Thanks @stgraber - after also adding lxc.cap.drop=
flannel actually works. The raw lxc config now is:
lxc.aa_profile=unconfined
lxc.mount.auto=proc:rw sys:rw cgroup:rw
lxc.cgroup.devices.allow=a
lxc.cap.drop=
Thanks @stgraber - after also adding lxc.cap.drop=
flannel actually works. The raw lxc config now is:
lxc.aa_profile=unconfined
lxc.mount.auto=proc:rw sys:rw cgroup:rw
lxc.cgroup.devices.allow=a
lxc.cap.drop=