@@ -3611,3 +3611,95 @@ spec:
36113611      - effect : NoExecute 
36123612        key : node.kubernetes.io/not-ready 
36133613        operator : Exists 
3614+ ---
3615+ apiVersion : security-profiles-operator.x-k8s.io/v1alpha1 
3616+ kind : AppArmorProfile 
3617+ metadata :
3618+   labels :
3619+     app : ' {{.Release.Name}}' 
3620+     spo.x-k8s.io/container-id : security-profiles-operator 
3621+   name : spo-apparmor 
3622+   namespace : ' {{ .Release.Namespace }}' 
3623+ spec :
3624+   abstract :
3625+     capability :
3626+       allowedCapabilities :
3627+       - dac_override 
3628+       - dac_read_search 
3629+       - mac_admin 
3630+       - sys_admin 
3631+       - sys_chroot 
3632+     executable :
3633+       allowedExecutables :
3634+       - /security-profiles-operator 
3635+       - /usr/sbin/apparmor_parser 
3636+     filesystem :
3637+       readOnlyPaths :
3638+       - / 
3639+       - /etc/apparmor/parser.conf 
3640+       - /proc/@{pid}/maps 
3641+       - /proc/@{pid}/mounts 
3642+       - /proc/sys/kernel/osrelease 
3643+       - /proc/sys/net/core/somaxconn 
3644+       - /sys/kernel/mm/transparent_hugepage/hpage_pmd_size 
3645+       - /var/run/secrets/kubernetes.io/serviceaccount/** 
3646+       - /var/run/secrets/metrics/** 
3647+       - /sys/module/apparmor/parameters/enabled 
3648+       - /sys/devices/system/cpu/possible 
3649+       readWritePaths :
3650+       - ' ptrace (read),  # ugly template injection hack' 
3651+       - /var/run/grpc/metrics.sock 
3652+       - /tmp/aa_profile_bin_* 
3653+       - /etc/apparmor.d/** 
3654+       - /sys/kernel/security/apparmor/ 
3655+       - /sys/kernel/security/apparmor/** 
3656+       - /var/lib/kubelet/seccomp/operator/** 
3657+     network :
3658+       allowedProtocols :
3659+         allowTcp : true 
3660+         allowUdp : true 
3661+   disabled : false 
3662+ ---
3663+ apiVersion : security-profiles-operator.x-k8s.io/v1alpha1 
3664+ kind : AppArmorProfile 
3665+ metadata :
3666+   labels :
3667+     app : ' {{.Release.Name}}' 
3668+     spo.x-k8s.io/container-id : bpf-recorder 
3669+   name : bpfrecorder-apparmor 
3670+   namespace : ' {{ .Release.Namespace }}' 
3671+ spec :
3672+   abstract :
3673+     capability :
3674+       allowedCapabilities :
3675+       - bpf 
3676+       - chown 
3677+       - perfmon 
3678+       - sys_resource 
3679+     executable :
3680+       allowedExecutables :
3681+       - /security-profiles-operator 
3682+     filesystem :
3683+       readOnlyPaths :
3684+       - /proc/@{pid}/cgroup 
3685+       - /proc/@{pid}/maps 
3686+       - /proc/sys/net/core/somaxconn 
3687+       - /sys/devices/kprobe/type 
3688+       - /sys/devices/system/cpu/online 
3689+       - /sys/fs/bpf/ 
3690+       - /sys/kernel/btf/vmlinux 
3691+       - /sys/kernel/debug/tracing/events/**/id 
3692+       - /sys/kernel/mm/transparent_hugepage/hpage_pmd_size 
3693+       - /sys/kernel/security/lsm 
3694+       - /var/run/secrets/kubernetes.io/serviceaccount/** 
3695+       - /var/run/secrets/kubernetes.io/serviceaccount/** 
3696+       readWritePaths :
3697+       - |- 
3698+         ptrace (read), 
3699+         # ugly template injection hack 
3700+        - /var/run/grpc/bpf-recorder.sock 
3701+     network :
3702+       allowedProtocols :
3703+         allowTcp : true 
3704+         allowUdp : true 
3705+   disabled : false 
0 commit comments