#include profile photoprism flags=(attach_disconnected,mediate_deleted) { #include capability, file, signal, mount, umount, remount, network udp, network tcp, network dgram, network stream, network inet, network inet6, network netlink raw, network unix dgram, capability setgid, capability setuid, capability dac_override, capability sys_admin, capability dac_read_search, capability sys_rawio, # S6-Overlay /init ix, /run/{s6,s6-rc*,service}/** ix, /package/** ix, /command/** ix, /run/{,**} rwk, /dev/tty rw, /bin/** ix, /usr/bin/** ix, /usr/lib/bashio/** ix, /etc/s6/** rix, /run/s6/** rix, /etc/services.d/** rwix, /etc/cont-init.d/** rwix, /etc/cont-finish.d/** rwix, /init rix, /var/run/** mrwkl, /var/run/ mrwkl, /dev/i2c-1 mrwkl, # Files required /dev/fuse mrwkl, /dev/sda1 mrwkl, /dev/sdb1 mrwkl, /dev/nvme0 mrwkl, /dev/nvme1 mrwkl, /dev/mmcblk0p1 mrwkl, /dev/* mrwkl, /tmp/** mrkwl, /dev/sda mrwkl, /dev/sdb mrwkl, /dev/sdc mrwkl, /dev/sdd mrwkl, /dev/sde mrwkl, /dev/sdf mrwkl, /dev/sdg mrwkl, /dev/nvme0 mrwkl, /dev/nvme1 mrwkl, /dev/nvme2 mrwkl, /dev/nvme3 mrwkl, /dev/nvme4 mrwkl, # Data access /data/** rw, # suppress ptrace denials when using 'docker ps' or using 'ps' inside a container ptrace (trace,read) peer=docker-default, # docker daemon confinement requires explict allow rule for signal signal (receive) set=(kill,term) peer=/usr/bin/docker, }