From 130c5624880e86bad40e7ead5c4d07f25d555f2a Mon Sep 17 00:00:00 2001 From: Jeroen Rijken Date: Thu, 21 Jul 2022 16:46:01 +0200 Subject: [PATCH] Allow containerd signal from k3s --- apparmor.d/groups/virt/containerd | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apparmor.d/groups/virt/containerd b/apparmor.d/groups/virt/containerd index 79806613..bdbc10fe 100644 --- a/apparmor.d/groups/virt/containerd +++ b/apparmor.d/groups/virt/containerd @@ -36,7 +36,7 @@ profile containerd @{exec_path} flags=(attach_disconnected) { umount /var/lib/containerd/tmpmounts/containerd-mount[0-9]*/, umount @{run}/netns/cni-@{uuid}, - signal (receive) set=term peer=dockerd, + signal (receive) set=term peer={dockerd,k3s}, signal (send) set=kill peer=cni-calico, @{exec_path} mr,