瀏覽代碼

Do not disable SELinux on RedHat systems

It looks like SELinux can be left running without any (so far) negative
effects on our Matrix services.

There's no need to use `:z` or `:Z` options when mounting volumes either.
This means that files we create are labeled with a default context
(which may not be ideal if we only want them used from containers),
but it's compatible and doesn't cause issues.

Relabelling files is probably something we wish to stay away from,
especially for things like the media store, which contains lots of
files and is possibly on a fuse-mounted (S3/goofys) filesystem.
pull/54/head
Slavi Pantaleev 7 年之前
父節點
當前提交
9f163b2bf5
共有 1 個文件被更改,包括 0 次插入4 次删除
  1. +0
    -4
      roles/matrix-server/tasks/setup/setup_base.yml

+ 0
- 4
roles/matrix-server/tasks/setup/setup_base.yml 查看文件

@@ -79,7 +79,3 @@
name: "{{ 'ntpd' if ansible_os_family == 'RedHat' else 'ntp' }}"
state: started
enabled: yes

- name: Ensure SELinux disabled
selinux: state=disabled
when: ansible_os_family == 'RedHat'

Loading…
取消
儲存