Apparmor #49

Closed
opened 2024-02-16 18:49:34 +01:00 by aaron · 6 comments
Owner
No description provided.
tom added this to the Prod ready project 2024-02-17 14:52:23 +01:00
tom added this to the Prod Ready milestone 2024-02-17 14:52:27 +01:00
Owner

Update:

  • Master1 has AppArmor enabled for testing

Ready Status:

  • Master1
  • Master2
  • Master3
  • Worker1
  • Worker2
  • Worker3
Update: - Master1 has AppArmor enabled for testing Ready Status: - [x] Master1 - [ ] Master2 - [ ] Master3 - [ ] Worker1 - [ ] Worker2 - [x] Worker3
Author
Owner

I can find no issue with master1, where it is enabled. Survived both containerd update and k8s/system update
@tom

I can find no issue with master1, where it is enabled. Survived both containerd update and k8s/system update @tom
Author
Owner

Also no issue with a worker node. Survives reboot without problems.

Also no issue with a worker node. Survives reboot without problems.
Author
Owner

@tom any news

@tom any news
Owner

@tom any news

I once read that there were temporary problems with the standard AppArmor Kubelet profiles, but unfortunately, I can't find anything more about this. Since neither Master1 nor Worker3 have shown such errors so far, this should be solved and we can reactivate AppArmor (and remove the deactivation in the playbook). 🙂

> @tom any news > I once read that there were temporary problems with the standard AppArmor Kubelet profiles, but unfortunately, I can't find anything more about this. Since neither Master1 nor Worker3 have shown such errors so far, this should be solved and we can reactivate AppArmor (and remove the deactivation in the playbook). 🙂
Author
Owner

PR that enables AppArmor again:
#57

PR that enables AppArmor again: #57
tom closed this issue 2025-02-01 09:07:33 +01:00
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Depends on
#57 enable AppArmor
yolokube/ansible
Reference
yolokube/ansible#49
No description provided.