Needed for certain containers like calico
This commit is contained in:
parent
13aee74df9
commit
5a02490082
1 changed files with 2 additions and 1 deletions
|
|
@ -17,6 +17,7 @@ profile containerd @{exec_path} flags=(attach_disconnected) {
|
||||||
capability chown,
|
capability chown,
|
||||||
capability dac_read_search,
|
capability dac_read_search,
|
||||||
capability dac_override,
|
capability dac_override,
|
||||||
|
capability fsetid,
|
||||||
capability net_admin,
|
capability net_admin,
|
||||||
capability sys_admin,
|
capability sys_admin,
|
||||||
|
|
||||||
|
|
@ -57,7 +58,7 @@ profile containerd @{exec_path} flags=(attach_disconnected) {
|
||||||
|
|
||||||
/var/lib/cni/results/cni-loopback-@{uuid}-lo l,
|
/var/lib/cni/results/cni-loopback-@{uuid}-lo l,
|
||||||
/var/lib/containerd/{,**} rwk,
|
/var/lib/containerd/{,**} rwk,
|
||||||
/var/lib/containerd/tmpmounts/containerd-mount[0-9]*/lib{64,}/** l,
|
/var/lib/containerd/tmpmounts/containerd-mount[0-9]*/** l,
|
||||||
/var/lib/docker/containerd/{,**} rwk,
|
/var/lib/docker/containerd/{,**} rwk,
|
||||||
/var/log/pods/**/[0-9]*.log w,
|
/var/log/pods/**/[0-9]*.log w,
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue