diff --git a/apparmor.d/groups/virt/containerd b/apparmor.d/groups/virt/containerd index 10738e9d..f1be9889 100644 --- a/apparmor.d/groups/virt/containerd +++ b/apparmor.d/groups/virt/containerd @@ -17,6 +17,7 @@ profile containerd @{exec_path} flags=(attach_disconnected) { capability chown, capability dac_read_search, capability dac_override, + capability fsetid, capability net_admin, capability sys_admin, @@ -57,7 +58,7 @@ profile containerd @{exec_path} flags=(attach_disconnected) { /var/lib/cni/results/cni-loopback-@{uuid}-lo l, /var/lib/containerd/{,**} rwk, - /var/lib/containerd/tmpmounts/containerd-mount[0-9]*/lib{64,}/** l, + /var/lib/containerd/tmpmounts/containerd-mount[0-9]*/** l, /var/lib/docker/containerd/{,**} rwk, /var/log/pods/**/[0-9]*.log w,