diff --git a/profiles/apparmor/template.go b/profiles/apparmor/template.go index 5dcf35bf45..9f207e2014 100644 --- a/profiles/apparmor/template.go +++ b/profiles/apparmor/template.go @@ -47,6 +47,7 @@ profile {{.Name}} flags=(attach_disconnected,mediate_deleted) { deny /sys/fs/c[^g]*/** wklx, deny /sys/fs/cg[^r]*/** wklx, deny /sys/firmware/** rwklx, + deny /sys/devices/virtual/powercap/** rwklx, deny /sys/kernel/security/** rwklx, # suppress ptrace denials when using 'docker ps' or using 'ps' inside a container