all
Sep 4, 2026
Kernel-level restrictions for pods: load an AppArmor profile on the node, point seccomp at RuntimeDefault or a localhost JSON, then test the deny.