Container SELinux Customization
Lukas Vrabec <[email protected]>
| Newsgroups | gmane.linux.redhat.fedora.selinux |
|---|---|
| Organization | Red Hat, Inc. |
| Message-ID | <[email protected]> |
Hi All, Back in April, I announced that we work on POC how we could automatically create SELinux security policies for different kind of containers. The original concept is described here: https://github.com/fedora-selinux/container-selinux-customization Long story short, using pre-defined policy blocks, system administrators would be able to simply create customized SELinux policies for containers. The goal is to create a standalone tool which would be able to do it. And we a have a prototype now. It's called "udica" and you can find it here: https://github.com/containers/udica In this repo you can find sources and examples how to create SELinux policy for your containers. I also created copr repository for Fedora 29 and Rawhide: https://copr.fedorainfracloud.org/coprs/lvrabec/udica/ Feedback is welcome. Any issues please report in github issues tracking system. Thanks, Lukas. -- Lukas Vrabec Software Engineer, Security Technologies Red Hat, Inc. _______________________________________________ selinux mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
signature.asc
(application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEE3wrP3ArXoyYgAS7LRyAaxC8pzgYFAluncukACgkQRyAaxC8p zgahqAf+I8EmVc4m+PWXCNKolKWu/ldmZVn04v6fB0nchkACZXY8+6ZtooFV2kD1 /Pf2MF3IhBRjg7OdAL9fLa0zLjkaTUOJ6g0NprxB1q1DXWOYjueGsHRL+PstUhmg oabtN80mdD4nTKFGB+YShTJr5GIkEDCJ7S1eHBiZh3j93eiYdCfvcfiZ0WWTA0vN 7lWcEC4qJXF0ujBjMXoh2qbSXru3gHH1uAEgzFnMTwja7Vul13w1kUUz2O+XBO1t CefY5LU+QpiDuNwoQMEURuMpYvVVRHxOpnl4Up/exaYsvLFytgUnch9pSw9jCvMJ R4T12Rc2DAhtUeF3QVmZ2J7v9DumwA== =0/4N -----END PGP SIGNATURE-----