-
Story
-
Resolution: Unresolved
-
Undefined
-
None
-
rhel-10.1
-
None
-
rhel-system-roles
-
0
-
False
-
False
-
-
Yes
-
Red Hat Enterprise Linux
-
None
-
None
-
None
-
Feature
-
-
Proposed
-
Unspecified
-
Unspecified
-
Unspecified
-
None
Feature request - Add support for setting policy rules by creating `/etc/fapolicyd/rules.d/` rules files.
I would imagine this could work similarly to how the [fedora.linux_system_roles.sudo](https://github.com/linux-system-roles/sudo?tab=readme-ov-file#sudo_sudoers_files) role works for setting `/etc/sudoers.d/` includes.
Currently, if any policies are to be set devoted tasks outside of the role are needed, for example:
```yaml
—
- name: Fapolicyd
hosts: all
become: true
vars:
fapolicyd_setup_permissive: true
fapolicyd_setup_integrity: none
fapolicyd_setup_trust: rpmdb,file
pre_tasks:
- Default deny all except whitelisted. DISA STIG RHEL-09-433016
- name: Ensure deny-all, permit-by-exception policy
ansible.builtin.copy:
dest: /etc/fapolicyd/rules.d/99-deny-all.rules
content: |
- Ansible managed
- RHEL-09-433016 - deny-all, permit-by-exception policy
deny perm=any all : all
owner: root
group: root
mode: '0640'
roles:
- fedora.linux_system_roles.fapolicyd
```
- links to