{{tag>Brouillon Sécurité}}
= Notes AppArmor
Voir :
* https://docs.docker.com/engine/security/apparmor/
The nscd Apparmor profile is not prepared for that and needs some additional
capabilities added.
Necessary changes are:
server-user nobody
capability setgid,
capability setuid,
After adding these lines, restart Apparmor and subsequently nscd
source : https://www.suse.com/fr-fr/support/kb/doc/?id=000017971
== K3S rootless
cat <,
include
/usr/local/bin/k3s flags=(unconfined) {
userns,
include if exists
}
EOF
sudo systemctl restart apparmor.service
Source : https://docs.k3s.io/advanced