Guest User

Untitled

a guest
Sep 21st, 2020
187
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.13 KB | None | 0 0
  1. (block envoy
  2. (blockinherit container)
  3. (blockinherit restricted_net_container)
  4. (allow process process ( capability ( chown dac_override fsetid fowner mknod net_raw setgid setuid setfcap setpcap net_bind_service sys_chroot kill audit_write )))
  5.  
  6. (allow process http_port_t ( tcp_socket ( name_bind )))
  7. (allow process mysqld_port_t ( tcp_socket ( name_bind )))
  8. (allow process http_port_t ( tcp_socket ( name_bind )))
  9. (allow process user_home_t ( dir ( open read getattr lock search ioctl add_name remove_name write )))
  10. (allow process user_home_t ( file ( getattr read write append ioctl lock map open create )))
  11. (allow process user_home_t ( sock_file ( getattr read write append open )))
  12. (allow process etc_t ( dir ( open read getattr lock search ioctl add_name remove_name write )))
  13. (allow process etc_t ( file ( getattr read write append ioctl lock map open create )))
  14. (allow process etc_t ( sock_file ( getattr read write append open )))
  15.  
  16. (allow process container_runtime_t ( fifo_file ( setattr )))
  17. (allow process unreserved_port_t ( tcp_socket ( name_bind )))
  18. )
  19.  
Add Comment
Please, Sign In to add comment