There are some containers that need some additional kernel capabilities which would normally be added via the --cap-add runtime option.
My proposal is to have a configuration option that looks like this:
set container name XYZ cap-add NET_ADMIN
The value of cap-add would be a list allowing more than one cap to be added.