mirror of
https://gitlab.com/apparmor/apparmor
synced 2025-09-04 00:05:14 +00:00
Update how to setup a policy namespace for containers
@@ -42,7 +42,7 @@ need the display lsm set
|
|||||||
## lxd
|
## lxd
|
||||||
|
|
||||||
Lxd already supports creating apparmor child namespaces.
|
Lxd already supports creating apparmor child namespaces.
|
||||||
Nesting requirement with user namespaces
|
Requirement when used with user namespaces
|
||||||
|
|
||||||
|
|
||||||
# Authority to create a policy namespace
|
# Authority to create a policy namespace
|
||||||
@@ -61,7 +61,7 @@ Depends on apparmor and kernel versions
|
|||||||
Caveat: Audit subsystem is not namespaced
|
Caveat: Audit subsystem is not namespaced
|
||||||
|
|
||||||
|
|
||||||
## Nesting Requirement
|
## User namespace requirements
|
||||||
|
|
||||||
if apparmor policy namespaces are used in conjunction with user namespaces. There is a nesting limit.
|
if apparmor policy namespaces are used in conjunction with user namespaces. There is a nesting limit.
|
||||||
|
|
||||||
|
Reference in New Issue
Block a user