u0639 \u0627\u062e\u062a\u0635\u0627\u0635\u06cc\u060c \u0645\u0646\u0627\u0633\u0628 \u0628\u0631\u0627\u06cc \u0628\u0631\u0646\u0627\u0645\u0647\u200c\u0646\u0648\u06cc\u0633\u0627\u0646\u060c \u062a\u0648\u0633\u0639\u0647\u200c\u062f\u0647\u0646\u062f\u06af\u0627\u0646 \u0648 \u0645\u062f\u06cc\u0631\u0627\u0646 \u0633\u0627\u06cc\u062a \u062f\u0631 \u067e\u0627\u0631\u0633\u062f\u0648 \u0641\u0631\u0627\u0647\u0645 \u0627\u0633\u062a.<\/p>\n<\/blockquote>\n<h3><span class=\"ez-toc-section\" id=\"%da%a9%d9%88%d8%a8%d8%b1%d9%86%d8%aa%db%8c%d8%b2_%d9%88_%d9%82%d8%a7%d8%a8%d9%84%db%8c%d8%aa%e2%80%8c%d9%87%d8%a7%db%8c_%d9%84%db%8c%d9%86%d9%88%da%a9%d8%b3\"><\/span>\u06a9\u0648\u0628\u0631\u0646\u062a\u06cc\u0632 \u0648 \u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>\u0648\u0642\u062a\u06cc \u0635\u062d\u0628\u062a \u0627\u0632 \u06a9\u0648\u0628\u0631\u0646\u062a\u06cc\u0632 \u0645\u06cc\u200c\u0634\u0648\u062f\u060c \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u062f \u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633 (Linux Capabilities) \u0631\u0627 \u062f\u0631 SecurityContext \u062e\u0648\u062f \u0627\u0636\u0627\u0641\u0647 \u06cc\u0627 \u062d\u0630\u0641 \u06a9\u0646\u06cc\u062f \u062a\u0627 \u0633\u0637\u0648\u062d \u062d\u0645\u0644\u0647 \u06a9\u0627\u0647\u0634 \u06cc\u0627\u0628\u062f.<br \/>\n\u0648\u0642\u062a\u06cc \u06cc\u06a9 pod \u0628\u0627 \u062a\u0635\u0648\u06cc\u0631 BusyBox \u0627\u062c\u0631\u0627 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u062f\u060c \u0628\u0647 \u0637\u0648\u0631 \u067e\u06cc\u0634\u200c\u0641\u0631\u0636 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u062f \u0627\u0632 \u067e\u06cc\u0646\u06af \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f.<\/p>\n<p>\u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0645\u062b\u0627\u0644:<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\r\n$ kubectl run ping-pod \\\r\n--image=busybox --restart=Never \\\r\n-it -- sh -c &quot;ping 8.8.8.8&quot;\r\n\r\n\u06f6\u06f4 bytes from 8.8.8.8: seq=1 ttl=61 time=13.500 ms\r\n\u06f6\u06f4 bytes from 8.8.8.8: seq=2 ttl=61 time=16.598 ms\r\n\u06f6\u06f4 bytes from 8.8.8.8: seq=3 ttl=61 time=16.262 ms\r\n<\/pre>\n<p>\u062d\u0627\u0644\u0627\u060c \u0641\u0631\u0636 \u06a9\u0646\u06cc\u062f \u0646\u0645\u06cc\u200c\u062e\u0648\u0627\u0647\u06cc\u062f \u0628\u0647 BusyBox pod \u0627\u062c\u0627\u0632\u0647 \u062f\u0647\u06cc\u062f \u067e\u06cc\u0646\u06af \u0627\u0646\u062c\u0627\u0645 \u062f\u0647\u062f.<\/p>\n<p>\u062f\u0631 \u0627\u06cc\u0646 \u062d\u0627\u0644\u062a\u060c \u0642\u0627\u0628\u0644\u06cc\u062a NET_RAW \u0631\u0627 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Security Context \u062d\u0630\u0641 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u0645.<\/p>\n<p>\u0642\u0627\u0628\u0644\u06cc\u062a NET_RAW \u0628\u0647 \u06cc\u06a9 \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631 \u0627\u062c\u0627\u0632\u0647 \u0645\u06cc\u200c\u062f\u0647\u062f \u062a\u0627 \u0633\u0648\u06a9\u062a\u200c\u0647\u0627\u06cc \u0634\u0628\u06a9\u0647 \u062e\u0627\u0645 \u0627\u06cc\u062c\u0627\u062f \u0648 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u062f. \u0627\u06cc\u0646 \u0628\u0631\u0627\u06cc \u062f\u0633\u062a\u0648\u0631\u0627\u062a\u06cc \u0645\u0627\u0646\u0646\u062f \u067e\u06cc\u0646\u06af \u0648 \u0628\u0631\u062e\u06cc \u0627\u0632 \u0627\u0628\u0632\u0627\u0631\u0647\u0627\u06cc \u062f\u06cc\u0628\u0627\u06af \u0634\u0628\u06a9\u0647 \u0645\u0648\u0631\u062f \u0646\u06cc\u0627\u0632 \u0627\u0633\u062a.<\/p>\n<p>\u0628\u0627 \u062d\u0630\u0641 NET_RAW\u060c \u0627\u0632 \u0627\u0631\u0633\u0627\u0644 \u0628\u0633\u062a\u0647\u200c\u0647\u0627\u06cc \u062e\u0627\u0645 \u062a\u0648\u0633\u0637 \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631 \u062c\u0644\u0648\u06af\u06cc\u0631\u06cc \u0645\u06cc\u200c\u06a9\u0646\u06cc\u0645.<\/p>\n<p>\u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0645\u062b\u0627\u0644\u060c<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\r\napiVersion: v1\r\nkind: Pod\r\nmetadata:\r\nname: busybox-ping\r\nspec:\r\ncontainers:\r\n- name: busybox\r\nimage: busybox:latest\r\ncommand: &#x5B;&quot;sleep&quot;, &quot;3600&quot;]\r\nsecurityContext:\r\ncapabilities:\r\ndrop:\r\n- NET_RAW\r\n<\/pre>\n<p>\u0627\u06af\u0631 \u0627\u06cc\u0646 pod \u0631\u0627 \u0645\u0633\u062a\u0642\u0631 \u06a9\u0646\u06cc\u062f \u0648 \u067e\u06cc\u0646\u06af \u0631\u0627 \u0627\u0645\u062a\u062d\u0627\u0646 \u06a9\u0646\u06cc\u062f\u060c \u062e\u0637\u0627\u06cc \u0632\u06cc\u0631 \u0631\u0627 \u062f\u0631\u06cc\u0627\u0641\u062a \u062e\u0648\u0627\u0647\u06cc\u062f \u06a9\u0631\u062f.<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\r\n$ kubectl exec -it busybox-secure -- ping 8.8.8.8\r\n\r\nPING 8.8.8.8 (8.8.8.8): 56 data bytes\r\nping: permission denied (are you root?)\r\ncommand terminated with exit code 1\r\n<\/pre>\n<h3><span class=\"ez-toc-section\" id=\"%d8%aa%d8%ad%d9%84%db%8c%d9%84_%d9%82%d8%a7%d8%a8%d9%84%db%8c%d8%aa%e2%80%8c%d9%87%d8%a7_%d8%a8%d8%a7_systemd\"><\/span>\u062a\u062d\u0644\u06cc\u0644 \u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627 \u0628\u0627 Systemd<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>\u062f\u0631 \u0633\u06cc\u0633\u062a\u0645\u200c\u0647\u0627\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633\u060c \u062f\u0633\u062a\u0648\u0631 systemd-analyze security \u0628\u0631\u0627\u06cc \u0627\u0631\u0632\u06cc\u0627\u0628\u06cc \u0627\u0645\u0646\u06cc\u062a \u0633\u0631\u0648\u06cc\u0633\u200c\u0647\u0627\u06cc systemd \u0628\u0627 \u062a\u062c\u0632\u06cc\u0647 \u0648 \u062a\u062d\u0644\u06cc\u0644 sandboxing \u0648 \u0648\u06cc\u0698\u06af\u06cc\u200c\u0647\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a\u06cc \u0622\u0646\u0647\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f.<\/p>\n<p>\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u0646\u062d\u0648\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u06cc\u06a9 \u0633\u0631\u0648\u06cc\u0633 \u0631\u0627 \u0627\u0632 \u0646\u0638\u0631 \u0645\u062d\u062f\u0648\u062f\u06cc\u062a\u200c\u0647\u0627\u06cc \u0642\u0627\u0628\u0644\u06cc\u062a \u0628\u0631\u0631\u0633\u06cc \u0645\u06cc\u200c\u06a9\u0646\u062f. (\u0645\u062b\u0644\u0627 CAP_NET_ADMIN\u060c CAP_DAC_OVERRIDE) \u0648 \u0645\u0648\u0627\u0631\u062f \u062f\u06cc\u06af\u0631.<\/p>\n<p>\u062f\u0631 \u0627\u06cc\u0646\u062c\u0627 \u0646\u0645\u0648\u0646\u0647\u200c\u0627\u06cc \u0627\u0632 \u062e\u0631\u0648\u062c\u06cc \u062f\u0633\u062a\u0648\u0631 systemd-analyze security \u0622\u0648\u0631\u062f\u0647 \u0634\u062f\u0647 \u0627\u0633\u062a.<\/p>\n<p>&nbsp;<\/p>\n<p>\u0634\u0645\u0627 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u062f \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0646\u0627\u0645 \u0648\u0627\u062d\u062f\u060c \u06cc\u06a9 \u0633\u0631\u0648\u06cc\u0633 \u062e\u0627\u0635 \u0631\u0627 \u0628\u06cc\u0634\u062a\u0631 \u062a\u062c\u0632\u06cc\u0647 \u0648 \u062a\u062d\u0644\u06cc\u0644 \u06a9\u0646\u06cc\u062f.<\/p>\n<p>\u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0645\u062b\u0627\u0644\u060c<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\r\nsystemd-analyze security apache2.service\r\n<\/pre>\n<h4><span class=\"ez-toc-section\" id=\"%d8%ac%d9%85%d8%b9_%d8%a8%d9%86%d8%af%db%8c\"><\/span>\u062c\u0645\u0639 \u0628\u0646\u062f\u06cc<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>\u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0644\u06cc\u0646\u0648\u06a9\u0633 (Linux Capabilities) \u0628\u0627 \u0641\u0631\u0627\u0647\u0645 \u06a9\u0631\u062f\u0646 \u0627\u0645\u06a9\u0627\u0646 \u06a9\u0646\u062a\u0631\u0644 \u062f\u0642\u06cc\u0642 \u0628\u0631 \u0631\u0648\u06cc \u06a9\u0627\u0631\u0647\u0627\u06cc\u06cc \u06a9\u0647 \u0641\u0631\u0622\u06cc\u0646\u062f\u0647\u0627 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u0646\u062f \u0627\u0646\u062c\u0627\u0645 \u062f\u0647\u0646\u062f\u060c \u0646\u0642\u0634 \u0645\u0647\u0645\u06cc \u062f\u0631 \u0627\u062c\u0631\u0627\u06cc \u0627\u0635\u0644 \u062d\u062f\u0627\u0642\u0644 \u0627\u0645\u062a\u06cc\u0627\u0632 (principle of least privilege) \u062f\u0627\u0631\u0646\u062f.<br \/>\n\u0628\u0631\u0627\u06cc \u0645\u0647\u0646\u062f\u0633\u0627\u0646 DevOps\u060c \u067e\u06cc\u0634\u06af\u06cc\u0631\u0627\u0646\u0647 \u0628\u0648\u062f\u0646 \u062f\u0631 \u0645\u0648\u0631\u062f \u0627\u06cc\u0646 \u0628\u0647\u062a\u0631\u06cc\u0646 \u0634\u06cc\u0648\u0647\u200c\u0647\u0627 \u0645\u0647\u0645 \u0627\u0633\u062a. \u0627\u0645\u0646\u06cc\u062a \u0646\u0628\u0627\u06cc\u062f \u06cc\u06a9 \u0627\u0645\u0631 \u0641\u0631\u0639\u06cc \u0628\u0627\u0634\u062f\u061b \u0628\u0627 \u0627\u0646\u062c\u0627\u0645 \u0627\u0642\u062f\u0627\u0645\u0627\u062a \u0627\u0645\u0646\u06cc\u062a\u06cc \u06a9\u0648\u0686\u06a9 \u0627\u0645\u0627 \u0647\u0648\u0634\u0645\u0646\u062f\u0627\u0646\u0647 \u062f\u0631 \u0647\u0631 \u06a9\u062c\u0627 \u06a9\u0647 \u0644\u0627\u0632\u0645 \u0628\u0627\u0634\u062f\u060c \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u062f \u0627\u0632 \u063a\u0627\u0641\u0644\u06af\u06cc\u0631\u06cc\u200c\u0647\u0627\u06cc \u0644\u062d\u0638\u0647 \u0622\u062e\u0631\u06cc \u062c\u0644\u0648\u06af\u06cc\u0631\u06cc \u06a9\u0646\u06cc\u062f \u0648 \u0632\u06cc\u0631\u0633\u0627\u062e\u062a \u062e\u0648\u062f \u0631\u0627 \u0627\u0632 \u0647\u0645\u0627\u0646 \u0627\u0628\u062a\u062f\u0627 \u0627\u06cc\u0645\u0646 \u0646\u06af\u0647 \u062f\u0627\u0631\u06cc\u062f.<\/p>\n","protected":false},"excerpt":{"rendered":"\u0644\u06cc\u0646\u0648\u06a9\u0633 \u0628\u0627 \u0628\u0647\u0631\u0647\u200c\u06af\u06cc\u0631\u06cc \u0627\u0632 \u0648\u06cc\u0698\u06af\u06cc\u200c\u0647\u0627\u06cc\u06cc \u0645\u0627\u0646\u0646\u062f Namespaces\u060c cgroups \u0648 \u0641\u0627\u06cc\u0644\u200c\u0633\u06cc\u0633\u062a\u0645\u200c\u0647\u0627\u06cc \u062a\u0631\u06a9\u06cc\u0628\u06cc\u060c \u0632\u06cc\u0631\u0633\u0627\u062e\u062a \u0627\u0635\u0644\u06cc \u0627\u062c\u0631\u0627\u06cc \u06a9\u0627\u0646\u062a\u06cc\u0646\u0631\u0647\u0627 \u0648 \u06a9\u0648\u0628\u0631\u0646\u062a\u06cc\u0632 \u0631\u0627&hellip;","protected":false},"author":1,"featured_media":3860,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"csco_singular_sidebar":"","csco_page_header_type":"","csco_page_load_nextpost":"","footnotes":""},"categories":[8,3],"tags":[],"class_list":{"0":"post-3761","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-server","8":"category-linux","9":"cs-entry"},"_links":{"self":[{"href":"https:\/\/parsdev.com/blog\/wp-json\/wp\/v2\/posts\/3761","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/parsdev.com/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/parsdev.com/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/parsdev.com/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/parsdev.com/blog\/wp-json\/wp\/v2\/comments?post=3761"}],"version-history":[{"count":12,"href":"https:\/\/parsdev.com/blog\/wp-json\/wp\/v2\/posts\/3761\/revisions"}],"predecessor-version":[{"id":4570,"href":"https:\/\/parsdev.com/blog\/wp-json\/wp\/v2\/posts\/3761\/revisions\/4570"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/parsdev.com/blog\/wp-json\/wp\/v2\/media\/3860"}],"wp:attachment":[{"href":"https:\/\/parsdev.com/blog\/wp-json\/wp\/v2\/media?parent=3761"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/parsdev.com/blog\/wp-json\/wp\/v2\/categories?post=3761"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/parsdev.com/blog\/wp-json\/wp\/v2\/tags?post=3761"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}