The docker compose file reference describes the
cap_drop elements in a rather terse fashion:
Add or drop container capabilities. See man 7 capabilities for a full list.
Do these elements have an order, that is, add first, then drop? Or does the order matter (is this supported in YAML at all for dictionaries?)?
What happens when one of