k3s-io / k3s-selinux

SELinux policy for k3s
Apache License 2.0
66 stars 20 forks source link

k3s-root: reduced executable privileges #26

Closed dweomer closed 2 years ago

dweomer commented 2 years ago

Addresses k3s-io/k3s#4562 Addresses k3s-io/k3s#4564 Addresses k3s-io/k3s#4600 Addresses k3s-io/k3s#4601

Address container_runtime_exec_t applied to too many executables. Introduce k3s_data_t, k3s_lock_t, and k3s_root_t types:


I should stress: this is effectively a complete policy re-write for k3s.

dweomer commented 2 years ago

This will require a claw-back of the k3s-specific file-context entries in upstream container-selinux.