I'd like to minimize the permissions of the process running the DCGM containers using an AppArmor profile. Does NVIDIA have a recommended AppArmor profile that can be used for this purpose to minimize security concerns for running DCGM (particularly on Kubernetes)?
Hello,
I'd like to run DCGM as a Daemonset in Kubernetes.
However, I notice it needs
SYS_ADMIN
privileges.I'd like to minimize the permissions of the process running the DCGM containers using an AppArmor profile. Does NVIDIA have a recommended AppArmor profile that can be used for this purpose to minimize security concerns for running DCGM (particularly on Kubernetes)?
Thanks!