Sorry for the delay in writing back to you, I've been on a mix of PTO and sick leave the last couple of weeks...
I've prepared a MP to actually add the relevant config snippet (`/dev/console rw,`) into `/etc/apparmor.d/usr.sbin.rsyslogd` in our cloud bootstrap, tested it and it all seems well.
However, John (on our team) made a good point that the AppArmor profile may not have this snippet by design - I understand you guys in Security would probably have the most oversight into this currently so before I merge the code do you see any issues with us forcing the profile to accept rw access to /dev/console? If so that's cool, I just want to check seeing as this profile is only now being enabled in Lunar :)
Hey Georgia!
Sorry for the delay in writing back to you, I've been on a mix of PTO and sick leave the last couple of weeks...
I've prepared a MP to actually add the relevant config snippet (`/dev/console rw,`) into `/etc/apparmor. d/usr.sbin. rsyslogd` in our cloud bootstrap, tested it and it all seems well.
However, John (on our team) made a good point that the AppArmor profile may not have this snippet by design - I understand you guys in Security would probably have the most oversight into this currently so before I merge the code do you see any issues with us forcing the profile to accept rw access to /dev/console? If so that's cool, I just want to check seeing as this profile is only now being enabled in Lunar :)