mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2024-11-15 07:54:17 +01:00
Add missing volumes
This commit is contained in:
parent
07f1db2725
commit
e6525e1f04
@ -26,8 +26,7 @@ profile k3s @{exec_path} flags=(complain) {
|
|||||||
capability sys_resource,
|
capability sys_resource,
|
||||||
|
|
||||||
ptrace peer=@{profile_name},
|
ptrace peer=@{profile_name},
|
||||||
ptrace (read) peer={cri-containerd.apparmor.d,cni-xtables-nft,unconfined},
|
ptrace (read) peer={cri-containerd.apparmor.d,cni-xtables-nft,kubernetes-pause,mount,unconfined},
|
||||||
ptrace (read) peer=mount,
|
|
||||||
|
|
||||||
# k3s requires ptrace to all AppArmor profiles loaded in Kubernetes
|
# k3s requires ptrace to all AppArmor profiles loaded in Kubernetes
|
||||||
# For simplification, let's assume for now all AppArmor profiles start with a predefined prefix.
|
# For simplification, let's assume for now all AppArmor profiles start with a predefined prefix.
|
||||||
@ -42,8 +41,11 @@ profile k3s @{exec_path} flags=(complain) {
|
|||||||
network inet6 stream,
|
network inet6 stream,
|
||||||
network netlink raw,
|
network netlink raw,
|
||||||
|
|
||||||
mount /var/lib/kubelet/pods/@{uuid}/volumes/kubernetes.io~*/{,**/},
|
mount -> /var/lib/kubelet/pods/@{uuid}/volumes/kubernetes.io~*/{,**/},
|
||||||
|
mount -> /var/lib/kubelet/pods/@{uuid}/volume-subpaths/{,**},
|
||||||
|
|
||||||
umount /var/lib/kubelet/pods/@{uuid}/volumes/kubernetes.io~*/{,**/},
|
umount /var/lib/kubelet/pods/@{uuid}/volumes/kubernetes.io~*/{,**/},
|
||||||
|
umount /var/lib/kubelet/pods/@{uuid}/volume-subpaths/{,**},
|
||||||
|
|
||||||
signal (send, receive) set=term,
|
signal (send, receive) set=term,
|
||||||
signal (send) set=kill peer=unconfined,
|
signal (send) set=kill peer=unconfined,
|
||||||
|
Loading…
Reference in New Issue
Block a user