## A scalable high-availability cluster resource manager. ######################################## ## ## All of the rules required to ## administrate an pacemaker environment. ## ## ## ## Domain allowed access. ## ## ## ## ## Role allowed access. ## ## ## # interface(`pacemaker_admin',` gen_require(` type pacemaker_t, pacemaker_initrc_exec_t, pacemaker_var_lib_t; type pacemaker_runtime_t; ') allow $1 pacemaker_t:process { ptrace signal_perms }; ps_process_pattern($1, pacemaker_t) init_startstop_service($1, $2, pacemaker_t, pacemaker_initrc_exec_t) files_search_var_lib($1) admin_pattern($1, pacemaker_var_lib_t) files_search_runtime($1) admin_pattern($1, pacemaker_runtime_t) ')