X-Git-Url: https://gerrit.akraino.org/r/gitweb?p=ta%2Fcaas-security.git;a=blobdiff_plain;f=ansible%2Froles%2Fhardening%2Ftemplates%2Fdocker.rules;fp=ansible%2Froles%2Fhardening%2Ftemplates%2Fdocker.rules;h=7baf1419ede29b6dbe182de73629b8db2ad09d6a;hp=0000000000000000000000000000000000000000;hb=c177c44e5d4c49eeb51b44487a614b865f8bf002;hpb=f2937b9484f58be8f23ae50500f30ca0f0e16e3b diff --git a/ansible/roles/hardening/templates/docker.rules b/ansible/roles/hardening/templates/docker.rules new file mode 100644 index 0000000..7baf141 --- /dev/null +++ b/ansible/roles/hardening/templates/docker.rules @@ -0,0 +1,23 @@ +{# +Copyright 2019 Nokia + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. +#} +-w /usr/bin/docker -k docker +-w /var/lib/docker/manifests -k docker" +-w /etc/docker -k docker +-w /usr/lib/systemd/system/docker.service -k docker +-w /var/run/docker.sock -k docker +-w /etc/sysconfig/docker-proxy -k docker +-w /etc/sysconfig/docker-storage -k docker +-w /etc/sysconfig/docker-registries -k docker