Correct way to enable AppArmor inside an unprivileged LXC

Dec 6, 2021
34
3
13
46
Hi,

Can someone with solid experience in AppArmor + PVE confirm if this is the correct way to enable AppArmor inside an unprivileged LXC? The goal is to add specific profiles within the LXC to enhance security.

Here's the line I'm considering for
/etc/pve/lxc/XXX.conf

lxc.mount.entry: /sys/kernel/security sys/kernel/security none bind,ro,0 0

As far as I know, AppArmor supports namespaces, so I should be able to add a "layer" over the LXC's own profile without altering the base security profiles. However, I want to be sure.


Thanks a lot.

edit: I did ask o1-preview and Sonnet 3.5, they don't seem reliable on that subject, even dangerous.
 
Last edited:

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!