adding feature for apparmor annotation#160
adding feature for apparmor annotation#160jonathanmhurley wants to merge 1 commit intozegl:masterfrom
Conversation
|
Requiring a AppArmor annotation can be a bit problematic,
This said, I'm for merging this features as a optional check that can be enabled with the |
|
Hi Gustav, FWIW I think this check is beneficial even considering your very valid point about PSP because PSP must be enabled at the cluster level and fails closed so apparmor is a good vehicle to get some of the security if there's a blocking reason why a cluster can't be changed. |
|
I think it will be good to check if the annotation is set to "unconfined" as that will be skipping apparmor |
link