On the Cluster worker node, enforce the prepared AppArmor profile
#include
profile nginx-deny flags=(attach_disconnected) {
#include
file,
# Deny all file writes.
deny /** w,
}
EOF'
Edit the prepared manifest file to include the AppArmor profile.
apiVersion: v1
kind: Pod
metadata:
name: apparmor-pod
spec:
containers:
- name: apparmor-pod
image: nginx
Finally, apply the manifests files and create the Pod specified on it.
Verify: Try to make a file inside the directory which is restricted.
Argelia
3 months agoRanee
3 months agoAnabel
3 months agoDella
4 months agoMicheal
4 months agoFelix
4 months agoWilliam
4 months agoMarguerita
5 months agoEric
5 months agoNobuko
5 months agoPage
5 months agoChantell
5 months agoLanie
5 months agoStephane
5 months agoChanel
5 months agoSantos
10 months agoIsabelle
10 months agoJina
8 months agoGalen
8 months agoRikki
8 months agoCharlette
9 months agoKris
10 months agoTerina
9 months agoCaprice
9 months agoWillow
9 months agoAnnita
10 months agoShawnta
11 months agoLachelle
11 months agoGretchen
11 months agoInes
10 months agoNovella
10 months agoShawnta
11 months ago