apparmor in containers (systemd-nspawn)

Asked by Matthias Pfau on 2018-04-12

On a debian stretch host with a working apparmor installation, I created a container (nspawn) and installed apparmor within that container.

Within the container, apparmor can't be started. `systemctl status apparmor` returns "ConditionSecurity=apparmor was not met". I also noted that the whole /sys/modules tree is missing within the container. Invoking `cat /sys/module/apparmor/parameters/enabled` on the host returns "Y".

Is AA virtualizable for containers? E.g. can multiple containers load their own AA profiles? If so, what is exactly needed to run apparmor in a container?

Thanks!

Cheers,
Matthias

Question information

Language:
English Edit question
Status:
Open
For:
Ubuntu apparmor Edit question
Assignee:
No assignee Edit question
Last query:
2018-04-12
Last reply:

Can you help with this problem?

Provide an answer of your own, or ask Matthias Pfau for more information if necessary.

To post a message you must log in.