Allow containerd to access SSL certs for pulling container images.

This commit is contained in:
Jeroen Rijken 2022-07-10 11:51:15 +02:00
parent edcd130432
commit 8413f6b9e6

View File

@ -9,6 +9,7 @@ include <tunables/global>
@{exec_path} = /{usr/,}bin/containerd @{exec_path} = /{usr/,}bin/containerd
profile containerd @{exec_path} { profile containerd @{exec_path} {
include <abstractions/base> include <abstractions/base>
include <abstractions/ssl_certs>
include <abstractions/nameservice-strict> include <abstractions/nameservice-strict>
capability dac_read_search, capability dac_read_search,