From b9c9839bb7679560f6e2f1a70a2a3e5e00e62373 Mon Sep 17 00:00:00 2001 From: Girish Ramakrishnan Date: Fri, 23 Nov 2018 11:23:33 -0800 Subject: [PATCH] apparmor is always enabled on all ubuntu --- src/docker.js | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/src/docker.js b/src/docker.js index 088229bbc..d628dd551 100644 --- a/src/docker.js +++ b/src/docker.js @@ -224,9 +224,6 @@ function createSubcontainer(app, name, cmd, options, callback) { // if required, we can make this a manifest and runtime argument later if (!isAppContainer) memoryLimit *= 2; - // apparmor is disabled on few servers - var enableSecurityOpt = config.CLOUDRON && safe(function () { return child_process.spawnSync('aa-enabled').status === 0; }, false); - addons.getEnvironment(app, function (error, addonEnv) { if (error) return callback(new Error('Error getting addon environment : ' + error)); @@ -277,7 +274,7 @@ function createSubcontainer(app, name, cmd, options, callback) { NetworkMode: 'cloudron', Dns: ['172.18.0.1'], // use internal dns DnsSearch: ['.'], // use internal dns - SecurityOpt: enableSecurityOpt ? [ 'apparmor=docker-cloudron-app' ] : null // profile available only on cloudron + SecurityOpt: [ 'apparmor=docker-cloudron-app' ] } };