You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The documentation should explain that AppArmor enforcement and security_driver="none" control different security layers. The AppArmor
profile still protects the libvirtd process, while security_driver="none"
disables dynamic per-VM AppArmor/sVirt confinement. This keeps basic host
protection while avoiding possible compatibility problems with CloudStack
VM and storage operations.
The aa-enforce step is mainly needed for existing hosts where previous
CloudStack versions disabled these profiles. On fresh hosts, the libvirt
profiles are normally already enabled. Existing hosts may also already have security_driver="none", while fresh hosts must now configure it manually.
The introduction still says that AppArmor and SELinux must be disabled.
This conflicts with the new instructions and should be updated.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Doc for apache/cloudstack#13281
📚 Documentation preview 📚: https://cloudstack-documentation--662.org.readthedocs.build/en/662/