You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
@@ -138,8 +138,6 @@ The linux kernel IMA namespace support is based on user namespaces. Therefore, t
Should we enable IMA namespaces by default when enabling user namespaces?
There will be a CRI API change which will allow the pod to use IMA namespaces and specify the namespace policy.
### Linux kernel
IMA is only available in Linux hosts and Linux containers. Unfortunately, IMA is not a separate namespace, which is needed in order to isolate it and be used inside containers. Upcoming kernel patches should add support for IMA namespaces.