Skip to content

Commit

Permalink
Fix file context for the default local-path storage class path, fixes k…
Browse files Browse the repository at this point in the history
  • Loading branch information
cruizer committed Jun 12, 2020
1 parent f0bfc40 commit 78330a7
Show file tree
Hide file tree
Showing 2 changed files with 6 additions and 0 deletions.
1 change: 1 addition & 0 deletions k3s.fc
Expand Up @@ -6,6 +6,7 @@
/var/lib/cni(/.*)? gen_context(system_u:object_r:container_var_lib_t,s0)
/var/lib/rancher/k3s(/.*)? gen_context(system_u:object_r:container_var_lib_t,s0)
/var/lib/rancher/k3s/data(/.*)? gen_context(system_u:object_r:container_runtime_exec_t,s0)
/var/lib/rancher/k3s/storage(/.*)? gen_context(system_u:object_r:container_file_t,s0)
#/var/lib/rancher/k3s/agent/containerd/[^/]*/snapshots(/.*)? gen_context(system_u:object_r:container_share_t,s0)
/var/lib/rancher/k3s/agent/containerd/[^/]*/snapshots -d gen_context(system_u:object_r:container_share_t,s0)
/var/lib/rancher/k3s/agent/containerd/[^/]*/snapshots/[^/]* -d gen_context(system_u:object_r:container_share_t,s0)
Expand Down
5 changes: 5 additions & 0 deletions k3s.te
Expand Up @@ -5,6 +5,11 @@ gen_require(`
')
filetrans_pattern(container_runtime_t, container_var_lib_t, container_runtime_exec_t, dir, "data")

gen_require(`
type container_runtime_t, container_var_lib_t, container_file_t;
')
filetrans_pattern(container_runtime_t, container_var_lib_t, container_file_t, dir, "storage")

gen_require(`
type container_runtime_t, container_var_lib_t, container_share_t;
')
Expand Down

0 comments on commit 78330a7

Please sign in to comment.