Q: "btw, anyone know if each of the selinux booleans are documented in detail somewhere?"
A: two levels of detail here:
1. semanage boolean -l | grep httpd_enable_homedirs
A written description (usually not very detailed) for the "httpd_enable_homedirs" boolean.
2. sesearch --allow -SC -T | grep httpd_enable_homedirs
All the "allow" type statement rules and type transition rules related to the "httpd_enable_homedirs" boolean. Very detailed but hard to interpret.
Be careful relabeling volumes with Container run times. Sometimes things can go very wrong? - I recently revieved an email from someone who made the mistake of volume mounting /root into his container with the :Z option. docker run -ti -v /root:/ro...
2 weken geleden