On the Cluster worker node, enforce the prepared AppArmor profile
#include
profile nginx-deny flags=(attach_disconnected) {
#include
file,
# Deny all file writes.
deny /** w,
}
EOF'
Edit the prepared manifest file to include the AppArmor profile.
apiVersion: v1
kind: Pod
metadata:
name: apparmor-pod
spec:
containers:
- name: apparmor-pod
image: nginx
Finally, apply the manifests files and create the Pod specified on it.
Verify: Try to make a file inside the directory which is restricted.
Argelia
10 months agoRanee
10 months agoAnabel
10 months agoDella
10 months agoMicheal
11 months agoFelix
11 months agoWilliam
11 months agoMarguerita
11 months agoEric
11 months agoNobuko
11 months agoPage
11 months agoChantell
11 months agoLanie
12 months agoStephane
12 months agoChanel
12 months agoSantos
1 year agoIsabelle
1 year agoJina
1 year agoGalen
1 year agoRikki
1 year agoCharlette
1 year agoKris
1 year agoTerina
1 year agoCaprice
1 year agoWillow
1 year agoAnnita
1 year agoShawnta
1 year agoLachelle
1 year agoGretchen
1 year agoInes
1 year agoNovella
1 year agoShawnta
1 year ago