spiegel_podman/pkg
Daniel J Walsh 5b7dce8a3d
Add support for confined users
The original SELinux support in Docker and Podman does not follow the
default SELinux rules for how label transitions are supposed to be
handled. Containers always switch their user and role to
system_u:system_r, rather then maintain the collers user and role.
For example
unconfined_u:unconfined_r:container_t:s0:c1,c2

Advanced SELinux administrators want to confine users but still allow
them to create containers from their role, but not allow them to launch
a privileged container like spc_t.

This means if a user running as
container_user_u:container_user_r:container_user_t:s0

Ran a container they would get

container_user_u:container_user_r:container_t:s0:c1,c2

If they run a privileged container they would run it with:

container_user_u:container_user_r:container_user_t:s0

If they want to force the label they would get an error

podman run --security-opt label=type:spc_t ...

Should fail. Because the container_user_r can not run with the spc_t.

SELinux rules would also prevent the user from forcing system_u user and
the sytem_r role.

Signed-off-by: Daniel J Walsh <dwalsh@redhat.com>
Signed-off-by: Chris Evich <cevich@redhat.com>
2023-08-01 11:25:00 -04:00
..
annotations Remove ReservedAnnotations from kube generate specification 2023-01-18 08:46:24 -05:00
api API: kill: return 409 on invalid state 2023-07-31 11:17:58 +02:00
auth fix(deps): update module github.com/docker/docker to v24 2023-05-22 15:32:12 +02:00
autoupdate auto update: fix usage of --authfile 2023-07-05 08:30:39 +02:00
bindings Don't log EOF error when using podman --remote build with an empty context directory. 2023-07-31 12:00:01 +00:00
channel bump golangci-lint to v1.50.1 2022-12-15 13:39:56 +01:00
checkpoint criu: return error when checking for min version 2023-06-12 15:29:21 +02:00
copy pkg: switch to golang native error wrapping 2022-07-08 08:54:47 +02:00
criu criu: return error when checking for min version 2023-06-12 15:29:21 +02:00
ctime Replace deprecated ioutil 2022-09-20 15:34:27 -04:00
domain Fix: use --all in podman stats to get all containers stats 2023-07-26 09:41:14 +03:00
env feat(env): support multiline in env-file 2023-07-31 09:59:45 +08:00
errorhandling Fix typos 2023-02-11 18:23:24 +01:00
inspect pkg/inspect: remove unused ImageResult type 2022-05-24 16:07:39 +02:00
k8s.io *: migrate image registry to registry.k8s.io 2023-04-11 10:30:43 -04:00
lookup source code comments and docs: fix typos, language, Markdown layout 2023-05-22 07:52:16 +02:00
machine Merge pull request #19455 from jakecorrenti/qemu-machine-funcs-to-methods 2023-08-01 09:43:17 +02:00
namespaces source code comments and docs: fix typos, language, Markdown layout 2023-05-22 07:52:16 +02:00
parallel Fix stutters 2022-09-10 07:52:00 -04:00
ps Add {{.Restarts}} to podman ps 2023-05-02 10:30:07 -04:00
rctl pkg/rctl: Remove unused cgo dependency 2022-10-31 15:13:48 +00:00
rootless add a podman-compose command 2023-07-24 19:23:04 +02:00
seccomp pkg: switch to golang native error wrapping 2022-07-08 08:54:47 +02:00
selinux Fix SELinux functions names to not be repetitive 2020-04-23 15:57:34 -04:00
signal Run codespell on code 2022-11-04 10:57:41 -04:00
specgen make /dev & /dev/shm read/only when --read-only --read-only-tmpfs=false 2023-07-30 06:09:30 -04:00
specgenutil Add support for confined users 2023-08-01 11:25:00 -04:00
systemd Add glob support to podman run/create --mount 2023-07-27 06:32:54 -04:00
terminal podman ssh work, using new c/common interface 2022-08-09 14:00:58 -04:00
timetype bump golangci-lint to v1.49.0 2022-10-17 09:19:41 +02:00
trust Revert the usage of home.GetConfigHome() 2023-07-17 18:29:06 +02:00
util Use constants for mount types 2023-07-14 07:17:21 -04:00