To add, the kubectl command above is executed from the kubernetes node and not t . . .

SidB:
To add, the kubectl command above is executed from the kubernetes node and not the client. Hope that is not going to make any difference.

unnivkn:
you have to start apparmor from the node, where your pod is running. k get po -owide