Docker can safely and easily run in conjunction with selinux. To ensure you're setup for selinux support, check the following:
'getenforce' - Are you enforcing/permissive/disabled? You should be enforcing. if not, run 'setenforce 1'.
'yum list installed docker-selinux*' - If nothing returns, then you're missing the selinux components and need to install them. Run 'yum install -y docker-selinux' to resolve.
'cat /etc/sysconfig/docker | grep OPTIONS' - You should see 'OPTIONS='--selinux-enabled''. If not make the change and restart the docker daemon: 'systemctl restart docker'.
Docker works auto-magically with selinux to enhance your system's security. The only things you need to do to properly work with the tool are to understand the switches involved with bind mounting storage. Visit the Bind Mounting Storage & Ports and Working with NFS mounts articles if you haven't already to understand the caveats with selinux and docker storage.
Next: Conclusion
Showing posts with label selinux. Show all posts
Showing posts with label selinux. Show all posts
Monday, November 2, 2015
Real-world Docker Series: Working with NFS Mounts
After seeing how to bind mount storage, you're probably wondering,
“How can I store data from a container on a NFS mounted device?”
There are 2 ways to accomplish this properly with selinux:
1.) There is a selinux boolean: virt_sandbox_use_nfs
To check the status of this boolean, you can run:
getsebool virt_sandbox_use_nfs
If the status of the boolean is off, then you can turn it on by
running:
setsebool -PV virt_sandbox_use_nfs on #Persistent and Verbose on
Errors
Now run getsebool virt_sandbox_use_nfs again to verify it's now on.
When bind mounting storage on the NFS mount, you will now need to
drop the :z and :Z options.
This now allows the containers to be able to access any
of the docker host's mounted NFS volumes when directed to.
2.) Setting the appropriate selinux file context as a mount option.
This is accomplished by adding the selinux context required for
docker container data to the /etc/fstab NFS mount options.
vi /etc/fstab and find the appropriate NFS mount. Append to the
entry's options: context=”system_u:object_r:svirt_sandbox_file_t”
and save the fstab.
Unless you are running a NFS v4.2 server and NFS v4.2 client you will
need to drop the :z and :Z options from your docker run command. NFS
v4.2 supports contexts properly and can properly store the file
contexts.
Method 2 is considered more secure, since you are allowing possible
access to only a specified NFS volume rather than all of them as seen
in method 1.
Subscribe to:
Posts (Atom)
