mirror of
https://github.com/moby/moby.git
synced 2022-11-09 12:21:53 -05:00
Adjust docker-default profile when docker daemon is confined
Adjust the docker-default profile for when the docker daemon is running in AppArmor confinement. To enable 'docker kill' we need to allow the container to receive kill signals from the daemon. Signed-off-by: Stefan Berger <stefanb@linux.vnet.ibm.com>
This commit is contained in:
parent
6079d9d6a3
commit
5cd6b3eca2
1 changed files with 6 additions and 0 deletions
|
@ -55,6 +55,12 @@ profile {{.Name}} flags=(attach_disconnected,mediate_deleted) {
|
|||
deny /sys/fs/cg[^r]*/** wklx,
|
||||
deny /sys/firmware/efi/efivars/** rwklx,
|
||||
deny /sys/kernel/security/** rwklx,
|
||||
|
||||
# docker daemon confinement requires explict allow rule for signal
|
||||
signal (receive) set=(kill,term) peer=/usr/bin/docker,
|
||||
|
||||
# suppress ptrace denails when using 'docker ps'
|
||||
ptrace (trace,read) peer=docker-default,
|
||||
}
|
||||
`
|
||||
|
||||
|
|
Loading…
Add table
Reference in a new issue