@@ -17,18 +17,42 @@ policy: |2
17
17
/proc/@{pid}/cgroup r,
18
18
/proc/@{pid}/mounts r,
19
19
/proc/@{pid}/setgroups r,
20
+ /proc/@{pid}/task/@{tid}/attr r,
21
+ /proc/@{pid}/task/@{tid}/attr/apparmor r,
22
+ /proc/@{pid}/task/@{tid}/attr/apparmor/current r,
20
23
/proc/@{pid}/uid_map r,
21
24
/proc/sys/kernel/cap_last_cap r,
22
25
/run r,
23
26
/sys/module/apparmor/parameters/enabled r,
27
+ /var/lib/containers/storage/overlay/*/merged r,
28
+ /var/lib/containers/storage/overlay/*/merged/dev r,
29
+ /var/lib/containers/storage/overlay/*/merged/etc r,
30
+ /var/lib/containers/storage/overlay/*/merged/proc r,
31
+ /var/lib/containers/storage/overlay/*/merged/run r,
32
+ /var/lib/containers/storage/overlay/*/merged/run/secrets r,
33
+ /var/lib/containers/storage/overlay/*/merged/run/secrets/kubernetes.io r,
34
+ /var/lib/containers/storage/overlay/*/merged/sys r,
35
+ /var/lib/containers/storage/overlay/*/merged/var r,
24
36
25
37
deny /proc/@{pid}/cgroup wlk,
26
38
deny /proc/@{pid}/mounts wlk,
27
39
deny /proc/@{pid}/setgroups wlk,
40
+ deny /proc/@{pid}/task/@{tid}/attr wlk,
41
+ deny /proc/@{pid}/task/@{tid}/attr/apparmor wlk,
42
+ deny /proc/@{pid}/task/@{tid}/attr/apparmor/current wlk,
28
43
deny /proc/@{pid}/uid_map wlk,
29
44
deny /proc/sys/kernel/cap_last_cap wlk,
30
45
deny /run wlk,
31
46
deny /sys/module/apparmor/parameters/enabled wlk,
47
+ deny /var/lib/containers/storage/overlay/*/merged wlk,
48
+ deny /var/lib/containers/storage/overlay/*/merged/dev wlk,
49
+ deny /var/lib/containers/storage/overlay/*/merged/etc wlk,
50
+ deny /var/lib/containers/storage/overlay/*/merged/proc wlk,
51
+ deny /var/lib/containers/storage/overlay/*/merged/run wlk,
52
+ deny /var/lib/containers/storage/overlay/*/merged/run/secrets wlk,
53
+ deny /var/lib/containers/storage/overlay/*/merged/run/secrets/kubernetes.io wlk,
54
+ deny /var/lib/containers/storage/overlay/*/merged/sys wlk,
55
+ deny /var/lib/containers/storage/overlay/*/merged/var wlk,
32
56
33
57
34
58
/etc/alpine-release wlk,
@@ -84,6 +108,7 @@ policy: |2
84
108
/lib/libssl.so.3 wlk,
85
109
/lib/libz.so.1.3.1 wlk,
86
110
/lib/sysctl.d/00-alpine.conf wlk,
111
+ /proc/@{pid}/task/@{tid}/attr/apparmor/exec wlk,
87
112
/sbin/apk wlk,
88
113
/sbin/ldconfig wlk,
89
114
/usr/bin/getconf wlk,
@@ -115,6 +140,9 @@ policy: |2
115
140
/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub wlk,
116
141
/usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616db30d.rsa.pub wlk,
117
142
/usr/share/udhcpc/default.script wlk,
143
+ /var/lib/containers/storage/overlay/*/merged/dev/termination-log wlk,
144
+ /var/lib/containers/storage/overlay/*/merged/etc/resolv.conf wlk,
145
+ /var/lib/containers/storage/overlay/*/merged/run/.containerenv wlk,
118
146
119
147
deny /etc/alpine-release r,
120
148
deny /etc/apk/arch r,
@@ -169,6 +197,7 @@ policy: |2
169
197
deny /lib/libssl.so.3 r,
170
198
deny /lib/libz.so.1.3.1 r,
171
199
deny /lib/sysctl.d/00-alpine.conf r,
200
+ deny /proc/@{pid}/task/@{tid}/attr/apparmor/exec r,
172
201
deny /sbin/apk r,
173
202
deny /sbin/ldconfig r,
174
203
deny /usr/bin/getconf r,
@@ -200,6 +229,9 @@ policy: |2
200
229
deny /usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub r,
201
230
deny /usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616db30d.rsa.pub r,
202
231
deny /usr/share/udhcpc/default.script r,
232
+ deny /var/lib/containers/storage/overlay/*/merged/dev/termination-log r,
233
+ deny /var/lib/containers/storage/overlay/*/merged/etc/resolv.conf r,
234
+ deny /var/lib/containers/storage/overlay/*/merged/run/.containerenv r,
203
235
204
236
205
237
/dev/null rwlk,
0 commit comments