Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- (block envoy
- (blockinherit container)
- (blockinherit restricted_net_container)
- (allow process process ( capability ( chown dac_override fsetid fowner mknod net_raw setgid setuid setfcap setpcap net_bind_service sys_chroot kill audit_write )))
- (allow process http_port_t ( tcp_socket ( name_bind )))
- (allow process mysqld_port_t ( tcp_socket ( name_bind )))
- (allow process http_port_t ( tcp_socket ( name_bind )))
- (allow process user_home_t ( dir ( open read getattr lock search ioctl add_name remove_name write )))
- (allow process user_home_t ( file ( getattr read write append ioctl lock map open create )))
- (allow process user_home_t ( sock_file ( getattr read write append open )))
- (allow process etc_t ( dir ( open read getattr lock search ioctl add_name remove_name write )))
- (allow process etc_t ( file ( getattr read write append ioctl lock map open create )))
- (allow process etc_t ( sock_file ( getattr read write append open )))
- (allow process container_runtime_t ( fifo_file ( setattr )))
- (allow process unreserved_port_t ( tcp_socket ( name_bind )))
- )
Add Comment
Please, Sign In to add comment