mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2025-01-18 08:58:15 +01:00
Allow signals from containerd to calico
This commit is contained in:
parent
8f81a39df1
commit
c03c624472
2 changed files with 3 additions and 0 deletions
|
@ -19,6 +19,8 @@ profile cni-calico @{exec_path} flags=(attach_disconnected) {
|
|||
network inet6 stream,
|
||||
network netlink raw,
|
||||
|
||||
signal (receive) set=kill peer=containerd,
|
||||
|
||||
@{exec_path} mr,
|
||||
@{exec_path}-ipam rix,
|
||||
|
||||
|
|
|
@ -37,6 +37,7 @@ profile containerd @{exec_path} flags=(attach_disconnected) {
|
|||
umount @{run}/netns/cni-@{uuid},
|
||||
|
||||
signal (receive) set=term peer=dockerd,
|
||||
signal (send) set=kill peer=cni-calico,
|
||||
|
||||
@{exec_path} mr,
|
||||
/{usr/,}{s,}bin/apparmor_parser rPx,
|
||||
|
|
Loading…
Reference in a new issue