Understand the Linux process capabilities restrictions with Talos Linux.
CAP_SYS_MODULE
(loading kernel modules)CAP_SYS_BOOT
(rebooting the system)
Note: even with CAP_SYS_MODULE
capability, Linux kernel module loading is restricted by requiring a valid signature.
Talos Linux creates a throw away signing key during kernel build, so it’s not possible to build/sign a kernel module for Talos Linux outside of the build process.