container: fix cilium denial
Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
This commit is contained in:
parent
d6b44b9c4f
commit
feaf607f3e
@ -866,6 +866,7 @@ allow spc_t self:netlink_audit_socket { create_netlink_socket_perms nlmsg_relay
|
||||
allow spc_t self:netlink_generic_socket create_socket_perms;
|
||||
allow spc_t self:netlink_netfilter_socket create_socket_perms;
|
||||
allow spc_t self:netlink_xfrm_socket create_socket_perms;
|
||||
allow spc_t self:perf_event { cpu kernel open read };
|
||||
|
||||
allow container_engine_system_domain spc_t:process { setsched signal_perms };
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user