set seliux contexts for all files and directories - https://gitlab.confdroid.com/internal/confdroid_management/-/issues/292
This commit is contained in:
@@ -15,6 +15,10 @@ class puppet_cd::main::files (
|
|||||||
owner => 'root',
|
owner => 'root',
|
||||||
group => 'root',
|
group => 'root',
|
||||||
mode => '0644',
|
mode => '0644',
|
||||||
|
selrange => s0,
|
||||||
|
selrole => object_r,
|
||||||
|
seltype => puppet_etc_t,
|
||||||
|
seluser => system_u,
|
||||||
content => template($pt_puppet_conf_erb),
|
content => template($pt_puppet_conf_erb),
|
||||||
notify => Service[$pt_agent_service],
|
notify => Service[$pt_agent_service],
|
||||||
}
|
}
|
||||||
@@ -44,6 +48,10 @@ class puppet_cd::main::files (
|
|||||||
owner => 'root',
|
owner => 'root',
|
||||||
group => 'root',
|
group => 'root',
|
||||||
mode => '0644',
|
mode => '0644',
|
||||||
|
selrange => s0,
|
||||||
|
selrole => object_r,
|
||||||
|
seltype => puppet_etc_t,
|
||||||
|
seluser => system_u,
|
||||||
content => template($pt_puppet_conf_erb),
|
content => template($pt_puppet_conf_erb),
|
||||||
notify => Service[$pt_agent_service,$pt_server_service],
|
notify => Service[$pt_agent_service,$pt_server_service],
|
||||||
}
|
}
|
||||||
@@ -56,6 +64,10 @@ class puppet_cd::main::files (
|
|||||||
owner => 'root',
|
owner => 'root',
|
||||||
group => 'root',
|
group => 'root',
|
||||||
mode => '0644',
|
mode => '0644',
|
||||||
|
selrange => s0,
|
||||||
|
selrole => object_r,
|
||||||
|
seltype => puppet_etc_t,
|
||||||
|
seluser => system_u,
|
||||||
content => template($pt_puppetdb_conf_erb),
|
content => template($pt_puppetdb_conf_erb),
|
||||||
notify => Service[$pt_agent_service,$pt_server_service],
|
notify => Service[$pt_agent_service,$pt_server_service],
|
||||||
}
|
}
|
||||||
@@ -66,6 +78,10 @@ class puppet_cd::main::files (
|
|||||||
owner => 'root',
|
owner => 'root',
|
||||||
group => 'root',
|
group => 'root',
|
||||||
mode => '0644',
|
mode => '0644',
|
||||||
|
selrange => s0,
|
||||||
|
selrole => object_r,
|
||||||
|
seltype => puppet_etc_t,
|
||||||
|
seluser => system_u,
|
||||||
content => template($pt_routes_erb),
|
content => template($pt_routes_erb),
|
||||||
notify => Service[$pt_server_service],
|
notify => Service[$pt_server_service],
|
||||||
}
|
}
|
||||||
@@ -74,6 +90,7 @@ class puppet_cd::main::files (
|
|||||||
owner => 'puppet',
|
owner => 'puppet',
|
||||||
group => 'puppet',
|
group => 'puppet',
|
||||||
mode => '0550',
|
mode => '0550',
|
||||||
|
selrange => s0,
|
||||||
selrole => object_r,
|
selrole => object_r,
|
||||||
seltype => foreman_enc_t,
|
seltype => foreman_enc_t,
|
||||||
seluser => system_u,
|
seluser => system_u,
|
||||||
|
|||||||
Reference in New Issue
Block a user