aboutsummaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* container: allow reading generic certsKenton Groombridge2024-09-211-0/+1
* various: rules required for DV manipulation in kubevirtKenton Groombridge2024-09-211-0/+3
* container: add container_kvm_t and supporting kubevirt rulesKenton Groombridge2024-09-211-1/+33
* container: allow spc various rules for kubevirtKenton Groombridge2024-09-211-2/+11
* container, kubernetes: add supporting rules for kubevirt and multusKenton Groombridge2024-09-211-0/+9
* container: allow super privileged containers to manage BPF dirsKenton Groombridge2024-09-211-1/+1
* container: allow containers to execute tmpfs filesKenton Groombridge2024-09-211-0/+1
* Reorder perms and classesfreedom1b28302024-09-211-18/+18
* container, crio, kubernetes: minor fixesKenton Groombridge2024-05-141-0/+1
* container: allow containers to getcapKenton Groombridge2024-05-141-1/+1
* container: allow system container engines to mmap runtime filesKenton Groombridge2024-05-141-1/+1
* Container: Minor fixes from interactive container use.Chris PeBenito2024-03-011-1/+6
* container: allow spc to map kubernetes runtime filesKenton Groombridge2024-03-011-0/+1
* container, kubernetes: allow kubernetes to use fuse-overlayfsKenton Groombridge2024-03-011-0/+2
* container, kubernetes: add support for rook-cephKenton Groombridge2024-03-011-3/+55
* container, kubernetes: add support for ciliumKenton Groombridge2024-03-011-2/+29
* container: various fixesKenton Groombridge2024-03-011-1/+15
* container: allow watching FUSEFS dirs and filesKenton Groombridge2024-03-011-0/+2
* container: rework capabilitiesKenton Groombridge2023-10-061-4/+84
* container: fix cilium denialMathieu Tortuyaux2023-10-061-0/+1
* container: fixes for podman run --log-driver=passthroughKenton Groombridge2023-03-311-0/+3
* container: fixes for podman 4.4.0Kenton Groombridge2023-03-311-0/+7
* container: Allow user namespace creation for all container engines.Chris PeBenito2023-03-311-0/+1
* container: add missing filetrans and filecon for containerd/dockerKenton Groombridge2023-02-131-1/+1
* container: add rules required for metallb BGP speakersKenton Groombridge2022-12-131-0/+4
* container: add tunable to allow spc to use tun-tap devicesKenton Groombridge2022-12-131-0/+11
* container, miscfiles: transition to s0 for public content created by containersKenton Groombridge2022-12-131-0/+4
* various: allow using glusterfs as backing storage for k8sKenton Groombridge2022-12-131-2/+7
* container, kubernetes: add rules for device plugins running as spcKenton Groombridge2022-12-131-1/+5
* container: add tunable to use dri devicesKenton Groombridge2022-12-131-3/+14
* container, kubernetes: add private type for generic container devicesKenton Groombridge2022-12-131-0/+5
* container: add tunable to allow containers to use huge pagesKenton Groombridge2022-12-131-0/+11
* container, kernel: add tunable to allow spc to create NFS serversKenton Groombridge2022-12-131-0/+19
* various: fixes for kubernetesKenton Groombridge2022-12-131-14/+65
* various: fixes for kubernetesKenton Groombridge2022-12-131-1/+73
* container: add type for container pluginsKenton Groombridge2022-12-131-0/+6
* container: Add missing UDP node bind access on container engines.Chris PeBenito2022-12-131-0/+1
* container: Boolean for ecryptfsPat Riehecky2022-09-031-0/+14
* container: Getattr generic device nodes.Chris PeBenito2022-09-031-0/+2
* container: Allow container engines to connect to http cache ports.Chris PeBenito2022-09-031-0/+1
* container, docker: Fixes for containerd and kubernetes testing.Chris PeBenito2022-09-031-0/+3
* container: add separate type for container engine unitsKenton Groombridge2022-09-031-0/+3
* container: allow container engines to manage tmp symlinksKenton Groombridge2022-09-031-0/+2
* container: allow containers to manipulate own fdsKenton Groombridge2022-09-031-0/+3
* container: also allow containers to watch public contentKenton Groombridge2022-09-031-0/+2
* container: add missing capabilitiesKenton Groombridge2022-04-091-2/+2
* container: add tunables to allow containers to access public contentKenton Groombridge2022-04-091-0/+30
* container: allow generic containers to read the vm_overcommit sysctlKenton Groombridge2022-04-091-0/+2
* container, podman: allow containers to interact with conmonKenton Groombridge2022-04-091-0/+5
* container: allow containers to getsessionKenton Groombridge2022-01-291-1/+1