Vault - rsyslog-haproxy.te (SELinux module)
Vault Solution · Config document · referenced from Load balancer, Audit logging and log shipping
A small SELinux type-enforcement module for the load-balancer nodes. HAProxy runs in a chroot and logs to a socket inside it; with SELinux enforcing, rsyslog is not allowed to create that socket in a directory labelled for HAProxy until this module says so.
| Item | Value |
|---|---|
| Path on the host | /etc/selinux/rsyslog-haproxy.te |
| Deployed on | both load-balancer nodes of every cluster |
| Compiled with | checkmodule -M -m, then semodule_package |
| Loaded with | semodule -i /etc/selinux/rsyslog-haproxy.pp |
The file
module rsyslog-haproxy 1.0; require { type syslogd_t; type haproxy_var_lib_t; class dir { add_name remove_name search write }; class sock_file { create setattr unlink }; } #============= syslogd_t ============== allow syslogd_t haproxy_var_lib_t:dir { add_name remove_name search write }; allow syslogd_t haproxy_var_lib_t:sock_file { create setattr unlink };