On the Cluster worker node, enforce the prepared AppArmor profile
#include
profile nginx-deny flags=(attach_disconnected) {
#include
file,
# Deny all file writes.
deny /** w,
}
EOF'
Edit the prepared manifest file to include the AppArmor profile.
apiVersion: v1
kind: Pod
metadata:
name: apparmor-pod
spec:
containers:
- name: apparmor-pod
image: nginx
Finally, apply the manifests files and create the Pod specified on it.
Verify: Try to make a file inside the directory which is restricted.
Argelia
5 months agoRanee
5 months agoAnabel
6 months agoDella
6 months agoMicheal
6 months agoFelix
6 months agoWilliam
6 months agoMarguerita
7 months agoEric
7 months agoNobuko
7 months agoPage
7 months agoChantell
7 months agoLanie
7 months agoStephane
7 months agoChanel
7 months agoSantos
12 months agoIsabelle
12 months agoJina
10 months agoGalen
10 months agoRikki
10 months agoCharlette
11 months agoKris
1 year agoTerina
11 months agoCaprice
11 months agoWillow
11 months agoAnnita
1 year agoShawnta
1 year agoLachelle
1 year agoGretchen
1 year agoInes
12 months agoNovella
1 year agoShawnta
1 year ago