From c3d382a703866e14c7f728d3738d7521dc8b6096 Mon Sep 17 00:00:00 2001 From: Shishir Mahajan Date: Mon, 31 Aug 2020 16:14:52 -0700 Subject: [PATCH] More updates. --- README.md | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/README.md b/README.md index d7cc110..f8bd262 100644 --- a/README.md +++ b/README.md @@ -113,6 +113,18 @@ mounts = [ } ] ``` +**Custom seccomp profile example** +The default `docker` seccomp profile found [`here`](https://github.com/moby/moby/blob/master/profiles/seccomp/default.json) +can be downloaded, and modified (by removing/adding syscalls) to create a custom seccomp profile. +The custom seccomp profile can then be saved under `/opt/seccomp/seccomp.json` on the Nomad client nodes. + +A nomad job can be launched using this custom seccomp profile. +``` +config { + seccomp = true + seccomp_profile = "/opt/seccomp/seccomp.json" +} +``` ## Networking