Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
45 changes: 45 additions & 0 deletions docs/infra/keel-provision.pending
Original file line number Diff line number Diff line change
Expand Up @@ -104,6 +104,51 @@ lxc.idmap = u 0 $SUB_UID 65536
lxc.idmap = g 0 $SUB_GID 65536
LXCDEF
chown runner:runner /home/runner/.config/lxc/default.conf
# The nesting profile the containers run under, as the lxc package ships it
# (1:6.0.4-4+deb13u4) plus two mount rules systemd 257 needs: at boot,
# systemd-journald (and every unit with credentials) runs sd-mkdcreds,
# which mounts a ramfs on /run/credentials/<unit> and remounts it
# read-only with (ro,remount,bind,nosuid,nodev,noexec,nosymfollow). The
# stock profile allows neither, so in a CI container journald died with
# status=243/CREDENTIALS, /dev/log was gone, and the first boot hooks that
# log under bash -e died with it (Keel-Linux/inithooks#38, the published
# core 19.0-6 booted headless on 2026-10-03). The file is the package's
# conffile, written here as /etc/nftables.conf is: an lxc upgrade that
# changes it asks, and this script is the answer. The profile keeps its
# name, so bin/unprivileged-lxc of keel-linux/.github and the default.conf
# above need no change.
cat > /etc/apparmor.d/lxc/lxc-default-with-nesting << 'PROFILE'
# Do not load this file. Rather, load /etc/apparmor.d/lxc-containers, which
# will source all profiles under /etc/apparmor.d/lxc
#
# Written by keel-provision: the lxc package's profile, plus the two mount
# rules marked below (systemd 257 credentials, Keel-Linux/inithooks#38).

profile lxc-container-default-with-nesting flags=(attach_disconnected,mediate_deleted) {
#include <abstractions/lxc/container-base>
#include <abstractions/lxc/start-container>

deny /dev/.lxc/proc/** rw,
deny /dev/.lxc/sys/** rw,
mount fstype=proc -> /var/cache/lxc/**,
mount fstype=sysfs -> /var/cache/lxc/**,
mount options=(rw,bind),
mount options=(rw,rbind) -> /run/systemd/mount-rootfs/,
mount options=(rw,rbind) -> /run/systemd/mount-rootfs/**,
mount options=(rw,rbind) -> /run/systemd/unit-root/,
mount options=(rw,rbind) -> /run/systemd/unit-root/**,
mount options=(rw,rshared) -> /,
mount options=(rw,nosuid,nodev,noexec) proc -> /run/systemd/unit-root/proc/,
mount fstype=cgroup -> /sys/fs/cgroup/**,
mount fstype=cgroup2 -> /sys/fs/cgroup/**,
# keel-provision: systemd 257 sd-mkdcreds, the credentials of a unit
mount fstype=ramfs,
mount options=(ro,remount,bind,nosuid,nodev,noexec,nosymfollow),
}
PROFILE
chmod 0644 /etc/apparmor.d/lxc/lxc-default-with-nesting
apparmor_parser -r /etc/apparmor.d/lxc-containers
aa-status 2>/dev/null | grep -q 'lxc-container-default-with-nesting' && log "nesting profile loaded with the credentials mounts"
loginctl enable-linger runner
install -d -m 0755 -o runner -g runner /var/tmp/keel-ci
rm -f /usr/local/sbin/keel-ci-boot-test /usr/local/sbin/keel-ci-cleanup
Expand Down