Merge pull request #5049 from Supermathie/aa-fix
apparmor: docker-default: Include base abstraction
This commit is contained in:
commit
908be5a3d9
1 changed files with 2 additions and 5 deletions
|
@ -11,13 +11,10 @@ import (
|
||||||
const DefaultProfilePath = "/etc/apparmor.d/docker"
|
const DefaultProfilePath = "/etc/apparmor.d/docker"
|
||||||
const DefaultProfile = `
|
const DefaultProfile = `
|
||||||
# AppArmor profile from lxc for containers.
|
# AppArmor profile from lxc for containers.
|
||||||
@{HOME}=@{HOMEDIRS}/*/ /root/
|
|
||||||
@{HOMEDIRS}=/home/
|
|
||||||
#@{HOMEDIRS}+=
|
|
||||||
@{multiarch}=*-linux-gnu*
|
|
||||||
@{PROC}=/proc/
|
|
||||||
|
|
||||||
|
#include <tunables/global>
|
||||||
profile docker-default flags=(attach_disconnected,mediate_deleted) {
|
profile docker-default flags=(attach_disconnected,mediate_deleted) {
|
||||||
|
#include <abstractions/base>
|
||||||
network,
|
network,
|
||||||
capability,
|
capability,
|
||||||
file,
|
file,
|
||||||
|
|
Loading…
Reference in a new issue