@@ -59,15 +59,19 @@ jobs:
5959 fail-fast : false
6060 matrix :
6161 run :
62- - name : critest / conmon / runc / amd64
63- arch : amd64
64- runner : ubuntu-latest
65- defaultRuntime : runc
66- runtimeType : oci
67- critest : 1
68- userns : 0
69- jobs : 1
70- timeout : 20
62+ # TODO: Re-enable runc integration tests when mitigation is found
63+ # Disabled due to AppArmor issue in nested environments
64+ # See: https://github.com/cri-o/cri-o/issues/9573
65+ # See: https://github.com/opencontainers/runc/issues/4968
66+ # - name: critest / conmon / runc / amd64
67+ # arch: amd64
68+ # runner: ubuntu-latest
69+ # defaultRuntime: runc
70+ # runtimeType: oci
71+ # critest: 1
72+ # userns: 0
73+ # jobs: 1
74+ # timeout: 20
7175
7276 - name : critest / conmon / crun / amd64
7377 arch : amd64
@@ -79,15 +83,15 @@ jobs:
7983 jobs : 1
8084 timeout : 20
8185
82- - name : critest / conmon-rs / runc / amd64
83- arch : amd64
84- runner : ubuntu-latest
85- defaultRuntime : runc
86- runtimeType : pod
87- critest : 1
88- userns : 0
89- jobs : 1
90- timeout : 20
86+ # - name: critest / conmon-rs / runc / amd64
87+ # arch: amd64
88+ # runner: ubuntu-latest
89+ # defaultRuntime: runc
90+ # runtimeType: pod
91+ # critest: 1
92+ # userns: 0
93+ # jobs: 1
94+ # timeout: 20
9195
9296 - name : critest / conmon-rs / crun / amd64
9397 arch : amd64
@@ -99,15 +103,15 @@ jobs:
99103 jobs : 1
100104 timeout : 20
101105
102- - name : critest / conmon / runc / arm64
103- arch : arm64
104- runner : ubuntu-24.04-arm
105- defaultRuntime : runc
106- runtimeType : oci
107- critest : 1
108- userns : 0
109- jobs : 1
110- timeout : 20
106+ # - name: critest / conmon / runc / arm64
107+ # arch: arm64
108+ # runner: ubuntu-24.04-arm
109+ # defaultRuntime: runc
110+ # runtimeType: oci
111+ # critest: 1
112+ # userns: 0
113+ # jobs: 1
114+ # timeout: 20
111115
112116 - name : critest / conmon / crun / arm64
113117 arch : arm64
@@ -119,15 +123,15 @@ jobs:
119123 jobs : 1
120124 timeout : 20
121125
122- - name : critest / conmon-rs / runc / arm64
123- arch : arm64
124- runner : ubuntu-24.04-arm
125- defaultRuntime : runc
126- runtimeType : pod
127- critest : 1
128- userns : 0
129- jobs : 1
130- timeout : 20
126+ # - name: critest / conmon-rs / runc / arm64
127+ # arch: arm64
128+ # runner: ubuntu-24.04-arm
129+ # defaultRuntime: runc
130+ # runtimeType: pod
131+ # critest: 1
132+ # userns: 0
133+ # jobs: 1
134+ # timeout: 20
131135
132136 - name : critest / conmon-rs / crun / arm64
133137 arch : arm64
@@ -139,15 +143,15 @@ jobs:
139143 jobs : 1
140144 timeout : 20
141145
142- - name : integration / conmon / runc / amd64
143- arch : amd64
144- runner : ubuntu-latest
145- defaultRuntime : runc
146- runtimeType : oci
147- critest : 0
148- userns : 0
149- jobs : 2
150- timeout : 120
146+ # - name: integration / conmon / runc / amd64
147+ # arch: amd64
148+ # runner: ubuntu-latest
149+ # defaultRuntime: runc
150+ # runtimeType: oci
151+ # critest: 0
152+ # userns: 0
153+ # jobs: 2
154+ # timeout: 120
151155
152156 - name : integration / conmon / crun / amd64
153157 arch : amd64
@@ -159,25 +163,25 @@ jobs:
159163 jobs : 2
160164 timeout : 120
161165
162- - name : integration / conmon-rs / runc / amd64
163- arch : amd64
164- runner : ubuntu-latest
165- defaultRuntime : runc
166- runtimeType : pod
167- critest : 0
168- userns : 0
169- jobs : 2
170- timeout : 120
166+ # - name: integration / conmon-rs / runc / amd64
167+ # arch: amd64
168+ # runner: ubuntu-latest
169+ # defaultRuntime: runc
170+ # runtimeType: pod
171+ # critest: 0
172+ # userns: 0
173+ # jobs: 2
174+ # timeout: 120
171175
172- - name : integration / userns / runc / amd64
173- arch : amd64
174- runner : ubuntu-latest
175- defaultRuntime : runc
176- runtimeType : oci
177- critest : 0
178- userns : 1
179- jobs : 2
180- timeout : 120
176+ # - name: integration / userns / runc / amd64
177+ # arch: amd64
178+ # runner: ubuntu-latest
179+ # defaultRuntime: runc
180+ # runtimeType: oci
181+ # critest: 0
182+ # userns: 1
183+ # jobs: 2
184+ # timeout: 120
181185 env :
182186 GOCOVERDIR : ${{ github.workspace }}/build/coverage/bats # It's used to make coverage profiles. https://go.dev/doc/build-cover
183187 name : ${{ matrix.run.name }}
0 commit comments