# Description: Can manage containers. This is restricted because it gives wide
# access to the system, which is needed for software managing containers.
# Usage: reserved

# Must use unrestricted because container managers like docker and LXD use
# seccomp themselves for container isolation. Since seccomp can only get more
# strict and containers may want to have more access than is in the default
# policy, use unrestricted seccomp policy.
@unrestricted
