Ubuntu 16.04下Docker容器中AppArmor间歇性运行问题求助
AppArmor with Docker 18.03.0-ce on Ubuntu 16.04: Intermittent Enforcement Issues
I'm testing how AppArmor integrates with Docker on my Ubuntu 16.04 system, and I've run into a confusing intermittent problem—sometimes AppArmor enforces policies exactly as expected, but other times it fails to do so. Let me walk through my setup and what I've verified so far:
- My Docker version is 18.03.0-ce, build 0520e24
- Launching a container with
$ docker run -it ubuntu bashworks smoothly, spinning up the expected Ubuntu 16.04 environment without errors - Running
$ sudo aa-statusconfirms that thedocker-defaultAppArmor profile is active and applied to the running container - When I execute
$ cat /proc/sysrq-triggerinside the container, I get the expectedpermission deniederror (this is the correct behavior, as thedocker-defaultprofile should block this action per official guidelines)
The trouble is, this enforcement isn't consistent. Every now and then, the same operation won't get blocked, or it seems like the AppArmor profile isn't being applied at all. I can't pinpoint what's causing this inconsistency.
Has anyone faced a similar intermittent issue with AppArmor and Docker? Any tips on how to debug or fix this would be greatly appreciated.
内容的提问来源于stack exchange,提问作者afkupuz72
相关产品推荐
相关产品推荐

