真题解析
Last updated
Last updated
apparmor_parser /etc/apparmor.d/nginx-apparmor
apparmor_status | grep nginx
nginx-deny-write# vim nginx-deploy.yaml
apiVersion: apps/v1
kind: Deployment
metadata:
creationTimestamp: null
labels:
app: nginx-deploy
name: nginx-deploy
spec:
replicas: 1
selector:
matchLabels:
app: nginx-deploy
strategy: {}
template:
metadata:
creationTimestamp: null
labels:
app: nginx-deploy
spec:
securityContext: # 添加此项配置
appArmorProfile:
type: Localhost # 加载宿主机上的配置
localhostProfile: nginx-deny-write # AppArmor 的 Profile 名称
containers:
- image: nginx
name: nginx
resources: {}
status: {}kubectl create -f nginx-deploy.yaml