Skip to content

Add support for container runtimes (podman, docker, etc) (or container-selinux support) #397

@0xC0ncord

Description

@0xC0ncord

Container runtime support is currently missing in refpolicy. An issue was opened at container-selinux to bring the possibility to build it against refpolicy, but doing so presents some problems that need reworking. The idea to make container-selinux compatible with refpolicy was the originally proposed solution, but it may instead be wiser to begin work on a container module in refpolicy itself, as to avoid the many incompatibilities or to avoid rules deemed potentially too permissive in refpolicy, etc.

Either way, I am opening this issue to bring visibility on this, as overall support for container runtimes in refpolicy seems to be reaching high demand.

container-selinux issue: containers/container-selinux#113

Metadata

Metadata

Assignees

No one assigned

    Labels

    ACKThe issue is acknowledged; a change is needed.help wantedExtra attention is neededquestionFurther information is requested

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions