03:05
2026-06-26
dev.to
ai-agents
When --cap-drop ALL Broke the Gate Socket
A developer at AGP discovered that their AI coding agent's governance plane failed to gate any tool calls because the container's --cap-drop ALL flag stripped CAP_DAC_OVERRIDE, causing Unix socket conβ¦