How to update default AppArmor profile for containers

May 7, 2016
11
1
43
38
How is apparmor profile "generated" created? How can we add additional rules to this profile? Or is there another way how to create profile with everything default generated profeile has but with added rules? We need to deny some operations inside LXC containers.
 
Found out how to do it.

Either to /etc/pve/VMID.conf or /etc/lxc/defult.conf add:

lxc.apparmor.raw: #include <pathto/customrules> (# is intentional!)

Then create custom AppArmor rules in /etc/apparmor.d/pathto/customrules
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!