LINUXOR.SK ... open source notes ...

Vault - rsyslog-haproxy.te (SELinux module)

category: solutionz · date: 2024-12-31 · updated: 2026-10-02 · author: LALA

Vault Solution · Config document · referenced from Load balancer, Audit logging and log shipping

A small SELinux type-enforcement module for the load-balancer nodes. HAProxy runs in a chroot and logs to a socket inside it; with SELinux enforcing, rsyslog is not allowed to create that socket in a directory labelled for HAProxy until this module says so.

ItemValue
Path on the host/etc/selinux/rsyslog-haproxy.te
Deployed onboth load-balancer nodes of every cluster
Compiled withcheckmodule -M -m, then semodule_package
Loaded withsemodule -i /etc/selinux/rsyslog-haproxy.pp

The file

c
module rsyslog-haproxy 1.0;

require {
    type syslogd_t;
    type haproxy_var_lib_t;
    class dir { add_name remove_name search write };
    class sock_file { create setattr unlink };
}

#============= syslogd_t ==============
allow syslogd_t haproxy_var_lib_t:dir { add_name remove_name search write };
allow syslogd_t haproxy_var_lib_t:sock_file { create setattr unlink };
← solutionz