diff --git a/roles/minio/tasks/deploy.yml b/roles/minio/tasks/deploy.yml index 0b75b2a..5216671 100644 --- a/roles/minio/tasks/deploy.yml +++ b/roles/minio/tasks/deploy.yml @@ -34,6 +34,7 @@ group: minio mode: u=rwx,go= state: directory + setype: container_file_t tags: - datadir diff --git a/roles/minio/templates/minio.container.j2 b/roles/minio/templates/minio.container.j2 index 5d22c29..c5497c9 100644 --- a/roles/minio/templates/minio.container.j2 +++ b/roles/minio/templates/minio.container.j2 @@ -10,7 +10,7 @@ Exec=server {% if minio_address|d %}--address {{ minio_address }} {% endif %}/da User=224 Group=224 EnvironmentFile=/etc/sysconfig/minio -Volume={{ minio_storage_path }}:/data:rw,Z +Volume={{ minio_storage_path }}:/data:rw Volume=/etc/minio/certs:/certs:ro,z Network=host NoNewPrivileges=yes