Skip to content
Discussion options

You must be logged in to vote

Apparmor is only allowing / denying things.

Setting up a sandbox, putting a container image in this sandbox and pivoting the root to this image (like snap, flatpak or docker do) is out of the scope of apparmor. However, in coordination with these sandbox manager, you can use apparmor to ensure sandbox escape is not possible. It is especially useful when you need to give access to devices file (graphics, usb...) to the sandbox.

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@dundalek
Comment options

@roddhjav
Comment options

@dundalek
Comment options

Answer selected by dundalek
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants