mirror of
https://github.com/containers/podman.git
synced 2025-10-24 15:03:45 +08:00
podman/libpod: add default AppArmor profile
Make users of libpod more secure by adding the libpod/apparmor package to load a pre-defined AppArmor profile. Large chunks of libpod/apparmor come from github.com/moby/moby. Also check if a specified AppArmor profile is actually loaded and throw an error if necessary. The default profile is loaded only on Linux builds with the `apparmor` buildtag enabled. Signed-off-by: Valentin Rothberg <vrothberg@suse.com> Closes: #1063 Approved by: rhatdan
This commit is contained in:

committed by
Atomic Bot

parent
84cfdb2061
commit
06ab343bd7
@ -83,4 +83,9 @@ COPY test/redhat_sigstore.yaml /etc/containers/registries.d/registry.access.redh
|
||||
|
||||
# Install varlink stuff
|
||||
RUN pip3 install varlink
|
||||
|
||||
WORKDIR /go/src/github.com/projectatomic/libpod
|
||||
|
||||
# Wrap all commands in the "docker-in-docker" script to allow nested containers,
|
||||
# and allow testing of apparmor.
|
||||
ENTRYPOINT ["./hack/dind"]
|
||||
|
Reference in New Issue
Block a user