diff --git a/tutorcodejail/patches/k8s-jobs b/tutorcodejail/patches/k8s-jobs deleted file mode 100644 index c82261b..0000000 --- a/tutorcodejail/patches/k8s-jobs +++ /dev/null @@ -1,21 +0,0 @@ ---- -# Dummy job that doesn't actually load the profile. -# To enforce apparmor we need to load the profile -# on each node, for that reason we use a DaemonSet -# defined in the k8s-deployments patch. -apiVersion: batch/v1 -kind: Job -metadata: - name: codejail-apparmor-job - labels: - app.kubernetes.io/component: job -spec: - template: - spec: - restartPolicy: Never - containers: - - name: codejail-apparmor-loader - image: busybox:1.28 - env: - - name: SKIP_INIT - value: "True" diff --git a/tutorcodejail/patches/local-docker-compose-jobs-services b/tutorcodejail/patches/local-docker-compose-jobs-services deleted file mode 100644 index db84a33..0000000 --- a/tutorcodejail/patches/local-docker-compose-jobs-services +++ /dev/null @@ -1,9 +0,0 @@ -codejail-apparmor-job: - image: {{ CODEJAIL_APPARMOR_DOCKER_IMAGE }} - privileged: true - environment: - SKIP_INIT: "{{ CODEJAIL_SKIP_INIT }}" - volumes: - - ../plugins/codejail/apps/profiles/docker-edx-sandbox:/profiles/docker-edx-sandbox:ro - - /sys:/sys - - /etc/apparmor.d:/etc/apparmor.d diff --git a/tutorcodejail/patches/local-docker-compose-services b/tutorcodejail/patches/local-docker-compose-services index 1ef2446..dccd85b 100644 --- a/tutorcodejail/patches/local-docker-compose-services +++ b/tutorcodejail/patches/local-docker-compose-services @@ -11,3 +11,18 @@ codejailservice: - ../plugins/codejail/apps/config/tutor.py:/openedx/codejailservice/codejailservice/tutor.py:ro - ../../data/codejail:/openedx/data restart: unless-stopped + depends_on: + - codejail-apparmor-loader + +codejail-apparmor-loader: + image: {{ CODEJAIL_APPARMOR_DOCKER_IMAGE }} + privileged: true + command: + - /usr/bin/loader + - -logtostderr + - -v=2 + - /profiles + volumes: + - ../plugins/codejail/apps/profiles/docker-edx-sandbox:/profiles/docker-edx-sandbox:ro + - /sys:/sys + - /etc/apparmor.d:/etc/apparmor.d diff --git a/tutorcodejail/plugin.py b/tutorcodejail/plugin.py index 5865781..fc7ed55 100644 --- a/tutorcodejail/plugin.py +++ b/tutorcodejail/plugin.py @@ -68,26 +68,6 @@ def get_apparmor_abi(): ] ) -# To add a custom initialization task, create a bash script template under: -# tutorcodejail/templates/codejail/tasks/ -# and then add it to the MY_INIT_TASKS list. Each task is in the format: -# ("", ("", "", "