Implement SELinux workaround tasks

This commit is contained in:
Alexander Gorelyshev
2026-07-02 14:45:09 +04:00
parent 9e052eb769
commit 4c06771d1c
3 changed files with 29 additions and 6 deletions

View File

@@ -4,6 +4,10 @@
gather_facts: false
any_errors_fatal: true
#
# NOTE: SELinux workarounds are not tested due to container limitations
#
tasks:
- name: "Include default vars"
ansible.builtin.include_vars:

View File

@@ -51,9 +51,10 @@
group: root
mode: "0644"
# a workaround for an issue reported here: https://github.com/czerwonk/ping_exporter/issues/152
- name: "Change `ping_t` SELinux domain to persmissive"
when: ansible_os_family == "RedHat"
community.general.selinux_permissive:
name: ping_t
permissive: true
- name: "Apply SELinux workarounds"
when:
- ansible_facts.os_family == "RedHat"
- ansible_selinux.status is defined
- ansible_selinux.status != "disabled"
ansible.builtin.include_tasks:
file: selinux.yml

View File

@@ -0,0 +1,18 @@
# a workaround for an issue reported here: https://github.com/czerwonk/ping_exporter/issues/152
- name: "Ensure SELinux management tools are installed"
ansible.builtin.package:
name: policycoreutils-python-utils
state: present
- name: "Override SELinux fcontext for ping_exporter binary"
community.general.sefcontext:
target: /usr/bin/ping_exporter
setype: bin_t
state: present
- name: "Apply SELinux context to ping_exporter binary"
register: ping_exporter_restorecon
changed_when: ping_exporter_restorecon.stdout | length > 0
notify: "Restart-ping-exporter"
ansible.builtin.command:
cmd: restorecon -v /usr/bin/ping_exporter