capabilities
netrorw
Filled is granted to every invocation, outlined to some and not others — see per-subcommand below; the rest need --cap at the point of use.
default
The syscall filter applied to this tool's entry point.
Tools sharing an image do not share a tier.
dotfiles mapped in
read-only unless noted
env passed through
11 forwarded
ALL_PROXYHTTPS_PROXYHTTP_PROXYNO_PROXYPIP_EXTRA_INDEX_URLPIP_INDEX_URLPIP_NO_INPUTall_proxyhttp_proxyhttps_proxyno_proxy
Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.
PIP_DISABLE_PIP_VERSION_CHECK
per-subcommand
narrower in places
config + ro − netrw
dotfiles ~/.config/pip
Where a tool needs more for one subcommand only, kapsl
scopes it there rather than granting it everywhere.
Where it needs less, kapsl takes it away there too.