Skip to content

Commit

Permalink
Add policy for kata containers
Browse files Browse the repository at this point in the history
Signed-off-by: Daniel J Walsh <[email protected]>
  • Loading branch information
rhatdan committed Mar 20, 2020
1 parent 5624558 commit b321ea4
Showing 1 changed file with 13 additions and 1 deletion.
14 changes: 13 additions & 1 deletion container.te
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
policy_module(container, 2.124.0)
policy_module(container, 2.125.0)
gen_require(`
class passwd rootok;
')
Expand Down Expand Up @@ -452,6 +452,7 @@ tunable_policy(`virt_use_samba',`
gen_require(`
type cephfs_t;
')

tunable_policy(`container_use_cephfs',`
manage_files_pattern(container_domain, cephfs_t, cephfs_t)
manage_lnk_files_pattern(container_domain, cephfs_t, cephfs_t)
Expand Down Expand Up @@ -1041,3 +1042,14 @@ dontaudit container_domain device_node:chr_file setattr;
dontaudit container_domain sysctl_type:file write;

allow container_t proc_t:filesystem remount;

# Container kvm - Policy for running kata containers
container_domain_template(container_kvm)
typeattribute container_kvm_t container_net_domain;

dev_rw_kvm(container_kvm_t)

dev_read_sysfs(container_kvm_t)
dev_getattr_mtrr_dev(container_kvm_t)
dev_read_rand(container_kvm_t)
dev_read_urand(container_kvm_t)

0 comments on commit b321ea4

Please sign in to comment.