Currently there is no way to add entries to the allowed device list. This means that there is no way to specify a wildcard entry, for devices that may be created during the lifetime of a container. Adding this would allow functionality equivalent to Docker's --device-cgroup-rule.