1 minute about AppArmor
AppArmor is a mandatory access control (MAC) Security Module that restricts the capabilities and permissions of a containerised workload. The permissions are...
Hannes Ullman
bifrost security

bifrost’s service leverages AppArmor, a Linux Security Module, to protect applications. But how does AppArmor work to protect your software?
Let’s take a closer look!
AppArmor is a mandatory access control (MAC) Security Module that restricts the capabilities and permissions of a containerised workload. The permissions are controlled through individual security profiles, which allow or disallow syscall actions. Restrictions could include network access, writing, loading, and reading files, as well as other fine-grained capabilities.
Deploying AppArmor tailored to the workload’s desired behaviour can prevent known and undiscovered vulnerabilities from being exploited. This reduces the risk of internal and external threats.
Three reasons to use AppArmor:
🔒 Enhanced Security
Limits what a container can do, reducing the attack surface of each workload.
🧩 Isolation
Provide a robust sandboxing fence around the container, making it more difficult for attackers to move laterally.
⚖️ Compliance
Helps meet security compliance requirements by enforcing strict controls,
Does your organisation leverage AppArmor or similar LSMs?
Tags
Do you know what's exploitable in your environment?
Deploy bifrost via Helm and it reads how every container is actually deployed, cutting your CVE list before a single line of code changes.