From e3622523f033a4e7e0fd71b55ebc2e9cb54ced24 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Franc=CC=A7ois=20Bonelle?= Date: Fri, 25 Aug 2023 04:01:10 +0200 Subject: [PATCH] fix --- promtail/apparmor.txt | 58 +++++++++++++++++++++---------------------- 1 file changed, 29 insertions(+), 29 deletions(-) diff --git a/promtail/apparmor.txt b/promtail/apparmor.txt index 2fe2702..ff31d45 100644 --- a/promtail/apparmor.txt +++ b/promtail/apparmor.txt @@ -43,39 +43,39 @@ profile hassio_promtail flags=(attach_disconnected,mediate_deleted) { # Start new profile for service /usr/bin/promtail cx -> promtail_profile, -profile promtail_profile flags=(attach_disconnected,mediate_deleted) { - include + profile promtail_profile flags=(attach_disconnected,mediate_deleted) { + include - # Receive signals from s6 - signal (receive) peer=*_promtail, + # Receive signals from s6 + signal (receive) peer=*_promtail, - # Network access - network tcp, - network udp, - network netlink raw, - network unix dgram, + # Network access + network tcp, + network udp, + network netlink raw, + network unix dgram, - # Temp files - /tmp/.positions.yaml* rw, + # Temp files + /tmp/.positions.yaml* rw, - # Addon data - /data/** r, - /data/promtail/** rwk, + # Addon data + /data/** r, + /data/promtail/** rwk, - # Config & log data - @{do_etc}/promtail/* rw, - /config/promtail/{,**} r, - /{share,ssl}/** r, - @{journald} r, + # Config & log data + @{do_etc}/promtail/* rw, + /config/promtail/{,**} r, + /{share,ssl}/** r, + @{journald} r, - # Runtime usage - /usr/bin/promtail rm, - /usr/bin/yq rm, - @{do_etc}/{hosts,passwd} r, - @{do_etc}/{resolv,nsswitch}.conf r, - @{PROC}/sys/net/core/somaxconn r, - @{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r, - /dev/null k, - @{do_etc}/ssl/certs/** r, - } + # Runtime usage + /usr/bin/promtail rm, + /usr/bin/yq rm, + @{do_etc}/{hosts,passwd} r, + @{do_etc}/{resolv,nsswitch}.conf r, + @{PROC}/sys/net/core/somaxconn r, + @{sys}/kernel/mm/transparent_hugepage/hpage_pmd_size r, + /dev/null k, + @{do_etc}/ssl/certs/** r, + } } \ No newline at end of file