bkernel: use more acls

We need also to allow pesign to the dir/socket so it can start and then
we need kojibuilder access to the socket too.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
This commit is contained in:
Kevin Fenzi 2023-02-01 10:59:32 -08:00
parent 4e23d73129
commit b4cf3d1cf0

View file

@ -34,8 +34,23 @@
tags:
- bkernel
- name: /var/run/pesign directory perms
acl: path=/var/run/pesign default=true entity=kojibuilder etype=group permissions=rwx recursive=true state=present
- name: /var/run/pesign directory perms (kojibuilder)
acl: path=/var/run/pesign entity=kojibuilder etype=group permissions=rwx recursive=true state=present
tags:
- bkernel
- name: /var/run/pesign directory perms (pesign)
acl: path=/var/run/pesign default=true entity=pesign etype=group permissions=rwx recursive=true state=present
tags:
- bkernel
- name: /var/run/pesign socket perms (kojibuilder)
acl: path=/var/run/pesign/socket entity=kojibuilder etype=group permissions=rwx recursive=true state=present
tags:
- bkernel
- name: /var/run/pesign socket perms (pesign)
acl: path=/var/run/pesign/socket default=true entity=pesign etype=group permissions=rwx recursive=true state=present
tags:
- bkernel