Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Explicitly disable app armor in opencpu chart #448

Open
fdlk opened this issue Jun 24, 2021 · 1 comment
Open

Explicitly disable app armor in opencpu chart #448

fdlk opened this issue Jun 24, 2021 · 1 comment
Labels
bug Something isn't working chart-opencpu OpenCPU chart

Comments

@fdlk
Copy link
Contributor

fdlk commented Jun 24, 2021

Which chart are you referring?

opencpu

How to reproduce

Unsure

Expected behavior

opencpu does not run with apparmor

Observed behavior

at some point the pod broke and started emitting

System failure for: aa_change_profile() (No such file or directory)

Perhaps we can set OCPU_DISABLE_APPARMOR env variable to prevent this

@fdlk fdlk added chart-opencpu OpenCPU chart bug Something isn't working labels Jun 24, 2021
@fdlk
Copy link
Contributor Author

fdlk commented Jun 24, 2021

Running with app armor in a container is dangerous because the app armor of the host node and that of the container are linked

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working chart-opencpu OpenCPU chart
Projects
None yet
Development

No branches or pull requests

1 participant