Skip to content

Commit dcd2dd4

Browse files
authored
Update SELinux standards (#27653)
* Update SELinux standards * address feedback
1 parent 89e642d commit dcd2dd4

File tree

1 file changed

+19
-7
lines changed

1 file changed

+19
-7
lines changed

content/en/docs/concepts/security/pod-security-standards.md

Lines changed: 19 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -113,7 +113,7 @@ enforced/disallowed:
113113
</td>
114114
</tr>
115115
<tr>
116-
<td>AppArmor <em>(optional)</em></td>
116+
<td>AppArmor</td>
117117
<td>
118118
On supported hosts, the 'runtime/default' AppArmor profile is applied by default.
119119
The baseline policy should prevent overriding or disabling the default AppArmor
@@ -124,14 +124,26 @@ enforced/disallowed:
124124
</td>
125125
</tr>
126126
<tr>
127-
<td>SELinux <em>(optional)</em></td>
127+
<td>SELinux</td>
128128
<td>
129-
Setting custom SELinux options should be disallowed.<br>
129+
Setting the SELinux type is restricted, and setting a custom SELinux user or role option is forbidden.<br>
130130
<br><b>Restricted Fields:</b><br>
131-
spec.securityContext.seLinuxOptions<br>
132-
spec.containers[*].securityContext.seLinuxOptions<br>
133-
spec.initContainers[*].securityContext.seLinuxOptions<br>
134-
<br><b>Allowed Values:</b> undefined/nil<br>
131+
spec.securityContext.seLinuxOptions.type<br>
132+
spec.containers[*].securityContext.seLinuxOptions.type<br>
133+
spec.initContainers[*].securityContext.seLinuxOptions.type<br>
134+
<br><b>Allowed Values:</b><br>
135+
undefined/empty<br>
136+
container_t<br>
137+
container_init_t<br>
138+
container_kvm_t<br>
139+
<br><b>Restricted Fields:</b><br>
140+
spec.securityContext.seLinuxOptions.user<br>
141+
spec.containers[*].securityContext.seLinuxOptions.user<br>
142+
spec.initContainers[*].securityContext.seLinuxOptions.user<br>
143+
spec.securityContext.seLinuxOptions.role<br>
144+
spec.containers[*].securityContext.seLinuxOptions.role<br>
145+
spec.initContainers[*].securityContext.seLinuxOptions.role<br>
146+
<br><b>Allowed Values:</b> undefined/empty<br>
135147
</td>
136148
</tr>
137149
<tr>

0 commit comments

Comments
 (0)