Skip to content
AITroveRead. Build. Understand.
Make this comfortable

AppArmor profiles: match Pod placement to actual node enforcement

Last updated: 5 Oct 20266 min read
tutorial
AdvancedBy AITrove Editorial

AppArmor constrains operations such as file access for a container process. An explicit RuntimeDefault request has different admission behavior from leaving the field unset when a node lacks AppArmor. A Localhost profile is resolved from a profile loaded on the node, so a Pod manifest alone cannot distribute its contents. Scheduling a restricted workload to a node without the required profile can fail or leave the intended rule unenforced, depending on the configuration.

Operational decision

A claim-export worker is allowed to read its input directory but must not write to its policy directory. Build a test profile and install it through a controlled node-image or node-agent rollout, then verify its hash and active mode on every node eligible for the worker. The fragment shows only the container security-context field; the named Localhost profile must exist before this Pod can rely on it. Use a node label whose assignment is controlled by the platform team, and schedule a canary to each eligible node pool. Attempt one allowed export and one denied policy write, then inspect the kernel audit result and the application error. Repeat after a node replacement. For RuntimeDefault, test a node with AppArmor disabled and check whether an explicit field prevents admission; do not infer enforcement from a Pod phase alone. Keep the profile distribution path and rollback path in the same release record as the workload.

yaml
securityContext:
  appArmorProfile:
    type: Localhost
    localhostProfile: receipt-exporter-deny-policy-write

Cost and verification

Custom profiles add node management and can reduce scheduling headroom until all eligible nodes are prepared. A profile that blocks a legitimate export produces an application outage, while a missing profile can defeat the intended isolation. Measure profile hash drift, Pod start failures by node, denied operations, and time to bring a replacement node into the eligible pool. The fragment is a container security-context section, not a complete Pod manifest.

Common Mistakes

  • Do not assume a Localhost profile is shipped inside the container image.
  • Do not trust a label without checking the node's loaded profile and enforcement mode.
  • Do not interpret a running Pod as proof that an omitted AppArmor field is enforced on every node.

Connected lessons

Practice and check

devops
operations
Storage details