We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 39dd703 commit 2927dacCopy full SHA for 2927dac
logrotate/selinux-policy/easyengine-logrotate.te
@@ -0,0 +1,19 @@
1
+module easyengine-logrotate 1.0;
2
+
3
+require {
4
+ type logrotate_t;
5
+ type container_runtime_exec_t;
6
+ type usr_t;
7
+ class file { read open getattr append execute execute_no_trans };
8
+}
9
10
+#============= logrotate_t ==============
11
12
+# 1. Quyền đọc docker inspect
13
+allow logrotate_t container_runtime_exec_t:file { read open getattr };
14
15
+# 2. Quyền thực thi docker compose
16
+allow logrotate_t container_runtime_exec_t:file { execute execute_no_trans };
17
18
+# 3. Quyền ghi append vào log file (giữ nguyên usr_t)
19
+allow logrotate_t usr_t:file append;
0 commit comments