Jeroen Rijken
61eab33cd8
Add ptrace subprofile
2022-07-21 19:46:45 +01:00
Jeroen Rijken
d6d9c943ae
Add missing permission
2022-07-21 19:46:45 +01:00
Jeroen Rijken
dca33292f7
Update ruleset for clean installation.
2022-07-21 19:46:45 +01:00
Jeroen Rijken
a1f4dbee50
First batch of cleanups based on PR comments.
2022-07-21 19:46:45 +01:00
Jeroen Rijken
c03c624472
Allow signals from containerd to calico
2022-07-21 19:46:45 +01:00
Jeroen Rijken
8f81a39df1
Support read AppArmor profiles
2022-07-21 19:46:45 +01:00
Jeroen Rijken
560250cf5f
Fix mode
2022-07-21 19:46:45 +01:00
Jeroen Rijken
2deb2a48a6
Fix name range.
2022-07-21 19:46:45 +01:00
Jeroen Rijken
a3415dc42c
Typo and calico proc.
2022-07-21 19:46:45 +01:00
Jeroen Rijken
c84455cca4
Fixes for container network creation.
2022-07-21 19:46:45 +01:00
Jeroen Rijken
3e006e3c76
Fix for calico unable to create network namespace.
2022-07-21 19:46:45 +01:00
Jeroen Rijken
5565217c91
Move xtables profile to child profile of k3s.
2022-07-21 19:46:45 +01:00
Jeroen Rijken
78cfb23bff
Apply suggested fixes from PR
2022-07-21 19:46:45 +01:00
Jeroen Rijken
5af6cda328
Allow dbus messages and user database reading.
2022-07-21 19:46:45 +01:00
Jeroen Rijken
28a3584c14
Initial support for xtables-nft-multi
2022-07-21 19:46:45 +01:00
Jeroen Rijken
463da2a8f4
Initial support for k3s
2022-07-21 19:46:45 +01:00
nobodysu
b8445e3b45
dbus style
2022-07-20 00:48:58 +03:00
Alexandre Pujol
8fda216cc2
doc: cosmetic.
2022-07-19 13:56:36 +01:00
Alexandre Pujol
f4dd2745d1
feat(profiles): add software-properties-dbus.
2022-07-19 00:03:01 +01:00
Alexandre Pujol
5b01f7963b
feat(profiles): add file-roller.
2022-07-18 23:58:12 +01:00
Alexandre Pujol
9692926752
feat(profiles): general update.
2022-07-18 23:57:25 +01:00
Jeroen Rijken
2ec802d40d
Remove deny root
2022-07-18 19:45:04 +01:00
Jeroen Rijken
e9bcd3f820
Small fixes
2022-07-18 19:45:04 +01:00
Jeroen Rijken
70aa5fdbb2
Small fixes
2022-07-18 19:45:04 +01:00
Jeroen Rijken
5a02490082
Needed for certain containers like calico
2022-07-18 19:45:04 +01:00
Jeroen Rijken
13aee74df9
Various containerd fixes
2022-07-18 19:45:04 +01:00
Alexandre Pujol
c750cb1b77
feat(profiles): general update.
2022-07-18 11:36:16 +01:00
Jeroen
081308db2f
Add ZFS Event Daemon ( #56 )
2022-07-17 22:04:13 +00:00
Alexandre Pujol
eb6c7548f5
feat(profiles): general update.
2022-07-15 21:55:59 +01:00
Jeroen Rijken
682df516bf
Make calico part of cni
2022-07-15 21:43:08 +01:00
Jeroen Rijken
02ad72b024
Allow containerd to (u)mount cni devices, and loopback to access them.
2022-07-15 21:43:08 +01:00
Jeroen Rijken
6c8e50534b
Cleanup profile
...
Signed-off-by: Jeroen Rijken <jeroen.rijken@xs4all.nl>
2022-07-15 21:43:08 +01:00
nobodysu
2d7ec5ad2c
Update spectre-meltdown-checker ( #50 )
...
* Update spectre-meltdown-checker
2022-07-15 20:42:15 +00:00
Alexandre Pujol
63f1a98c37
feat(profiles): add cron-ubuntu-fan.
2022-07-10 14:30:56 +01:00
Alexandre Pujol
23642eb0be
feat(profiles): general update.
2022-07-10 14:28:44 +01:00
Alexandre Pujol
c0e62f30bb
feat(profiles): add wireguard.
2022-07-10 14:24:30 +01:00
Alexandre Pujol
d8449de55e
feat(profiles): add and merge some cni profiles.
2022-07-10 14:24:09 +01:00
Alexandre Pujol
4f7cf8d90e
Merge branch 'Jeroen0494-feat/cni'
...
* Jeroen0494-feat/cni:
Alphabetical sorting, group common options.
Cleanup profiles according to standards
Allow mount-zfs access to pts
Typo
Initramfs generation updates
Executable updates for zpool
Basic ZFS support
Apply suggestions from code review
Update CNI path, set containerd to attach_disconnected, cleanups.
Add headers to new policies
Syntax fixes
Allow containerd to access SSL certs for pulling container images.
Calico profile cleanup.
Cleanup profiles according to standards part 1/2
Update build instructions for Ubuntu
Add AppArmor support to containerd
Add CNI for containerd
2022-07-10 13:42:30 +01:00
Alex
40d8c68f22
Merge branch 'master' into feat/cni
2022-07-10 13:41:50 +01:00
Jeroen Rijken
d10f2c073c
Alphabetical sorting, group common options.
2022-07-10 13:39:01 +01:00
Jeroen Rijken
59f8b893ff
Cleanup profiles according to standards
2022-07-10 13:39:01 +01:00
Jeroen Rijken
c9b4423e45
Allow mount-zfs access to pts
2022-07-10 13:39:01 +01:00
Jeroen Rijken
da08ef6aa6
Typo
2022-07-10 13:39:01 +01:00
Jeroen Rijken
cc5d1a0e07
Initramfs generation updates
2022-07-10 13:39:01 +01:00
Jeroen Rijken
99c311e699
Executable updates for zpool
2022-07-10 13:39:01 +01:00
Jeroen Rijken
3810c1668e
Basic ZFS support
2022-07-10 13:39:01 +01:00
Alex
6e1e7dc32b
Apply suggestions from code review
2022-07-10 12:38:11 +00:00
Jeroen Rijken
8a13d71edb
Update CNI path, set containerd to attach_disconnected, cleanups.
2022-07-10 13:36:44 +02:00
Jeroen Rijken
9fb43325a3
Add headers to new policies
2022-07-10 12:49:33 +02:00
Jeroen Rijken
7524bfa343
Syntax fixes
2022-07-10 12:43:52 +02:00