The driver and provisioner runs as privileged, so make all the other sidecar containers privileged too. This helps on system with SELinux, non-privileged container can't access socket of a privileged one.