Choose a place for the virtualenv, call it Create a virtualenv: virtualenv Install the sandbox requirements Edit an AppArmor profile: /bin/python { ... } Parse the profiles $ apparmor_parser $ aaenforce /bin/python