diff --git a/pkg/drivers/kic/oci/oci.go b/pkg/drivers/kic/oci/oci.go index f1e53843eb085146c6df278f09eab4c1717cc607..94951fa4cc32980da425665dca22c5551b5a9e8c 100644 --- a/pkg/drivers/kic/oci/oci.go +++ b/pkg/drivers/kic/oci/oci.go @@ -108,7 +108,9 @@ func CreateContainerNode(p CreateParams) error { // including some ones docker would otherwise do by default. // for now this is what we want. in the future we may revisit this. "--privileged", - "--security-opt", "seccomp=unconfined", // also ignore seccomp + "--security-opt", "seccomp=unconfined", // ignore seccomp + // ignore apparmore github actions docker: https://github.com/kubernetes/minikube/issues/7624 + "--security-opt", "apparmor=unconfined", "--tmpfs", "/tmp", // various things depend on working /tmp "--tmpfs", "/run", // systemd wants a writable /run // logs,pods be stroed on filesystem vs inside container,