Making AOSP’s nsjail Work with AppArmor (Ubuntu 24.04)
TL;DR On Ubuntu 24.04 (kernel 6.8) with kernel.apparmor_restrict_unprivileged_userns=1, our AOSP 16 (also applicable to 15 and similar versions) builds showed:
TL;DR On Ubuntu 24.04 (kernel 6.8) with kernel.apparmor_restrict_unprivileged_userns=1, our AOSP 16 (also applicable to 15 and similar versions) builds showed:
TL;DR If your AOSP build fails with: it almost always means your system is blocking unprivileged user namespaces under AppArmor.
— THIS GUIDE ERASES THE ENTIRE TARGET DISK — Data-destructive warning: The steps below wipe the whole disk (wipefs -a,
Why use Nexus as a Docker Registry? If you already run Sonatype Nexus and don’t want to stand up Harbor,
Overview Part A — Install Nexus 1. Become root 2. Create service user & base folders 3. Download & extract
TL;DR: This upgrades Harbor 2.13.1 → 2.14.0 for the exact setup from my previous guide:Install Harbor 2.13.1 on Ubuntu 24.04
Goal: grow /var/lib/libvirt/images/rbe-b.qcow2 offline on the host, then expand LVM inside the Ubuntu 24.04 guest. TL;DR (commands only) Host (VM
Topology What you get TL;DR Build the five binaries with Bazelisk, create storage/worker file pools, drop the Jsonnet files under
Goal: native install of phpLDAPadmin v2 (2.3.5) under /opt/phpLDAPadmin, served by Nginx + PHP-FPM 8.4, connecting to LDAP/LDAPS. Node is
(Build from source • MITM with a dedicated Squid MITM Root CA (self-signed) • Broad caching • Run as proxy