ah ok, based on slack conversation and the outputs of ls -alZ docker/rabbitmq, it seems like this points to docker rootful daemon (the default config) by default using a label of system_u:object_r:container_file_t:s0:cXXX,cYYY (container_file_t having been added by this fix).
This seemingly isn't affecting podman because it runs as rootless by default and has some defaults that let it read files in the users homedir.
This likely isn't affecting the CI because I doubt SELinux is enabled in the CI.
So yeah SELinux + docker compatibility with our stock config does seem to be a gap in our testing.
Originally posted by @MoralCode in #508 (comment)
ah ok, based on slack conversation and the outputs of
ls -alZ docker/rabbitmq, it seems like this points to docker rootful daemon (the default config) by default using a label ofsystem_u:object_r:container_file_t:s0:cXXX,cYYY(container_file_t having been added by this fix).This seemingly isn't affecting podman because it runs as rootless by default and has some defaults that let it read files in the users homedir.
This likely isn't affecting the CI because I doubt SELinux is enabled in the CI.
So yeah SELinux + docker compatibility with our stock config does seem to be a gap in our testing.
Originally posted by @MoralCode in #508 (comment)