When using the HA plugin, charon-systemd try to read '@{PROC}/@{pid}/net/ipt_CLUSTERIP/' and to write in files into '@{PROC}/@{pid}/net/ipt_CLUSTERIP/'
So the 2 rules may be append to charon-systemd.apparmor.conf
# Cluster IP
@{PROC}/@{pid}/net/ipt_CLUSTERIP/ r,
@{PROC}/@{pid}/net/ipt_CLUSTERIP/* rw,
When using the HA plugin, charon-systemd try to read '@{PROC} /@{pid} /net/ipt_ CLUSTERIP/ ' and to write in files into '@{PROC} /@{pid} /net/ipt_ CLUSTERIP/ '
So the 2 rules may be append to charon- systemd. apparmor. conf
# Cluster IP /@{pid} /net/ipt_ CLUSTERIP/ r, /@{pid} /net/ipt_ CLUSTERIP/ * rw,
@{PROC}
@{PROC}