image: swap config: binds: - /dev:/dev - /var:/var devices: # all devices (/dev/mapper is a character device) - path: all type: a capabilities: - CAP_SYS_ADMIN - CAP_MKNOD net: new ipc: new