I think you have that the wrong way around. The containers run *without* cap_sys_{module,boot,time,audit_control,mac_admin}.