aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorKenton Groombridge <concord@gentoo.org>2024-02-10 21:10:38 -0500
committerKenton Groombridge <concord@gentoo.org>2024-03-01 12:04:30 -0500
commit8408521b92f2bd41a35f10df1b7d41a4b61f52fe (patch)
treec698150d9a17241c68dbad45ded1eb71b168e294
parentkernel: dontaudit read fixed disk devices (diff)
downloadhardened-refpolicy-8408521b92f2bd41a35f10df1b7d41a4b61f52fe.tar.gz
hardened-refpolicy-8408521b92f2bd41a35f10df1b7d41a4b61f52fe.tar.bz2
hardened-refpolicy-8408521b92f2bd41a35f10df1b7d41a4b61f52fe.zip
container: add filecons for rook-ceph
Signed-off-by: Kenton Groombridge <concord@gentoo.org>
-rw-r--r--policy/modules/services/container.fc3
1 files changed, 3 insertions, 0 deletions
diff --git a/policy/modules/services/container.fc b/policy/modules/services/container.fc
index 9871812de..f98e68ba0 100644
--- a/policy/modules/services/container.fc
+++ b/policy/modules/services/container.fc
@@ -103,6 +103,9 @@ HOME_DIR/\.docker(/.*)? gen_context(system_u:object_r:container_conf_home_t,s0)
/var/lib/etcd(/.*)? gen_context(system_u:object_r:container_file_t,s0)
/var/lib/kube-proxy(/.*)? gen_context(system_u:object_r:container_file_t,s0)
+/var/lib/rook(/.*)? gen_context(system_u:object_r:container_file_t,s0)
+/var/lib/rook/rook-ceph/[^/]+/[^/]+/block -b gen_context(system_u:object_r:container_device_t,s0)
+
/var/local-path-provisioner(/.*)? gen_context(system_u:object_r:container_file_t,s0)
/var/log/containerd(/.*)? gen_context(system_u:object_r:container_log_t,s0)