On the Cluster worker node, enforce the prepared AppArmor profile
#include
profile nginx-deny flags=(attach_disconnected) {
#include
file,
# Deny all file writes.
deny /** w,
}
EOF'
Edit the prepared manifest file to include the AppArmor profile.
apiVersion: v1
kind: Pod
metadata:
name: apparmor-pod
spec:
containers:
- name: apparmor-pod
image: nginx
Finally, apply the manifests files and create the Pod specified on it.
Verify: Try to make a file inside the directory which is restricted.
Argelia
7 months agoRanee
7 months agoAnabel
7 months agoDella
7 months agoMicheal
8 months agoFelix
8 months agoWilliam
8 months agoMarguerita
8 months agoEric
8 months agoNobuko
8 months agoPage
8 months agoChantell
8 months agoLanie
9 months agoStephane
9 months agoChanel
9 months agoSantos
1 year agoIsabelle
1 year agoJina
11 months agoGalen
12 months agoRikki
12 months agoCharlette
1 year agoKris
1 year agoTerina
1 year agoCaprice
1 year agoWillow
1 year agoAnnita
1 year agoShawnta
1 year agoLachelle
1 year agoGretchen
1 year agoInes
1 year agoNovella
1 year agoShawnta
1 year ago