I am trying to make AppArmor work inside a Debian 10 container, which is running on a Ubuntu 18.04 host with LXD 3.0.3.
I have create the vm05 Debian10 CT and enabled security nesting:
$ lxc config show vm05 --expanded|fgrep nest security.nesting: "true"
However, after installing apparmor userland tools & profiles and rebooting vm05, it doesn’t load any AppArmor profiles:
root@vm05:~# cat /etc/debian_version 10.4 root@vm05:~# dpkg -l|fgrep apparm ii apparmor 2.13.2-10 amd64 user-space parser utility for AppArmor ii apparmor-profiles 2.13.2-10 all experimental profiles for AppArmor security policies ii libapparmor1:amd64 2.13.2-10 amd64 changehat AppArmor library root@vm05:~# root@vm05:~# apparmor_status apparmor module is loaded. 0 profiles are loaded. 0 profiles are in enforce mode. 0 profiles are in complain mode. 0 processes have profiles defined. 0 processes are in enforce mode. 0 processes are in complain mode. 0 processes are unconfined but have a profile defined. root@vm05:~#
There are several profiles in /etc/apparmor.d/
Any hints about troubleshooting this?
Thanks in advance, K.