policy for openshift
false
Allow openshift to access nfs file systems without labels
All of the rules required to administrate an openshift environment
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
| role |
Role allowed access. |
Read openshift lib files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow the specified domain to append openshift log files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed to transition. |
Dontaudit Read and write inherited script fifo files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow calling app to transition to an openshift domain
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access |
Getattr openshift lib files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Execute openshift server in the openshift domain.
| Parameter: | Description: |
|---|---|
| domain |
The type of the process performing this action. |
Execute openshift server in the openshift domain.
| Parameter: | Description: |
|---|---|
| domain |
The type of the process performing this action. |
| role |
Role access to this domain. |
Send a signal to openshift init scripts.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Send a null signal to openshift init scripts.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create private objects in the mail lib directory.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
| private type |
The type of the object to be created. |
| object |
The object class of the object being created. |
| name |
The name of the object being created. |
Create, read, write, and delete openshift cache dirs.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create, read, write, and delete openshift cache files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Manage openshift lib content.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create, read, write, and delete openshift lib files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create, read, write, and delete openshift lib files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow domain to manage openshift log files
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Manage openshift tmp files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Manage openshift tmp sockets.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Mounton openshift tmp directory.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Make the specified type usable as a openshift domain.
| Parameter: | Description: |
|---|---|
| type |
Type to be used as a openshift domain type. |
Read openshift cache files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read openshift lib files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow the specified domain to read openshift's log files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read openshift PID files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Relabel openshift library files
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Execute openshift in the openshift domain, and allow the specified role the openshift domain.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed to transition. |
| role |
Role allowed access. |
Read and write inherited openshift files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Search openshift cache directories.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Search openshift lib directories.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow calling app to transition to an openshift domain
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access |
Make the specified type usable as a openshift domain.
| Parameter: | Description: |
|---|---|
| openshiftdomain_prefix |
The prefix of the domain (e.g., openshift is the prefix for openshift_t). |