Skip to content

Commit d2a01fb

Browse files
authored
Merge pull request #1257 from kube-hetzner/add/selinux-rules
Added Selinux Rules
2 parents fbfa469 + ff05af8 commit d2a01fb

File tree

1 file changed

+7
-1
lines changed

1 file changed

+7
-1
lines changed

locals.tf

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -793,7 +793,7 @@ EOF
793793
type kernel_t, bin_t, kernel_generic_helper_t, iscsid_t, iscsid_exec_t, var_run_t,
794794
init_t, unlabeled_t, systemd_logind_t, systemd_hostnamed_t, container_t,
795795
cert_t, container_var_lib_t, etc_t, usr_t, container_file_t, container_log_t,
796-
container_share_t, container_runtime_exec_t, container_runtime_t, var_log_t, proc_t, io_uring_t;
796+
container_share_t, container_runtime_exec_t, container_runtime_t, var_log_t, proc_t, io_uring_t, fuse_device_t, http_port_t;
797797
class key { read view };
798798
class file { open read execute execute_no_trans create link lock rename write append setattr unlink getattr watch };
799799
class sock_file { watch write create unlink };
@@ -806,6 +806,8 @@ EOF
806806
class bpf map_create;
807807
class io_uring sqpoll;
808808
class anon_inode create;
809+
class tcp_socket name_connect;
810+
class chr_file { open read write };
809811
}
810812
811813
#============= kernel_generic_helper_t ==============
@@ -822,6 +824,9 @@ EOF
822824
allow init_t unlabeled_t:dir { add_name remove_name rmdir };
823825
allow init_t unlabeled_t:lnk_file create;
824826
allow init_t container_t:file { open read };
827+
allow init_t container_file_t:file { execute execute_no_trans };
828+
allow init_t fuse_device_t:chr_file { open read write };
829+
allow init_t http_port_t:tcp_socket name_connect;
825830
826831
#============= systemd_logind_t ==============
827832
allow systemd_logind_t unlabeled_t:dir search;
@@ -861,6 +866,7 @@ EOF
861866
allow container_t self:bpf map_create;
862867
allow container_t io_uring_t:anon_inode create;
863868
allow container_t self:io_uring sqpoll;
869+
allow container_t io_uring_t:anon_inode { create map read write };
864870
865871
# Create the k3s registries file if needed
866872
%{if var.k3s_registries != ""}

0 commit comments

Comments
 (0)