udica icon indicating copy to clipboard operation
udica copied to clipboard

Run time security for containers using udica

Open HariAccuknox opened this issue 5 years ago • 6 comments

Runtime Security After creating my_container.process for a container can we make it t apply to container without restarting the containers.

Describe the solution you'd like

Running a udica daemon to capture the container specs to create and applying SIGHUP to the daemon to hot reload

Describe alternatives you've considered

Running daemonsets in all nodes or one daemon to all nodes to .

HariAccuknox avatar Sep 18 '20 11:09 HariAccuknox

@JAORMX @rhatdan , Guys we can discuss this RFE here.

wrabcak avatar Sep 18 '20 13:09 wrabcak

@wrabcak wouldn't applying a new SELinux policy require a container restart either way? thought you needed to set SELinux labels on process start.

JAORMX avatar Sep 18 '20 13:09 JAORMX

Can we provide default selinux profile with certain profiles for containers and overriding containers with daemon sighup . This will certainly improve sel implementation in containers

On Fri, 18 Sep 2020, 19:05 Juan Osorio Robles, [email protected] wrote:

@wrabcak https://github.com/wrabcak wouldn't applying a new SELinux policy require a container restart either way? thought you needed to set SELinux labels on process start.

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHub https://github.com/containers/udica/issues/75#issuecomment-694871423, or unsubscribe https://github.com/notifications/unsubscribe-auth/APYLVFQ7SZWZ6FDRCQZZOSDSGNO2LANCNFSM4RR3S27A .

HariAccuknox avatar Sep 18 '20 18:09 HariAccuknox

@JAORMX, there is a possibility to force label change during process runtime, but I don't know if it's possible for containers.

wrabcak avatar Sep 21 '20 11:09 wrabcak

@JAORMX, there is a possibility to force label change during process runtime, but I don't know if it's possible for containers.

Uhm...that might be an RFE then for the container runtime (e.g. Podman) more than Udica.

JAORMX avatar Sep 21 '20 12:09 JAORMX

Sorry, it's not possible discuss with SELinux userspace maintainer.

wrabcak avatar Sep 21 '20 12:09 wrabcak