Whenever GEP-33 lands in a release stable enough for us to use it, we will want to set/transport capabilities on the synced MachineImages. How that is done on the GardenLinux side is still to be determined (a reasonable assumption would be via metadata values), but this sync job will definitely have to support setting them.