policy for kubernetes
All of the rules required to administrate a kubernetes environment.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
| role |
Role allowed access. |
Associated the specified domain to be a domain which is capable of operating as a container domain which can be spawned by kubernetes. engine.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Associated the specified domain to be a domain which is capable of operating as a kubernetes container engine.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Execute kubeadm in the kubeadm domain.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed to transition. |
Execute kubelet in the kubelet domain.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed to transition. |
Do not audit attempts to search kubernetes container engine keys.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Get the status of kubernetes systemd units.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow the specified domain to get the process group ID of all kubernetes containers.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed to transition. |
Allow kubelet to send a kill signal to the specified domain.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow the specified domain to list the contents of kubernetes plugin directories.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
List the contents of kubernetes tmpfs directories.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Manage kubernetes config files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow the specified domain to manage kubernetes plugin files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Manage kubernetes runtime directories.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Manage kubernetes runtime files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Manage kubernetes runtime sock files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Manage kubernetes runtime symlinks.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Manage kubernetes tmpfs directories.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Manage kubernetes tmpfs files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Manage kubernetes tmpfs symlinks.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Memory map kubernetes runtime files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Mount on kubernetes config directories.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Mount on kubernetes config files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Mount on kubernetes runtime directories.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow the specified file type to be mounted on by kubernetes.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read kubernetes config files and symlinks.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read the process state (/proc/pid) of kubernetes container engines.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read the process state (/proc/pid) of kubelet.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read kubernetes tmpfs files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read kubernetes tmpfs symlinks.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Relabel directories from the kubernetes tmpfs type.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Relabel files from the kubernetes tmpfs type.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Relabel symlinks from the kubernetes tmpfs type.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Reload kubernetes systemd units.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Run kubernetes container engine bpf programs.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Execute kubeadm in the kubeadm domain, and allow the specified role the kubeadm domain.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed to transition. |
| role |
The role to be allowed the kubeadm domain. |
Execute kubelet in the kubelet domain, and allow the specified role the kubelet domain.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed to transition. |
| role |
The role to be allowed the kubelet domain. |
Read and write FIFO files from kubernetes container engines.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Search kubernetes config directories.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow the specified domain to search through the contents of kubernetes plugin directories.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Start kubernetes systemd units.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Stop kubernetes systemd units.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Connect to kubelet over a unix stream socket.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Inherit and use file descriptors from kubelet.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow the specified domain to watch kubernetes config directories.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow the specified domain to watch kubernetes config files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow the specified domain to watch kubernetes plugin directories.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Watch kubernetes runtime files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Watch kubernetes tmpfs directories.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Watch kubernetes tmpfs files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Role access for kubectl.
| Parameter: | Description: |
|---|---|
| role_prefix |
The prefix of the user role (e.g., user is the prefix for user_r). |
| user_domain |
User domain for the role. |
| user_exec_domain |
User exec domain for execute and transition access. |
| role |
Role allowed access |