-
Notifications
You must be signed in to change notification settings - Fork 6.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CRI-O: installing default AppArmor profile "crio-default" failed #10783
Comments
Have same error |
Signed-off-by: Wong Hoi Sing Edison <hswong3i@pantarei-design.com>
Signed-off-by: Wong Hoi Sing Edison <hswong3i@pantarei-design.com>
The Kubernetes project currently lacks enough contributors to adequately respond to all issues. This bot triages un-triaged issues according to the following rules:
You can:
Please send feedback to sig-contributor-experience at kubernetes/community. /lifecycle stale |
/remove-lifecycle |
BTW this is quick solution for those who have this error:
in
|
The Kubernetes project currently lacks enough active contributors to adequately respond to all issues. This bot triages un-triaged issues according to the following rules:
You can:
Please send feedback to sig-contributor-experience at kubernetes/community. /lifecycle rotten |
After upgrading our servers from Ubuntu 23.10 to 24.04, the apparmor profile for cri-o now works fine. I have reverted crio.conf to original configuration, and crio.service starts this way. apparmor_profile = "crio-default" I am unable from now to reproduce the issue, and it appears that not so many users experienced this issue. I am now closing the issue. Feel free to re-open if you are able to reproduce it. |
Summary: default AppArmor profile crio-default does not exist or cannot be loaded -> crio fails to start
Environment
playbook error output
journalctl error output
what we have tried
unsuccessfully
successfully
roles/container-engine/cri-o/templates/crio.conf
add optionapparmor_profile = "unconfined"
-> see my fork and commit as an ugly workaround.full journalctl log
apparmor status
crio.conf ugly patch
Since there is no variable that sets this option, we had to patch the template.
The text was updated successfully, but these errors were encountered: