diff --git a/doc/source/node_management/kubernetes/figures/CPUFrequencyDefault.png b/doc/source/node_management/kubernetes/figures/CPUFrequencyDefault.png index dac91ced8..be47ad2ba 100644 Binary files a/doc/source/node_management/kubernetes/figures/CPUFrequencyDefault.png and b/doc/source/node_management/kubernetes/figures/CPUFrequencyDefault.png differ diff --git a/doc/source/node_management/kubernetes/figures/pcd1567096217474.png b/doc/source/node_management/kubernetes/figures/pcd1567096217474.png index f25f98f18..3f40bdbc5 100644 Binary files a/doc/source/node_management/kubernetes/figures/pcd1567096217474.png and b/doc/source/node_management/kubernetes/figures/pcd1567096217474.png differ diff --git a/doc/source/node_management/kubernetes/host_inventory/hosts-tab.rst b/doc/source/node_management/kubernetes/host_inventory/hosts-tab.rst index 89e709d94..ca6ebaea5 100644 --- a/doc/source/node_management/kubernetes/host_inventory/hosts-tab.rst +++ b/doc/source/node_management/kubernetes/host_inventory/hosts-tab.rst @@ -171,6 +171,9 @@ A sample **Hosts** tab is illustrated below: the serial console cable is disconnected. The server must support data carrier detect on the serial console port. + - **AppArmor Module**: Choose whether or not to enable Apparmor on + the host. The host needs to be locked before changing this value. + - The **Installation Parameters** tab provides access to installation settings. Changes take effect if the host is re-installed. For more information, see the document that pertains to your |prod| diff --git a/doc/source/node_management/kubernetes/host_inventory/overview-tab.rst b/doc/source/node_management/kubernetes/host_inventory/overview-tab.rst index 48eb0471b..c3a90fbea 100644 --- a/doc/source/node_management/kubernetes/host_inventory/overview-tab.rst +++ b/doc/source/node_management/kubernetes/host_inventory/overview-tab.rst @@ -33,6 +33,8 @@ The following items are included in the summary: - location, as entered by the operator using the Edit Host window (see :ref:`Hosts Tab `). +- AppArmor's value on this host, which can be enabled or disabled. + - time stamps of when the host was created and last updated - the host's state diff --git a/doc/source/security/kubernetes/enable-disable-apparmor-on-a-host-using-horizon-a318ab726396.rst b/doc/source/security/kubernetes/enable-disable-apparmor-on-a-host-using-horizon-a318ab726396.rst new file mode 100644 index 000000000..55af8d052 --- /dev/null +++ b/doc/source/security/kubernetes/enable-disable-apparmor-on-a-host-using-horizon-a318ab726396.rst @@ -0,0 +1,24 @@ +.. _enable-disable-apparmor-on-a-host-using-horizon-a318ab726396: + +----------------------------------------------- +Enable/Disable AppArmor on a Host using Horizon +----------------------------------------------- + +To enable or disable AppArmor on the host using Horizon: + +#. Lock the host. + + .. figure:: figures/worker-hosts-2023-3-20_1-46-22.png + :width: 800 + + .. figure:: figures/confirm-lock-host-2023-3-20_1-55-28.png + +#. Click on Edit Host button. On the "Host Info" tab, enable or disable the + AppArmor Module and finally click on "Save". + + .. figure:: figures/edit-host-2023-3-20_1-54-13.png + +#. Unlock the host. + + .. figure:: figures/display-item-2023-3-20_1-58-33.png + :width: 800 diff --git a/doc/source/security/kubernetes/figures/confirm-lock-host-2023-3-20_1-55-28.png b/doc/source/security/kubernetes/figures/confirm-lock-host-2023-3-20_1-55-28.png new file mode 100644 index 000000000..97c00682c Binary files /dev/null and b/doc/source/security/kubernetes/figures/confirm-lock-host-2023-3-20_1-55-28.png differ diff --git a/doc/source/security/kubernetes/figures/display-item-2023-3-20_1-58-33.png b/doc/source/security/kubernetes/figures/display-item-2023-3-20_1-58-33.png new file mode 100644 index 000000000..094d00171 Binary files /dev/null and b/doc/source/security/kubernetes/figures/display-item-2023-3-20_1-58-33.png differ diff --git a/doc/source/security/kubernetes/figures/edit-host-2023-3-20_1-54-13.png b/doc/source/security/kubernetes/figures/edit-host-2023-3-20_1-54-13.png new file mode 100644 index 000000000..5962a53ff Binary files /dev/null and b/doc/source/security/kubernetes/figures/edit-host-2023-3-20_1-54-13.png differ diff --git a/doc/source/security/kubernetes/figures/worker-hosts-2023-3-20_1-46-22.png b/doc/source/security/kubernetes/figures/worker-hosts-2023-3-20_1-46-22.png new file mode 100644 index 000000000..441aba2af Binary files /dev/null and b/doc/source/security/kubernetes/figures/worker-hosts-2023-3-20_1-46-22.png differ diff --git a/doc/source/security/kubernetes/index-security-kub-81153c1254c3.rst b/doc/source/security/kubernetes/index-security-kub-81153c1254c3.rst index d471f3ed9..2fbb2afd4 100644 --- a/doc/source/security/kubernetes/index-security-kub-81153c1254c3.rst +++ b/doc/source/security/kubernetes/index-security-kub-81153c1254c3.rst @@ -198,6 +198,7 @@ AppArmor about-apparmor-ebdab8f1ed87 enable-disable-apparmor-on-a-host-63a7a184d310 + enable-disable-apparmor-on-a-host-using-horizon-a318ab726396 install-security-profiles-operator-1b2f9a0f0108 profile-management-a8df19c86a5d apply-a-profile-to-a-pod-c2fa4d958dec