Skip to content

engine/security: Document custom AppArmor profile templates - #25607

Open
vvoland wants to merge 1 commit into
docker:mainfrom
vvoland:apparmor-custom-profiles
Open

engine/security: Document custom AppArmor profile templates#25607
vvoland wants to merge 1 commit into
docker:mainfrom
vvoland:apparmor-custom-profiles

Conversation

@vvoland

@vvoland vvoland commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Docker Engine 29.8 can render docker-default from a daemon-configured Go template.

Document the supported template data, safe file placement, daemon configuration, and verification so administrators do not treat the template as a directly loadable profile.

Description

Related issues or tickets

Reviews

  • Technical review
  • Editorial review
  • Product review

@netlify

netlify Bot commented Jul 20, 2026

Copy link
Copy Markdown

Deploy Preview for docsdocker ready!

Name Link
🔨 Latest commit a388897
🔍 Latest deploy log https://app.netlify.com/projects/docsdocker/deploys/6a996dff7e83740008d51496
😎 Deploy Preview https://deploy-preview-25607--docsdocker.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@github-actions github-actions Bot added area/engine Issue affects Docker engine/daemon area/security labels Jul 20, 2026
@vvoland
vvoland force-pushed the apparmor-custom-profiles branch from ab5f317 to 905e3fe Compare August 28, 2026 20:28
@vvoland
vvoland marked this pull request as ready for review August 28, 2026 20:28
@vvoland
vvoland requested a review from dvdksn as a code owner August 28, 2026 20:28
@vvoland
vvoland requested review from thaJeztah and a balanced review from Copilot August 31, 2026 09:59

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Documents Docker Engine 29.8 support for custom default AppArmor templates.

Changes:

  • Explains supported template data and security considerations.
  • Adds daemon configuration, restart, and verification instructions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread content/manuals/engine/security/apparmor.md Outdated
Comment thread content/manuals/engine/security/apparmor.md Outdated
@vvoland
vvoland force-pushed the apparmor-custom-profiles branch from 905e3fe to 6ce110c Compare August 31, 2026 12:04
@vvoland
vvoland requested a balanced review from Copilot August 31, 2026 12:08

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.

@vvoland
vvoland requested a review from docker-agent August 31, 2026 12:30
@thaJeztah thaJeztah added this to the engine/29.8.0 milestone Sep 1, 2026
Comment thread content/manuals/engine/security/apparmor.md Outdated
@vvoland
vvoland force-pushed the apparmor-custom-profiles branch from 6ce110c to 0d8e970 Compare September 3, 2026 12:53
Docker Engine 29.8 can render docker-default from a daemon-configured Go
template.

Document the supported template data, safe file placement, daemon
configuration, and verification so administrators do not treat the
template as a directly loadable profile.

Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com>
@vvoland
vvoland force-pushed the apparmor-custom-profiles branch from 0d8e970 to a388897 Compare September 3, 2026 12:54

@thaJeztah thaJeztah left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/engine Issue affects Docker engine/daemon area/security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants