Fix site build (#16531)
The `*.profile` file referenced do not need to be provided in a separate file. Making them separate files is preventing hugo from correctly building the site.
This commit is contained in:
committed by
Kubernetes Prow Robot
parent
d7b4c74d0f
commit
82d8113545
@@ -178,7 +178,18 @@ k8s-apparmor-example-deny-write (enforce)
|
||||
First, we need to load the profile we want to use onto our nodes. The profile we'll use simply
|
||||
denies all file writes:
|
||||
|
||||
{{< code language="text" file="deny-write.profile" >}}
|
||||
```shell
|
||||
#include <tunables/global>
|
||||
|
||||
profile k8s-apparmor-example-deny-write flags=(attach_disconnected) {
|
||||
#include <abstractions/base>
|
||||
|
||||
file,
|
||||
|
||||
# Deny all file writes.
|
||||
deny /** w,
|
||||
}
|
||||
```
|
||||
|
||||
Since we don't know where the Pod will be scheduled, we'll need to load the profile on all our
|
||||
nodes. For this example we'll just use SSH to install the profiles, but other approaches are
|
||||
|
||||
@@ -1,10 +0,0 @@
|
||||
#include <tunables/global>
|
||||
|
||||
profile k8s-apparmor-example-deny-write flags=(attach_disconnected) {
|
||||
#include <abstractions/base>
|
||||
|
||||
file,
|
||||
|
||||
# Deny all file writes.
|
||||
deny /** w,
|
||||
}
|
||||
Reference in New Issue
Block a user