The open-source application container engine.
false
Determine whether container can connect to all TCP ports.
false
Allow sandbox containers to manage cgroup (systemd)
false
Determine whether container can use ceph file system
false
Allow containers to use any device volume mounted into container
false
Determine whether container can use ecrypt file system
false
Determine whether sshd can launch container engines
All of the rules required to administrate an container environment
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to append to container files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute container_auth_exec_t in the container_auth domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute container_auth in the caller domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Connect to container_auth over a unix stream socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute container lib directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to execute container shared files in the caller domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create a file type used for container files.
Parameter: | Description: |
---|---|
script_file |
Type to be used for an container file. |
Allow domain to create container content
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute container in the container domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute kubelet_exec_t in the kubelet_t domain
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
role |
Role allowed access. |
Connect to kubelet over a unix stream socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create objects in a container var lib directory with an automatic type transition to a specified private type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
private_type |
The type of the object to create. |
object_class |
The class of the object to be created. |
name |
The name of the object being created. |
Manage container config files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage container directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage container files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage container lib directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage container lib files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage container share dirs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage container share files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read container lib files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read container PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read container share files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read the process state of container runtime
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute container in the container domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Allow any container_runtime_exec_t to be an entrypoint of this domain
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute container in the caller domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Read container runtime tmpfs files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute container runtime in the container runtime domain
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
role |
Role allowed access. |
container domain typebounds calling domain.
Parameter: | Description: |
---|---|
domain |
Domain to be typebound. |
Read and write container shared memory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search container lib directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read the process state of spc containers
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write a spc_t unnamed pipe.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Connect to SPC containers over a unix stream socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Connect to container over a unix stream socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute container server in the container domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Read and write the container pty type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Summary is missing!
Parameter: | Description: |
---|---|
? |
Parameter descriptions are missing! |
Summary is missing!
Parameter: | Description: |
---|---|
? |
Parameter descriptions are missing! |
Summary is missing!
Parameter: | Description: |
---|---|
? |
Parameter descriptions are missing! |
Summary is missing!
Parameter: | Description: |
---|---|
? |
Parameter descriptions are missing! |
Summary is missing!
Parameter: | Description: |
---|---|
? |
Parameter descriptions are missing! |
Summary is missing!
Parameter: | Description: |
---|---|
? |
Parameter descriptions are missing! |
Summary is missing!
Parameter: | Description: |
---|---|
? |
Parameter descriptions are missing! |
Summary is missing!
Parameter: | Description: |
---|---|
? |
Parameter descriptions are missing! |
Summary is missing!
Parameter: | Description: |
---|---|
? |
Parameter descriptions are missing! |
Summary is missing!
Parameter: | Description: |
---|---|
? |
Parameter descriptions are missing! |
Summary is missing!
Parameter: | Description: |
---|---|
? |
Parameter descriptions are missing! |
Creates types and rules for a basic container process domain.
Parameter: | Description: |
---|---|
prefix |
Prefix for the domain. |
prefix |
Prefix for the file type. |
Manage container files template
Parameter: | Description: |
---|---|
prefix |
Prefix for the domain. |
prefix |
Prefix for the file type. |
Creates types and rules for a basic container runtime process domain.
Parameter: | Description: |
---|---|
prefix |
Prefix for the domain. |