Use the 'generated' apparmor profile for all containers

Depends-On: https://review.opendev.org/c/openstack/openstack-ansible-openstack_hosts/+/924994
Depends-On: https://review.opendev.org/c/openstack/openstack-ansible-repo_server/+/925571
Change-Id: I038d2e03b794aacdf68f0e6daf660b7d6bfe6c41
This commit is contained in:
Jonathan Rosser 2024-07-22 17:50:31 +01:00
parent 9553aad54b
commit f55df9f330

View File

@ -13,11 +13,6 @@
# See the License for the specific language governing permissions and
# limitations under the License.
# This is the default LXC AppArmor profile
# Groups which need the unbound profile have a specific override
lxc_container_config_list:
- "lxc.apparmor.profile={{ (hostvars[physical_host]['ansible_facts']['distribution'] == 'Debian' ) | ternary('unconfined', 'lxc-openstack') }}"
# Needed by playbooks/common-tasks/os-lxc-container-setup.yml
lxc_container_log_path: "/var/log/lxc"