Hacker News new | ask | show | jobs
by deckiedan 3415 days ago
Oh yes, SElinux tooling is an abomination.

I feel like there should be a way to write a new set of simplified tooling on top of the kernel API.

I've been running fedora at home an on my laptop for about a year now, and don't need to turn SElinux off. I only needed to add one custom role myself too, when trying to mount certain host directories as volumes in docker. Which is fair enough.