3 ms·
While the article shows how they build SELinux policy from scrath, they also mention udica tool[1] which generates SELinux profile based on container inspection
by marbu 6y ago
While the article shows how they build SELinux policy from scrath, they also mention udica tool[1] which generates SELinux profile based on container inspection:
# podman inspect my_container_id | udica my_container
I wonder how much would the result be different in their case or how much time would they save by having the first version of the policy being generated this way instead of writing it from scratch.
[1] https://github.com/containers/udica https://github.com/containers/udica