Commit cf8c73a7d3e4da8f79ea7071f3724e4deb1529c2

Authored by Antonio Terceiro
1 parent aebfbe16

Add SELinux

cookbooks/basics/files/default/selinux_config 0 → 100644
... ... @@ -0,0 +1,4 @@
  1 +# MANAGED WITH CHEF. DO NOT CHANGE BY HAND
  2 +
  3 +SELINUX=enforcing
  4 +SELINUXTYPE=targeted
... ...
cookbooks/basics/recipes/default.rb
1 1 # enable EPEL repository by default
2 2 package 'epel-release'
3 3  
  4 +# replicate production security setup
  5 +package 'selinux-policy'
  6 +package 'policycoreutils-python'
  7 +cookbook_file '/etc/selinux/config' do
  8 + source 'selinux_config'
  9 + owner 'root'
  10 + group 'root'
  11 + mode 0644
  12 +end
  13 +execute 'setenforce Enforcing'
  14 +
4 15 package 'vim'
5 16 package 'bash-completion'
6 17 package 'rsyslog'
... ...