Skip to content

Commit 2927dac

Browse files
authored
Create easyengine-logrotate.te
1 parent 39dd703 commit 2927dac

File tree

1 file changed

+19
-0
lines changed

1 file changed

+19
-0
lines changed
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
module easyengine-logrotate 1.0;
2+
3+
require {
4+
type logrotate_t;
5+
type container_runtime_exec_t;
6+
type usr_t;
7+
class file { read open getattr append execute execute_no_trans };
8+
}
9+
10+
#============= logrotate_t ==============
11+
12+
# 1. Quyền đọc docker inspect
13+
allow logrotate_t container_runtime_exec_t:file { read open getattr };
14+
15+
# 2. Quyền thực thi docker compose
16+
allow logrotate_t container_runtime_exec_t:file { execute execute_no_trans };
17+
18+
# 3. Quyền ghi append vào log file (giữ nguyên usr_t)
19+
allow logrotate_t usr_t:file append;

0 commit comments

Comments
 (0)