Needed for certain containers like calico

This commit is contained in:
Jeroen Rijken 2022-07-16 17:38:02 +02:00 committed by Alex
parent 13aee74df9
commit 5a02490082

View File

@ -17,6 +17,7 @@ profile containerd @{exec_path} flags=(attach_disconnected) {
capability chown, capability chown,
capability dac_read_search, capability dac_read_search,
capability dac_override, capability dac_override,
capability fsetid,
capability net_admin, capability net_admin,
capability sys_admin, capability sys_admin,
@ -57,7 +58,7 @@ profile containerd @{exec_path} flags=(attach_disconnected) {
/var/lib/cni/results/cni-loopback-@{uuid}-lo l, /var/lib/cni/results/cni-loopback-@{uuid}-lo l,
/var/lib/containerd/{,**} rwk, /var/lib/containerd/{,**} rwk,
/var/lib/containerd/tmpmounts/containerd-mount[0-9]*/lib{64,}/** l, /var/lib/containerd/tmpmounts/containerd-mount[0-9]*/** l,
/var/lib/docker/containerd/{,**} rwk, /var/lib/docker/containerd/{,**} rwk,
/var/log/pods/**/[0-9]*.log w, /var/log/pods/**/[0-9]*.log w,