CR: P16g AppArmor Deployment — Risk & Communications
Risk Assessment
| Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|
Boot parameter change prevents boot |
Low |
High |
Fallback boot entry available; can edit from systemd-boot menu |
Misconfigured profiles break applications |
Medium |
Medium |
Complain mode first (Phase 2), enforce only after baseline established |
Browser bwrap sandbox conflicts with AppArmor |
Medium |
Medium |
Use |
Docker containers fail under AppArmor |
Low |
Medium |
Docker has built-in AppArmor support; test with |
Related
-
INC: P16g No MAC — Incident that triggered this CR
-
INC: Vault Backup SELinux — Related MAC incident on server infrastructure