Public bug reported:

On a debian stretch host with a working apparmor installation, I created
a container (nspawn) and installed apparmor within that container.

Within the container, apparmor can't be started. `systemctl status
apparmor` returns "ConditionSecurity=apparmor was not met". I also noted
that the whole /sys/modules tree is missing within the container.
Invoking `cat /sys/module/apparmor/parameters/enabled` on the host
returns "Y".

Is AA virtualizable for containers? E.g. can multiple containers load
their own AA profiles? If so, what is exactly needed to run apparmor in
a container?

Thanks!

Cheers,
Matthias

** Affects: apparmor (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1765130

Title:
  Can't use apparmor-utils in nspawn container

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1765130/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to