Overview

Request 1005892 accepted

- corrected comment in AppArmor profile
- added AppArmor profile
- added sandboxing options to systemd service unit



Witek Bedyk's avatar

Could you give some context on that? Will other exporters also get AppArmor profile?


Michael Ströder's avatar

It is just hardening to prevent misusing this exporter to break out into the system.

Currently only mtail has an AppArmor profile maintained by me: https://build.opensuse.org/package/view_file/server:monitoring/mtail/apparmor-usr.sbin.mtail?expand=1

But in my local setup node-exporter also runs with a home-grown AppArmor profile and I will submit this to the package soon.

Request History
Michael Ströder's avatar

stroeder created request

- corrected comment in AppArmor profile
- added AppArmor profile
- added sandboxing options to systemd service unit


Eric Schirra's avatar

ecsos accepted request

openSUSE Build Service is sponsored by