AppArmor constrains operations such as file access for a container process. An explicit RuntimeDefault request has different admission behavior from leaving the field unset when a node lacks AppArmor. A Localhost profile is resolved from a profile loaded on the node, so a Pod manifest alone cannot distribute its contents. Scheduling a restricted workload to a node without the required profile can fail or leave the intended rule unenforced, depending on the configuration.
AppArmor profiles: match Pod placement to actual node enforcement
Operational decision
A claim-export worker is allowed to read its input directory but must not write to its policy directory. Build a test profile and install it through a controlled node-image or node-agent rollout, then verify its hash and active mode on every node eligible for the worker. The fragment shows only the container security-context field; the named Localhost profile must exist before this Pod can rely on it. Use a node label whose assignment is controlled by the platform team, and schedule a canary to each eligible node pool. Attempt one allowed export and one denied policy write, then inspect the kernel audit result and the application error. Repeat after a node replacement. For RuntimeDefault, test a node with AppArmor disabled and check whether an explicit field prevents admission; do not infer enforcement from a Pod phase alone. Keep the profile distribution path and rollback path in the same release record as the workload.
securityContext:
appArmorProfile:
type: Localhost
localhostProfile: receipt-exporter-deny-policy-writeCost and verification
Custom profiles add node management and can reduce scheduling headroom until all eligible nodes are prepared. A profile that blocks a legitimate export produces an application outage, while a missing profile can defeat the intended isolation. Measure profile hash drift, Pod start failures by node, denied operations, and time to bring a replacement node into the eligible pool. The fragment is a container security-context section, not a complete Pod manifest.
Common Mistakes
- Do not assume a Localhost profile is shipped inside the container image.
- Do not trust a label without checking the node's loaded profile and enforcement mode.
- Do not interpret a running Pod as proof that an omitted AppArmor field is enforced on every node.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Container runtime restrictions: remove privileges a service does not use
- Seccomp RuntimeDefault: test syscall behavior across node runtimes
- Node autoscaling: make pending Pods schedulable before traffic rises
- Pod Security Admission: stage warnings before a namespace denies Pods
