Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[RFE] SELinux custom policies #1592

Open
mnbro opened this issue Nov 28, 2024 · 1 comment
Open

[RFE] SELinux custom policies #1592

mnbro opened this issue Nov 28, 2024 · 1 comment
Labels
area/selinux Issues related to SELinux kind/feature A feature request

Comments

@mnbro
Copy link

mnbro commented Nov 28, 2024

Is there a milestone for implementing SELinux custom policies for Flatcar Linux?

I saw some issues caused by this and I also see some stalled/unclear next steps like in #598 pending for a couple of years.

@tormath1
Copy link
Contributor

Flatcar is shipped with policies from the refpolicy repository (similar to Gentoo) with the current policies:

sec-policy/selinux-base-2.20240226-r2::portage-stable
sec-policy/selinux-base-policy-2.20240226-r2::portage-stable
sec-policy/selinux-container-2.20240226-r2::portage-stable
sec-policy/selinux-dbus-2.20240226-r2::portage-stable
sec-policy/selinux-policykit-2.20240226-r2::portage-stable
sec-policy/selinux-sssd-2.20240226-r2::portage-stable
sec-policy/selinux-unconfined-2.20240226-r2::portage-stable

At this moment, I think it might be possible to load custom policies on Flatcar (via Ignition) but for projects like rke2-selinux it's a bit more complex as those policies rely on containers-selinux which diverges from the refpolicy container implementation.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
area/selinux Issues related to SELinux kind/feature A feature request
Projects
Status: 📝 Needs Triage
Development

No branches or pull requests

2 participants