Polish AppArmor tutorial

This commit is contained in:
Qiming Teng
2017-09-26 10:00:59 +08:00
committed by Andrew Chen
parent c34b2a6c39
commit b176f8e3fb
+2 -15
View File
@@ -192,20 +192,7 @@ Next, we'll run a simple "Hello AppArmor" pod with the deny-write profile:
{% include code.html language="yaml" file="hello-apparmor-pod.yaml" ghlink="/docs/tutorials/clusters/hello-apparmor-pod.yaml" %} {% include code.html language="yaml" file="hello-apparmor-pod.yaml" ghlink="/docs/tutorials/clusters/hello-apparmor-pod.yaml" %}
```shell ```shell
$ kubectl create -f /dev/stdin <<EOF $ kubectl create -f ./hello-apparmor-pod.yaml
apiVersion: v1
kind: Pod
metadata:
name: hello-apparmor
annotations:
container.apparmor.security.beta.kubernetes.io/hello: localhost/k8s-apparmor-example-deny-write
spec:
containers:
- name: hello
image: busybox
command: [ "sh", "-c", "echo 'Hello AppArmor!' && sleep 1h" ]
EOF
pod "hello-apparmor" created
``` ```
If we look at the pod events, we can see that the Pod container was created with the AppArmor If we look at the pod events, we can see that the Pod container was created with the AppArmor
@@ -260,7 +247,7 @@ Node: gke-test-default-pool-239f5d02-x1kf/
Start Time: Tue, 30 Aug 2016 17:58:56 -0700 Start Time: Tue, 30 Aug 2016 17:58:56 -0700
Labels: <none> Labels: <none>
Annotations: container.apparmor.security.beta.kubernetes.io/hello=localhost/k8s-apparmor-example-allow-write Annotations: container.apparmor.security.beta.kubernetes.io/hello=localhost/k8s-apparmor-example-allow-write
Status: Failed Status: Pending
Reason: AppArmor Reason: AppArmor
Message: Pod Cannot enforce AppArmor: profile "k8s-apparmor-example-allow-write" is not loaded Message: Pod Cannot enforce AppArmor: profile "k8s-apparmor-example-allow-write" is not loaded
IP: IP: