Remove dangling files related to apparmor
This commit is contained in:
@@ -1,10 +0,0 @@
|
|||||||
#include <tunables/global>
|
|
||||||
|
|
||||||
profile k8s-apparmor-example-deny-write flags=(attach_disconnected) {
|
|
||||||
#include <abstractions/base>
|
|
||||||
|
|
||||||
file,
|
|
||||||
|
|
||||||
# Deny all file writes.
|
|
||||||
deny /** w,
|
|
||||||
}
|
|
||||||
@@ -1,13 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Pod
|
|
||||||
metadata:
|
|
||||||
name: hello-apparmor
|
|
||||||
annotations:
|
|
||||||
# Tell Kubernetes to apply the AppArmor profile "k8s-apparmor-example-deny-write".
|
|
||||||
# Note that this is ignored if the Kubernetes node is not running version 1.4 or greater.
|
|
||||||
container.apparmor.security.beta.kubernetes.io/hello: localhost/k8s-apparmor-example-deny-write
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: hello
|
|
||||||
image: busybox
|
|
||||||
command: [ "sh", "-c", "echo 'Hello AppArmor!' && sleep 1h" ]
|
|
||||||
Reference in New Issue
Block a user