|
@@ -23,3 +23,15 @@ profile docker-default flags=(attach_disconnected,mediate_deleted) {
|
|
deny /sys/firmware/efi/efivars/** rwklx,
|
|
deny /sys/firmware/efi/efivars/** rwklx,
|
|
deny /sys/kernel/security/** rwklx,
|
|
deny /sys/kernel/security/** rwklx,
|
|
}
|
|
}
|
|
|
|
+
|
|
|
|
+profile docker-unconfined flags=(attach_disconnected,mediate_deleted) {
|
|
|
|
+ #include <abstractions/base>
|
|
|
|
+
|
|
|
|
+ network,
|
|
|
|
+ capability,
|
|
|
|
+ file,
|
|
|
|
+ umount,
|
|
|
|
+ mount,
|
|
|
|
+ pivot_root,
|
|
|
|
+ change_profile -> *,
|
|
|
|
+}
|