Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Run time security for containers using udica #75

Open
HariAccuknox opened this issue Sep 18, 2020 · 6 comments
Open

Run time security for containers using udica #75

HariAccuknox opened this issue Sep 18, 2020 · 6 comments
Labels
known bug Bug is known or not possible to fix in udica component wontfix This will not be worked on

Comments

@HariAccuknox
Copy link

HariAccuknox commented Sep 18, 2020

Runtime Security
After creating my_container.process for a container can we make it t apply to container without restarting the containers.

Describe the solution you'd like

Running a udica daemon to capture the container specs to create and applying SIGHUP to the daemon to hot reload

Describe alternatives you've considered

Running daemonsets in all nodes or one daemon to all nodes to
.

@wrabcak
Copy link
Member

wrabcak commented Sep 18, 2020

@JAORMX @rhatdan , Guys we can discuss this RFE here.

@JAORMX
Copy link
Collaborator

JAORMX commented Sep 18, 2020

@wrabcak wouldn't applying a new SELinux policy require a container restart either way? thought you needed to set SELinux labels on process start.

@HariAccuknox
Copy link
Author

HariAccuknox commented Sep 18, 2020 via email

@wrabcak
Copy link
Member

wrabcak commented Sep 21, 2020

@JAORMX, there is a possibility to force label change during process runtime, but I don't know if it's possible for containers.

@JAORMX
Copy link
Collaborator

JAORMX commented Sep 21, 2020

@JAORMX, there is a possibility to force label change during process runtime, but I don't know if it's possible for containers.

Uhm...that might be an RFE then for the container runtime (e.g. Podman) more than Udica.

@wrabcak
Copy link
Member

wrabcak commented Sep 21, 2020

Sorry, it's not possible discuss with SELinux userspace maintainer.

@vmojzis vmojzis added the known bug Bug is known or not possible to fix in udica component label Jul 16, 2021
@vmojzis vmojzis added the wontfix This will not be worked on label Jun 21, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
known bug Bug is known or not possible to fix in udica component wontfix This will not be worked on
Projects
None yet
Development

No branches or pull requests

4 participants