aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar SkewedZeppelin <8296104+SkewedZeppelin@users.noreply.github.com>2018-04-01 06:16:21 -0400
committerLibravatar GitHub <noreply@github.com>2018-04-01 06:16:21 -0400
commit4f1a707f84ecabb708b37a7772f3c8d950e1624a (patch)
tree8dd71d0ff2c8579d605a94410fdff5c808d713d3 /etc
parentMerge pull request #1853 from glitsj16/gnome-logs (diff)
parentRemove /usr/local from gcloud.profile (diff)
downloadfirejail-4f1a707f84ecabb708b37a7772f3c8d950e1624a.tar.gz
firejail-4f1a707f84ecabb708b37a7772f3c8d950e1624a.tar.zst
firejail-4f1a707f84ecabb708b37a7772f3c8d950e1624a.zip
Merge pull request #1849 from jelford/gcloud-profile
Added a basic profile for gcloud
Diffstat (limited to 'etc')
-rw-r--r--etc/gcloud.profile40
1 files changed, 40 insertions, 0 deletions
diff --git a/etc/gcloud.profile b/etc/gcloud.profile
new file mode 100644
index 000000000..195dc9302
--- /dev/null
+++ b/etc/gcloud.profile
@@ -0,0 +1,40 @@
1# Firejail profile for gcloud
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/gcloud.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ${HOME}/.boto
9noblacklist ${HOME}/.config/gcloud
10noblacklist /var/run/docker.sock
11
12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-programs.inc
15
16apparmor
17caps.drop all
18machine-id
19netfilter
20nodbus
21nodvd
22# required for sudo-free docker
23#nogroups
24nonewprivs
25noroot
26notv
27protocol unix,inet,inet6
28seccomp
29shell none
30tracelog
31
32disable-mnt
33private-dev
34private-etc ca-certificates,ssl,hosts,localtime,nsswitch.conf,resolv.conf,pki,crypto-policies,ld.so.cache
35private-tmp
36
37noexec /tmp
38
39# will break user-local installs of gcloud tooling
40# noexec ${HOME}