[
     {
          "Id": "4c21b1800f48c254e67f36ba1dfe75051d236fa6b281fe9ec9416c3cd6542066",
          "Created": "2026-08-13T13:59:51.223171682+03:00",
          "Path": "/usr/bin/tini",
          "Args": [
               "--",
               "/bin/sh",
               "-c",
               "[ -n \"${HOME-}\" ] || { echo 'agent_cred: HOME unset in container' >&2; exit 10; }\nagent_cred_target=\"${HOME%/}/.codex/auth.json\"\ntrap 'rm -f \"$agent_cred_target\"' EXIT HUP INT TERM\nmkdir -p \"${agent_cred_target%/*}\" || { echo 'agent_cred: cannot create credential directory' >&2; exit 10; }\n[ -r '/sandbox-secrets/codex/auth.json' ] || { echo 'agent_cred: staging mount missing: /sandbox-secrets/codex/auth.json' >&2; exit 10; }\ncp '/sandbox-secrets/codex/auth.json' \"$agent_cred_target\" || { echo 'agent_cred: credential copy failed' >&2; exit 10; }\nchmod 600 \"$agent_cred_target\" || { echo 'agent_cred: cannot restrict credential mode' >&2; exit 10; }\n\"$@\"",
               "sh",
               "codex",
               "exec",
               "--sandbox",
               "danger-full-access",
               "--skip-git-repo-check",
               "-C",
               "/sandbox/workspaces/uj-020-cancellation-d8bc7588a5ef",
               "-m",
               "gpt-5.6-sol",
               "-c",
               "model_reasoning_effort=low",
               "Act as a senior application-security and correctness auditor performing an independent adversarial pre-ship review. User request: Re-review the current UJ-020 diff after fixes. Review exactly the current git diff and only essential cited references. Confirm: (1) ordinary API keys fail closed when site scope is absent; (2) license-auth site and plugin scope is exact in both lookup and compare-and-swap update; (3) unauthorized versus missing responses expose no existence oracle; (4) terminal-state, race, and idempotency behavior is correct. Report blockers only and do not edit any files. Treat every boundary input, datastore value, and auth claim as hostile. Enumerate every branch and check object-level authorization, fail-open validation, exact token/resource binding, timing/response oracles, injection, atomicity, single-winner CAS semantics, retry/redelivery idempotency, and information disclosure. For each candidate, state a concrete trigger, try once to refute it from code/callers, and report only findings that survive. Maintain/check the repository attack-surface map at .security/attack-surface.md only if this can be done without modifying files; because the user explicitly forbids edits, do not create or update it. Use any existing fresh map read-only, otherwise enumerate the changed scope in-memory. Output a numbered severity-ordered blocker list. Each finding must include title, absolute file:line, severity, concrete trigger/exploit, and specific fix. End with Headline and Residual/unverified. If no blocker is exploitable, say so directly and list only the top assumptions that remain unverified. Do not include non-blocking improvements."
          ],
          "State": {
               "OciVersion": "1.2.1",
               "Status": "exited",
               "Running": false,
               "Paused": false,
               "Restarting": false,
               "OOMKilled": false,
               "Dead": false,
               "Pid": 0,
               "ExitCode": 0,
               "Error": "",
               "StartedAt": "2026-08-13T13:59:51.350881574+03:00",
               "FinishedAt": "2026-08-13T14:01:11.329050417+03:00",
               "CheckpointedAt": "0001-01-01T00:00:00Z",
               "RestoredAt": "0001-01-01T00:00:00Z"
          },
          "Image": "a7eb5250818c802b103779019e19d4ada20a636aef9054930ec30016516b9aaf",
          "ImageDigest": "sha256:05abf7962fb582174c8c33f712fb82c38951ccac266621d7b40e652b67d81097",
          "ImageName": "localhost/overdeck-agent-sandbox:d1c7f17660b1",
          "Rootfs": "",
          "Pod": "",
          "ResolvConfPath": "/run/user/1000/containers/overlay-containers/4c21b1800f48c254e67f36ba1dfe75051d236fa6b281fe9ec9416c3cd6542066/userdata/resolv.conf",
          "HostnamePath": "/run/user/1000/containers/overlay-containers/4c21b1800f48c254e67f36ba1dfe75051d236fa6b281fe9ec9416c3cd6542066/userdata/hostname",
          "HostsPath": "/run/user/1000/containers/overlay-containers/4c21b1800f48c254e67f36ba1dfe75051d236fa6b281fe9ec9416c3cd6542066/userdata/hosts",
          "StaticDir": "/home/user/.local/share/containers/storage/overlay-containers/4c21b1800f48c254e67f36ba1dfe75051d236fa6b281fe9ec9416c3cd6542066/userdata",
          "OCIConfigPath": "/home/user/.local/share/containers/storage/overlay-containers/4c21b1800f48c254e67f36ba1dfe75051d236fa6b281fe9ec9416c3cd6542066/userdata/config.json",
          "OCIRuntime": "crun",
          "ConmonPidFile": "/run/user/1000/containers/overlay-containers/4c21b1800f48c254e67f36ba1dfe75051d236fa6b281fe9ec9416c3cd6542066/userdata/conmon.pid",
          "PidFile": "/run/user/1000/containers/overlay-containers/4c21b1800f48c254e67f36ba1dfe75051d236fa6b281fe9ec9416c3cd6542066/userdata/pidfile",
          "Name": "overdeck-sandbox-uj-020-cancellation-d8bc7588a5ef",
          "RestartCount": 0,
          "Driver": "overlay",
          "MountLabel": "",
          "ProcessLabel": "",
          "AppArmorProfile": "",
          "EffectiveCaps": null,
          "BoundingCaps": null,
          "ExecIDs": [],
          "GraphDriver": {
               "Name": "overlay",
               "Data": {
                    "LowerDir": "/home/user/.local/share/containers/storage/overlay/3e8801912cbeb9ee125d408c661688b63aa79edff23bb1d465e0592cd7aee30e/diff:/home/user/.local/share/containers/storage/overlay/fa6614715059bf58e1ff8042c3ceac8c70948a9fdfebbca3f10e99cb426c9116/diff:/home/user/.local/share/containers/storage/overlay/e1440254663234040539164f7031e3e60276ea61c8128a827269453309a19b08/diff:/home/user/.local/share/containers/storage/overlay/66dcc187f20c9adfa3e3d9076e59f32b9fee63ddc435137e2ed586dce5ad0b0a/diff:/home/user/.local/share/containers/storage/overlay/e54fd5490a1c3dc0ddfcc9b31e08dca344fa2211e9ef34dae4788878a3ab069b/diff:/home/user/.local/share/containers/storage/overlay/291c74a8d55109cf4a6ca696cbdc6affc42e1de28dde5422ae494fb8abd87195/diff:/home/user/.local/share/containers/storage/overlay/aada397d822a1a53d2824a0c53a996d4159e8b7aade3d4ce28397f77feadb6e0/diff:/home/user/.local/share/containers/storage/overlay/e4b696f23f3708113e735eae64e9b39c39250decdbee572c781e6e817d6e53fb/diff:/home/user/.local/share/containers/storage/overlay/94f8cd5e058475b44b2454e8efb618afdb9f213c8b17d737aecd4d8f68f4f103/diff:/home/user/.local/share/containers/storage/overlay/b5f84eefc76473ba4d51f4aac92c04dc9ab54ffef84ca96d737e8d6e7dfc923f/diff:/home/user/.local/share/containers/storage/overlay/89fa520c6803c2724c744bf1ef5ce0f6b61121cff78c107ed751055f880c6bde/diff:/home/user/.local/share/containers/storage/overlay/8bba409efaa55e20fd14dab87cd1d2fc6c02f0eddd668a8731251e16a87b0842/diff:/home/user/.local/share/containers/storage/overlay/1c9774c7f21648d1e3974dbed4f761882063e0c59b45565ea0a20ee1e79c3015/diff:/home/user/.local/share/containers/storage/overlay/7de836d8555b12af133986347e4d0d5ad97230067302caa638ce6c01cb807330/diff:/home/user/.local/share/containers/storage/overlay/33abc4ad76e2099a56041549ac0643312ed831660ea7f28e07f05bc228e12f78/diff",
                    "UpperDir": "/home/user/.local/share/containers/storage/overlay/0c1ff6202a28999aeab78d5a14f2358dad9ae304767740193d87aee9c5c48354/diff",
                    "WorkDir": "/home/user/.local/share/containers/storage/overlay/0c1ff6202a28999aeab78d5a14f2358dad9ae304767740193d87aee9c5c48354/work"
               }
          },
          "Mounts": [
               {
                    "Type": "bind",
                    "Source": "/home/user/.local/share/overdeck-sandbox/secrets/e2e_key",
                    "Destination": "/sandbox-secrets/e2e_key",
                    "Driver": "",
                    "Mode": "",
                    "Options": [
                         "rbind"
                    ],
                    "RW": false,
                    "Propagation": "rprivate"
               },
               {
                    "Type": "bind",
                    "Source": "/home/user/.local/share/overdeck-sandbox/secrets/e2e_known_hosts",
                    "Destination": "/sandbox-secrets/e2e_known_hosts",
                    "Driver": "",
                    "Mode": "",
                    "Options": [
                         "rbind"
                    ],
                    "RW": false,
                    "Propagation": "rprivate"
               },
               {
                    "Type": "bind",
                    "Source": "/home/user/cdx-offload/git-common/wp-content-898fc4388a24",
                    "Destination": "/home/user/cdx-offload/git-common/wp-content-898fc4388a24",
                    "Driver": "",
                    "Mode": "",
                    "Options": [
                         "rbind"
                    ],
                    "RW": true,
                    "Propagation": "rprivate"
               },
               {
                    "Type": "bind",
                    "Source": "/home/user/cdx-offload/git-common/wp-content-898fc4388a24/worktrees/uj-020-cancellation",
                    "Destination": "/home/user/cdx-offload/git-common/wp-content-898fc4388a24/worktrees/uj-020-cancellation",
                    "Driver": "",
                    "Mode": "",
                    "Options": [
                         "rbind"
                    ],
                    "RW": true,
                    "Propagation": "rprivate"
               },
               {
                    "Type": "bind",
                    "Source": "/home/user/.local/state/overdeck-sandbox/creds/1786618781277011012-2395397-11008/codex/auth.json",
                    "Destination": "/sandbox-secrets/codex/auth.json",
                    "Driver": "",
                    "Mode": "",
                    "Options": [
                         "rbind"
                    ],
                    "RW": false,
                    "Propagation": "rprivate"
               },
               {
                    "Type": "bind",
                    "Source": "/home/user/sandbox",
                    "Destination": "/sandbox",
                    "Driver": "",
                    "Mode": "",
                    "Options": [
                         "rbind"
                    ],
                    "RW": true,
                    "Propagation": "rprivate"
               }
          ],
          "Dependencies": [],
          "NetworkSettings": {
               "EndpointID": "",
               "Gateway": "",
               "IPAddress": "",
               "IPPrefixLen": 0,
               "IPv6Gateway": "",
               "GlobalIPv6Address": "",
               "GlobalIPv6PrefixLen": 0,
               "MacAddress": "",
               "Bridge": "",
               "SandboxID": "",
               "HairpinMode": false,
               "LinkLocalIPv6Address": "",
               "LinkLocalIPv6PrefixLen": 0,
               "Ports": {},
               "SandboxKey": "",
               "Networks": {
                    "pasta": {
                         "EndpointID": "",
                         "Gateway": "",
                         "IPAddress": "",
                         "IPPrefixLen": 0,
                         "IPv6Gateway": "",
                         "GlobalIPv6Address": "",
                         "GlobalIPv6PrefixLen": 0,
                         "MacAddress": "",
                         "NetworkID": "pasta",
                         "DriverOpts": null,
                         "IPAMConfig": null,
                         "Links": null
                    }
               }
          },
          "Namespace": "",
          "IsInfra": false,
          "IsService": false,
          "KubeExitCodePropagation": "invalid",
          "lockNumber": 0,
          "Config": {
               "Hostname": "sandbox-uj-020-cancellation-d8bc7588a5ef",
               "Domainname": "",
               "User": "agent",
               "AttachStdin": false,
               "AttachStdout": false,
               "AttachStderr": false,
               "Tty": false,
               "OpenStdin": true,
               "StdinOnce": false,
               "Env": [
                    "BASH_ENV=/etc/overdeck-sandbox/toolgap.bash",
                    "DEBIAN_FRONTEND=noninteractive",
                    "COREPACK_ENABLE_DOWNLOAD_PROMPT=0",
                    "PNPM_STORE_DIR=/sandbox/store/pnpm",
                    "DISABLE_AUTOUPDATER=1",
                    "container=podman",
                    "HOME=/sandbox/home",
                    "PNPM_HOME=/sandbox/home/.local/share/pnpm",
                    "SANDBOX_IMAGE=localhost/overdeck-agent-sandbox:d1c7f17660b1",
                    "SANDBOX_E2E_TARGET=user@host.containers.internal",
                    "SANDBOX_E2E_PORT=2222",
                    "PATH=/usr/local/node/bin:/sandbox/home/.local/share/pnpm:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin",
                    "LANG=C.UTF-8",
                    "PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD=1",
                    "SANDBOX_ID=uj-020-cancellation-d8bc7588a5ef",
                    "SANDBOX_TOOLGAP_FILE=/sandbox/toolgap/gaps.jsonl",
                    "PLAYWRIGHT_BROWSERS_PATH=/ms-playwright",
                    "HOSTNAME=sandbox-uj-020-cancellation-d8bc7588a5ef"
               ],
               "Cmd": [
                    "/bin/sh",
                    "-c",
                    "[ -n \"${HOME-}\" ] || { echo 'agent_cred: HOME unset in container' \u003e\u00262; exit 10; }\nagent_cred_target=\"${HOME%/}/.codex/auth.json\"\ntrap 'rm -f \"$agent_cred_target\"' EXIT HUP INT TERM\nmkdir -p \"${agent_cred_target%/*}\" || { echo 'agent_cred: cannot create credential directory' \u003e\u00262; exit 10; }\n[ -r '/sandbox-secrets/codex/auth.json' ] || { echo 'agent_cred: staging mount missing: /sandbox-secrets/codex/auth.json' \u003e\u00262; exit 10; }\ncp '/sandbox-secrets/codex/auth.json' \"$agent_cred_target\" || { echo 'agent_cred: credential copy failed' \u003e\u00262; exit 10; }\nchmod 600 \"$agent_cred_target\" || { echo 'agent_cred: cannot restrict credential mode' \u003e\u00262; exit 10; }\n\"$@\"",
                    "sh",
                    "codex",
                    "exec",
                    "--sandbox",
                    "danger-full-access",
                    "--skip-git-repo-check",
                    "-C",
                    "/sandbox/workspaces/uj-020-cancellation-d8bc7588a5ef",
                    "-m",
                    "gpt-5.6-sol",
                    "-c",
                    "model_reasoning_effort=low",
                    "Act as a senior application-security and correctness auditor performing an independent adversarial pre-ship review. User request: Re-review the current UJ-020 diff after fixes. Review exactly the current git diff and only essential cited references. Confirm: (1) ordinary API keys fail closed when site scope is absent; (2) license-auth site and plugin scope is exact in both lookup and compare-and-swap update; (3) unauthorized versus missing responses expose no existence oracle; (4) terminal-state, race, and idempotency behavior is correct. Report blockers only and do not edit any files. Treat every boundary input, datastore value, and auth claim as hostile. Enumerate every branch and check object-level authorization, fail-open validation, exact token/resource binding, timing/response oracles, injection, atomicity, single-winner CAS semantics, retry/redelivery idempotency, and information disclosure. For each candidate, state a concrete trigger, try once to refute it from code/callers, and report only findings that survive. Maintain/check the repository attack-surface map at .security/attack-surface.md only if this can be done without modifying files; because the user explicitly forbids edits, do not create or update it. Use any existing fresh map read-only, otherwise enumerate the changed scope in-memory. Output a numbered severity-ordered blocker list. Each finding must include title, absolute file:line, severity, concrete trigger/exploit, and specific fix. End with Headline and Residual/unverified. If no blocker is exploitable, say so directly and list only the top assumptions that remain unverified. Do not include non-blocking improvements."
               ],
               "Image": "localhost/overdeck-agent-sandbox:d1c7f17660b1",
               "Volumes": null,
               "WorkingDir": "/sandbox/workspaces/uj-020-cancellation-d8bc7588a5ef",
               "Entrypoint": [
                    "/usr/bin/tini",
                    "--"
               ],
               "OnBuild": null,
               "Labels": {
                    "io.buildah.version": "1.43.2"
               },
               "Annotations": {
                    "io.container.manager": "libpod",
                    "io.podman.annotations.cid-file": "/home/user/.local/share/overdeck-sandbox/runs/uj-020-cancellation-d8bc7588a5ef/cid",
                    "io.podman.annotations.pids-limit": "512",
                    "io.podman.annotations.userns": "keep-id",
                    "org.opencontainers.image.stopSignal": "15",
                    "org.systemd.property.KillSignal": "15",
                    "org.systemd.property.TimeoutStopUSec": "uint64 10000000"
               },
               "StopSignal": "SIGTERM",
               "HealthcheckOnFailureAction": "none",
               "HealthLogDestination": "local",
               "HealthcheckMaxLogCount": 5,
               "HealthcheckMaxLogSize": 500,
               "CreateCommand": [
                    "podman",
                    "run",
                    "--replace",
                    "--interactive",
                    "--cidfile",
                    "/home/user/.local/share/overdeck-sandbox/runs/uj-020-cancellation-d8bc7588a5ef/cid",
                    "--name",
                    "overdeck-sandbox-uj-020-cancellation-d8bc7588a5ef",
                    "--hostname",
                    "sandbox-uj-020-cancellation-d8bc7588a5ef",
                    "--userns=keep-id",
                    "--cap-drop=ALL",
                    "--security-opt=no-new-privileges",
                    "--pids-limit",
                    "512",
                    "--memory",
                    "12g",
                    "--memory-swap",
                    "12g",
                    "--cpus",
                    "4",
                    "--cpu-shares",
                    "256",
                    "--volume",
                    "/home/user/sandbox:/sandbox:rw",
                    "--volume",
                    "/home/user/.local/share/overdeck-sandbox/secrets/e2e_key:/sandbox-secrets/e2e_key:ro",
                    "--volume",
                    "/home/user/.local/share/overdeck-sandbox/secrets/e2e_known_hosts:/sandbox-secrets/e2e_known_hosts:ro",
                    "--volume",
                    "/home/user/cdx-offload/git-common/wp-content-898fc4388a24:/home/user/cdx-offload/git-common/wp-content-898fc4388a24:rw",
                    "--volume",
                    "/home/user/cdx-offload/git-common/wp-content-898fc4388a24/worktrees/uj-020-cancellation:/home/user/cdx-offload/git-common/wp-content-898fc4388a24/worktrees/uj-020-cancellation:rw",
                    "--volume",
                    "/home/user/.local/state/overdeck-sandbox/creds/1786618781277011012-2395397-11008/codex/auth.json:/sandbox-secrets/codex/auth.json:ro",
                    "--workdir",
                    "/sandbox/workspaces/uj-020-cancellation-d8bc7588a5ef",
                    "--env",
                    "SANDBOX_ID=uj-020-cancellation-d8bc7588a5ef",
                    "--env",
                    "SANDBOX_IMAGE=localhost/overdeck-agent-sandbox:d1c7f17660b1",
                    "--env",
                    "SANDBOX_E2E_TARGET=user@host.containers.internal",
                    "--env",
                    "SANDBOX_E2E_PORT=2222",
                    "localhost/overdeck-agent-sandbox:d1c7f17660b1",
                    "/bin/sh",
                    "-c",
                    "[ -n \"${HOME-}\" ] || { echo 'agent_cred: HOME unset in container' \u003e\u00262; exit 10; }\nagent_cred_target=\"${HOME%/}/.codex/auth.json\"\ntrap 'rm -f \"$agent_cred_target\"' EXIT HUP INT TERM\nmkdir -p \"${agent_cred_target%/*}\" || { echo 'agent_cred: cannot create credential directory' \u003e\u00262; exit 10; }\n[ -r '/sandbox-secrets/codex/auth.json' ] || { echo 'agent_cred: staging mount missing: /sandbox-secrets/codex/auth.json' \u003e\u00262; exit 10; }\ncp '/sandbox-secrets/codex/auth.json' \"$agent_cred_target\" || { echo 'agent_cred: credential copy failed' \u003e\u00262; exit 10; }\nchmod 600 \"$agent_cred_target\" || { echo 'agent_cred: cannot restrict credential mode' \u003e\u00262; exit 10; }\n\"$@\"",
                    "sh",
                    "codex",
                    "exec",
                    "--sandbox",
                    "danger-full-access",
                    "--skip-git-repo-check",
                    "-C",
                    "/sandbox/workspaces/uj-020-cancellation-d8bc7588a5ef",
                    "-m",
                    "gpt-5.6-sol",
                    "-c",
                    "model_reasoning_effort=low",
                    "Act as a senior application-security and correctness auditor performing an independent adversarial pre-ship review. User request: Re-review the current UJ-020 diff after fixes. Review exactly the current git diff and only essential cited references. Confirm: (1) ordinary API keys fail closed when site scope is absent; (2) license-auth site and plugin scope is exact in both lookup and compare-and-swap update; (3) unauthorized versus missing responses expose no existence oracle; (4) terminal-state, race, and idempotency behavior is correct. Report blockers only and do not edit any files. Treat every boundary input, datastore value, and auth claim as hostile. Enumerate every branch and check object-level authorization, fail-open validation, exact token/resource binding, timing/response oracles, injection, atomicity, single-winner CAS semantics, retry/redelivery idempotency, and information disclosure. For each candidate, state a concrete trigger, try once to refute it from code/callers, and report only findings that survive. Maintain/check the repository attack-surface map at .security/attack-surface.md only if this can be done without modifying files; because the user explicitly forbids edits, do not create or update it. Use any existing fresh map read-only, otherwise enumerate the changed scope in-memory. Output a numbered severity-ordered blocker list. Each finding must include title, absolute file:line, severity, concrete trigger/exploit, and specific fix. End with Headline and Residual/unverified. If no blocker is exploitable, say so directly and list only the top assumptions that remain unverified. Do not include non-blocking improvements."
               ],
               "Umask": "0022",
               "Timeout": 0,
               "StopTimeout": 10,
               "Passwd": true,
               "sdNotifyMode": "container"
          },
          "HostConfig": {
               "Binds": [
                    "/home/user/.local/share/overdeck-sandbox/secrets/e2e_key:/sandbox-secrets/e2e_key:ro,rprivate,rbind",
                    "/home/user/.local/share/overdeck-sandbox/secrets/e2e_known_hosts:/sandbox-secrets/e2e_known_hosts:ro,rprivate,rbind",
                    "/home/user/cdx-offload/git-common/wp-content-898fc4388a24:/home/user/cdx-offload/git-common/wp-content-898fc4388a24:rw,rprivate,rbind",
                    "/home/user/cdx-offload/git-common/wp-content-898fc4388a24/worktrees/uj-020-cancellation:/home/user/cdx-offload/git-common/wp-content-898fc4388a24/worktrees/uj-020-cancellation:rw,rprivate,rbind",
                    "/home/user/.local/state/overdeck-sandbox/creds/1786618781277011012-2395397-11008/codex/auth.json:/sandbox-secrets/codex/auth.json:ro,rprivate,rbind",
                    "/home/user/sandbox:/sandbox:rw,rprivate,rbind"
               ],
               "CgroupManager": "systemd",
               "CgroupMode": "private",
               "ContainerIDFile": "/home/user/.local/share/overdeck-sandbox/runs/uj-020-cancellation-d8bc7588a5ef/cid",
               "LogConfig": {
                    "Type": "journald",
                    "Config": null,
                    "Path": "",
                    "Tag": "",
                    "Size": "-1B"
               },
               "NetworkMode": "pasta",
               "PortBindings": {},
               "RestartPolicy": {
                    "Name": "no",
                    "MaximumRetryCount": 0
               },
               "AutoRemove": false,
               "AutoRemoveImage": false,
               "Annotations": {
                    "io.container.manager": "libpod",
                    "io.podman.annotations.cid-file": "/home/user/.local/share/overdeck-sandbox/runs/uj-020-cancellation-d8bc7588a5ef/cid",
                    "io.podman.annotations.pids-limit": "512",
                    "io.podman.annotations.userns": "keep-id",
                    "org.opencontainers.image.stopSignal": "15",
                    "org.systemd.property.KillSignal": "15",
                    "org.systemd.property.TimeoutStopUSec": "uint64 10000000"
               },
               "VolumeDriver": "",
               "VolumesFrom": null,
               "CapAdd": [],
               "CapDrop": [
                    "CAP_CHOWN",
                    "CAP_DAC_OVERRIDE",
                    "CAP_FOWNER",
                    "CAP_FSETID",
                    "CAP_KILL",
                    "CAP_NET_BIND_SERVICE",
                    "CAP_SETFCAP",
                    "CAP_SETGID",
                    "CAP_SETPCAP",
                    "CAP_SETUID",
                    "CAP_SYS_CHROOT"
               ],
               "Dns": [],
               "DnsOptions": [],
               "DnsSearch": [],
               "ExtraHosts": [],
               "HostsFile": "",
               "GroupAdd": [],
               "IpcMode": "shareable",
               "Cgroup": "",
               "Cgroups": "default",
               "Links": null,
               "OomScoreAdj": 0,
               "PidMode": "private",
               "Privileged": false,
               "PublishAllPorts": false,
               "ReadonlyRootfs": false,
               "SecurityOpt": [
                    "no-new-privileges"
               ],
               "Tmpfs": {},
               "UTSMode": "private",
               "UsernsMode": "private",
               "IDMappings": {
                    "UidMap": [
                         "0:1:1000",
                         "1000:0:1",
                         "1001:1001:64536"
                    ],
                    "GidMap": [
                         "0:1:1000",
                         "1000:0:1",
                         "1001:1001:64536"
                    ]
               },
               "ShmSize": 65536000,
               "Runtime": "oci",
               "ConsoleSize": [
                    0,
                    0
               ],
               "Isolation": "",
               "CpuShares": 256,
               "Memory": 12884901888,
               "NanoCpus": 4000000000,
               "CgroupParent": "user.slice",
               "BlkioWeight": 0,
               "BlkioWeightDevice": null,
               "BlkioDeviceReadBps": null,
               "BlkioDeviceWriteBps": null,
               "BlkioDeviceReadIOps": null,
               "BlkioDeviceWriteIOps": null,
               "CpuPeriod": 100000,
               "CpuQuota": 400000,
               "CpuRealtimePeriod": 0,
               "CpuRealtimeRuntime": 0,
               "CpusetCpus": "",
               "CpusetMems": "",
               "Devices": [],
               "DiskQuota": 0,
               "KernelMemory": 0,
               "MemoryReservation": 0,
               "MemorySwap": 12884901888,
               "MemorySwappiness": -1,
               "OomKillDisable": false,
               "PidsLimit": 512,
               "Ulimits": [
                    {
                         "Name": "RLIMIT_NOFILE",
                         "Soft": 524288,
                         "Hard": 524288
                    },
                    {
                         "Name": "RLIMIT_NPROC",
                         "Soft": 127162,
                         "Hard": 127162
                    }
               ],
               "CpuCount": 0,
               "CpuPercent": 0,
               "IOMaximumIOps": 0,
               "IOMaximumBandwidth": 0,
               "CgroupConf": null
          },
          "UseImageHosts": false,
          "UseImageHostname": false
     }
]
