master
issue: setcap build image shouldn't require a shell (#136633)
ensure permissions are consistent on dockerized binaries
add kube-log-runner to images on the fly, replicating the same /go-runner path as the current base image