feat: use an "init service" to load the apparmor profile#63
Merged
MoisesGSalas merged 1 commit intomainfrom Nov 25, 2025
Merged
feat: use an "init service" to load the apparmor profile#63MoisesGSalas merged 1 commit intomainfrom
MoisesGSalas merged 1 commit intomainfrom
Conversation
fd8056e to
9a11838
Compare
9a11838 to
4bff93b
Compare
This follows the same logic as the "permissions" service used by tutor core. The `codejail-apparmor-loader` service runs the command used previously by the init job. It makes more sense to handling loading of the apparmor profile with an init service: - The profile is ephemeral, rebooting the host will require to load it again. - The profile is a dependency for the container to start. Things like database migrations, which are the main use case for init jobs, don't block the start of the main service container.
4bff93b to
80bd61a
Compare
BetoFandino
approved these changes
Nov 25, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This follows the same logic as the "permissions" service used by tutor core. The
codejail-apparmor-loaderservice runs the command used previously by the init job.It makes more sense to handling loading of the apparmor profile with an init service: