Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[prometheus-node-exporter] SELinux policy #4867

Open
garrisig opened this issue Sep 20, 2024 · 1 comment
Open

[prometheus-node-exporter] SELinux policy #4867

garrisig opened this issue Sep 20, 2024 · 1 comment
Labels
enhancement New feature or request

Comments

@garrisig
Copy link

Is your feature request related to a problem ?

For the prometheus-node-exporter daemonset to run on a Kubernetes cluster deployed on a SELinux enabled distro, one needs to set the SELinux type to spc_t, that seems too much privileged

Describe the solution you'd like.

I wrote a specific policy that creates a new SELinux type container_prometheus_node_exporter_t. I am willing to contribute it, but I am not sure what is the right place for it.

Describe alternatives you've considered.

Opening this issue on the container-selinux repository, but it seems to fit better here.

Additional context.

No response

@garrisig garrisig added the enhancement New feature or request label Sep 20, 2024
@mlec1
Copy link

mlec1 commented Sep 25, 2024

I would be interested to see your policy. Could you post it here at least please ??!!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants