mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2024-11-15 07:54:17 +01:00
Needed for certain containers like calico
This commit is contained in:
parent
13aee74df9
commit
5a02490082
@ -17,6 +17,7 @@ profile containerd @{exec_path} flags=(attach_disconnected) {
|
||||
capability chown,
|
||||
capability dac_read_search,
|
||||
capability dac_override,
|
||||
capability fsetid,
|
||||
capability net_admin,
|
||||
capability sys_admin,
|
||||
|
||||
@ -57,7 +58,7 @@ profile containerd @{exec_path} flags=(attach_disconnected) {
|
||||
|
||||
/var/lib/cni/results/cni-loopback-@{uuid}-lo l,
|
||||
/var/lib/containerd/{,**} rwk,
|
||||
/var/lib/containerd/tmpmounts/containerd-mount[0-9]*/lib{64,}/** l,
|
||||
/var/lib/containerd/tmpmounts/containerd-mount[0-9]*/** l,
|
||||
/var/lib/docker/containerd/{,**} rwk,
|
||||
/var/log/pods/**/[0-9]*.log w,
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user