AppArmor fails to start on TKr <1.30
search cancel

AppArmor fails to start on TKr <1.30

book

Article ID: 403599

calendar_today

Updated On:

Products

VMware vSphere Kubernetes Service

Issue/Introduction

AppArmor service shows as inactive.

systemctl status apparmor.service
○ apparmor.service - Load AppArmor profiles
     Loaded: loaded (/usr/lib/systemd/system/apparmor.service; enabled; preset: enabled)
     Active: inactive (dead)
  Condition: start condition failed at Mon 2025-01-01 00:00:00 UTC; 6 days ago

 

KubeApi logs show the following permissions error

failed to mkdir "/sys/kernel/security/apparmor": mkdir /sys/kernel/security/apparmor: operation not permitted

Environment

VKr/TKr <= 1.30

Cause

Broadcom engineering teams are researching the root cause of this issue.

Resolution

The issue is fixed in VKr 1.31 and above.