sorcery-go/manifests/lxc-sorcery-essence.apparmor

28 lines
1.0 KiB
Plaintext
Executable File

# DEPRECATED — Retained for reference only.
#
# The Sorcery-Go security model uses eBPF LSM programs (Tomb Guard +
# cgroup filters) for in-kernel enforcement. This AppArmor profile is
# superseded by pkg/warding/ebpf/c/tomb_guard.bpf.c and is no longer
# loaded by the Warding. See docs/SECURITY.md for the current model.
#include <tunables/global>
profile lxc-sorcery-essence flags=(attach_disconnected, mediate_deleted) {
#include <abstractions/lxc/container-default>
# 1. Global Essence Store Access (READ ONLY)
/var/lib/sorcery-go/tomb/ r,
/var/lib/sorcery-go/tomb/** r,
# 2. Deny all write/append/link/rename/delete attempts
deny /var/lib/sorcery-go/tomb/** wklx,
# 3. Allow BoltDB read-only access for local manifest verification
/var/lib/sorcery-go/state/state.db r,
# 4. Allow the Sorcery-Go engine binary to execute
/usr/local/sbin/sorcery-go rix,
# 5. Allow writes only inside the container's own rootfs
/var/lib/lxc/*/rootfs/** rwkl,
}