Skip to content

Conversation

@HomayoonAlimohammadi
Copy link
Contributor

Overview

This PR rebases strict on top of master for the 1.35 release.

berkayoz and others added 23 commits September 5, 2025 10:23
Add explicit AppArmor rules to permit common socket types (inet, inet6, unix)
needed by Kubernetes workloads (e.g., kube-controller, coredns). Plucky ships
AppArmor 4.1.0, which is stricter and requires exact socket types to be set.
This resolves "apparmor=DENIED operation=create class=net" denials.

Fixes #5082
Fixes #5190
Fixes #5140
Signed-off-by: Homayoon (Hue) Alimohammadi <[email protected]>
* feat: bump containerd to 2.1.3 and update build process

* fix: move ctr flag before args in airgap test

* feat: add erofs-utils for containerd 2 requirement
…ube-system namespace (#5345)

Signed-off-by: Homayoon (Hue) Alimohammadi <[email protected]>
Signed-off-by: Homayoon (Hue) Alimohammadi <[email protected]>
@HomayoonAlimohammadi HomayoonAlimohammadi merged commit 6c9a8d3 into strict Dec 18, 2025
22 checks passed
@HomayoonAlimohammadi HomayoonAlimohammadi deleted the feat/update-strict branch December 18, 2025 14:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants