-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Document change to K3s SELinux option #2686
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from 2 commits
e37a34c
30ee90e
a7a0d50
74c65c5
a8706f8
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -314,6 +314,24 @@ rpm -i https://rpm.rancher.io/k3s-selinux-0.1.1-rc1.el7.noarch.rpm | |
|
|
||
| To force the install script to log a warning rather than fail, you can set the following environment variable: `INSTALL_K3S_SELINUX_WARN=true`. | ||
|
|
||
| The way that SELinux enforcement is enabled or disabled depends on the K3s version. | ||
|
|
||
| {{% tabs %}} | ||
| {{% tab "K3s v1.19.1+k3s1" %}} | ||
|
|
||
| To leverage experimental SELinux, specify the `--selinux` flag when starting K3s servers and agents. | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Can we explicitly say, not passing the flag would have selinux in disabled mode
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Hmm. In my opinion this is probably fine as it is.
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I'll leave this sentence as is because @dweomer clarified it in his suggestion as well |
||
|
|
||
| This option can also be specified in the K3s [configuration file:]({{<baseurl>}}/k3s/latest/en/installation/install-options/#configuration-file) | ||
|
|
||
| ``` | ||
| selinux: true | ||
| ``` | ||
| {{%/tab%}} | ||
| {{% tab "K3s prior to v1.19.1+k3s1" %}} | ||
|
|
||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. As suggested, https://github.com/rancher/docs/pull/2686/files#r489578963, mentioning the
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Added the info to the K3s v1.19+ tab:
|
||
| You can turn off SELinux enforcement in the embedded containerd by launching K3s with the `--disable-selinux` flag. | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. We do not have --disable-selinux flag instead use --selinux=false or skip selinux flag which does not enable selinux
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. This tab is saying that the There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Sounds good @catherineluse Thanks |
||
|
|
||
| {{%/tab%}} | ||
| {{% /tabs %}} | ||
|
|
||
| Note that support for SELinux in containerd is still under development. Progress can be tracked in [this pull request](https://github.com/containerd/cri/pull/1246). | ||
Uh oh!
There was an error while loading. Please reload this page.