Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[RFE] SELinux custom policies #1592

Open
mnbro opened this issue Nov 28, 2024 · 1 comment
Open

[RFE] SELinux custom policies #1592

mnbro opened this issue Nov 28, 2024 · 1 comment
Labels
area/selinux Issues related to SELinux kind/feature A feature request

Comments

@mnbro
Copy link

mnbro commented Nov 28, 2024

Is there a milestone for implementing SELinux custom policies for Flatcar Linux?

I saw some issues caused by this and I also see some stalled/unclear next steps like in #598 pending for a couple of years.

@tormath1
Copy link
Contributor

Flatcar is shipped with policies from the refpolicy repository (similar to Gentoo) with the current policies:

sec-policy/selinux-base-2.20240226-r2::portage-stable
sec-policy/selinux-base-policy-2.20240226-r2::portage-stable
sec-policy/selinux-container-2.20240226-r2::portage-stable
sec-policy/selinux-dbus-2.20240226-r2::portage-stable
sec-policy/selinux-policykit-2.20240226-r2::portage-stable
sec-policy/selinux-sssd-2.20240226-r2::portage-stable
sec-policy/selinux-unconfined-2.20240226-r2::portage-stable

At this moment, I think it might be possible to load custom policies on Flatcar (via Ignition) but for projects like rke2-selinux it's a bit more complex as those policies rely on containers-selinux which diverges from the refpolicy container implementation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/selinux Issues related to SELinux kind/feature A feature request
Projects
Status: 📝 Needs Triage
Development

No branches or pull requests

2 participants