policy for kubernetes
All of the rules required to administrate a kubernetes environment.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
role |
Role allowed access. |
Associated the specified domain to be a domain which is capable of operating as a container domain which can be spawned by kubernetes. engine.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Associated the specified domain to be a domain which is capable of operating as a kubernetes container engine.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute kubeadm in the kubeadm domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute kubelet in the kubelet domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Do not audit attempts to search kubernetes container engine keys.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Get the status of kubernetes systemd units.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to get the process group ID of all kubernetes containers.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Allow kubelet to send a kill signal to the specified domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to list the contents of kubernetes plugin directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List the contents of kubernetes tmpfs directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage kubernetes config files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to manage kubernetes plugin files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage kubernetes runtime directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage kubernetes runtime files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage kubernetes runtime sock files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage kubernetes runtime symlinks.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage kubernetes tmpfs directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage kubernetes tmpfs files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage kubernetes tmpfs symlinks.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Memory map kubernetes runtime files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount on kubernetes config directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount on kubernetes config files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount on kubernetes runtime directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified file type to be mounted on by kubernetes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read kubernetes config files and symlinks.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read the process state (/proc/pid) of kubernetes container engines.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read the process state (/proc/pid) of kubelet.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read kubernetes tmpfs files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read kubernetes tmpfs symlinks.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel directories from the kubernetes tmpfs type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel files from the kubernetes tmpfs type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel symlinks from the kubernetes tmpfs type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Reload kubernetes systemd units.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Run kubernetes container engine bpf programs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute kubeadm in the kubeadm domain, and allow the specified role the kubeadm domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
role |
The role to be allowed the kubeadm domain. |
Execute kubelet in the kubelet domain, and allow the specified role the kubelet domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
role |
The role to be allowed the kubelet domain. |
Read and write FIFO files from kubernetes container engines.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search kubernetes config directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to search through the contents of kubernetes plugin directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Start kubernetes systemd units.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Stop kubernetes systemd units.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Connect to kubelet over a unix stream socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Inherit and use file descriptors from kubelet.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to watch kubernetes config directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to watch kubernetes config files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to watch kubernetes plugin directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Watch kubernetes runtime files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Watch kubernetes tmpfs directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Watch kubernetes tmpfs files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Role access for kubectl.
Parameter: | Description: |
---|---|
role_prefix |
The prefix of the user role (e.g., user is the prefix for user_r). |
user_domain |
User domain for the role. |
user_exec_domain |
User exec domain for execute and transition access. |
role |
Role allowed access |