Small fixes

This commit is contained in:
Jeroen Rijken 2022-08-22 18:37:53 +02:00
parent 746a36bfb4
commit 586ea8fc27
2 changed files with 4 additions and 2 deletions

View file

@ -5,6 +5,8 @@
abi <abi/3.0>,
include <tunables/global>
@{date} = "[0-9][0-9][0-9][0-9]-[1-12]-[1-31]"
@{time} = "[1-24]-[0-60]-[0-60]"
@{exec_path} = /{usr/,}lib/cni/calico /opt/cni/bin/calico
profile cni-calico @{exec_path} flags=(attach_disconnected) {
@ -30,7 +32,7 @@ profile cni-calico @{exec_path} flags=(attach_disconnected) {
/var/lib/calico/{,**} r,
/var/log/calico/cni/ r,
/var/log/calico/cni/cni.log rw,
/var/log/calico/cni/cni-@{date}T@{time}.[0-9]*.log rw,
@{run}/calico/ rw,
@{run}/calico/ipam.lock rwk,

View file

@ -87,7 +87,7 @@ profile containerd @{exec_path} flags=(attach_disconnected) {
owner /var/tmp/** rwkl,
owner /tmp/** rwkl,
/tmp/cri-containerd.apparmor.d[0-9]* rwl,
/tmp/ctd-volume[0-9]*/{data,} rw,
/tmp/ctd-volume[0-9]*/{data/,} rw,
@{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r,
@{sys}/kernel/security/apparmor/profiles r,