From e6525e1f0453ff59c8200f206dc0358a33bcc1cd Mon Sep 17 00:00:00 2001 From: Jeroen Rijken Date: Sat, 23 Jul 2022 15:28:07 +0200 Subject: [PATCH] Add missing volumes --- apparmor.d/groups/virt/k3s | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/apparmor.d/groups/virt/k3s b/apparmor.d/groups/virt/k3s index 00b3a726..0c661036 100644 --- a/apparmor.d/groups/virt/k3s +++ b/apparmor.d/groups/virt/k3s @@ -26,8 +26,7 @@ profile k3s @{exec_path} flags=(complain) { capability sys_resource, ptrace peer=@{profile_name}, - ptrace (read) peer={cri-containerd.apparmor.d,cni-xtables-nft,unconfined}, - ptrace (read) peer=mount, + ptrace (read) peer={cri-containerd.apparmor.d,cni-xtables-nft,kubernetes-pause,mount,unconfined}, # k3s requires ptrace to all AppArmor profiles loaded in Kubernetes # For simplification, let's assume for now all AppArmor profiles start with a predefined prefix. @@ -42,8 +41,11 @@ profile k3s @{exec_path} flags=(complain) { network inet6 stream, network netlink raw, - mount /var/lib/kubelet/pods/@{uuid}/volumes/kubernetes.io~*/{,**/}, + mount -> /var/lib/kubelet/pods/@{uuid}/volumes/kubernetes.io~*/{,**/}, + mount -> /var/lib/kubelet/pods/@{uuid}/volume-subpaths/{,**}, + umount /var/lib/kubelet/pods/@{uuid}/volumes/kubernetes.io~*/{,**/}, + umount /var/lib/kubelet/pods/@{uuid}/volume-subpaths/{,**}, signal (send, receive) set=term, signal (send) set=kill peer=unconfined,