Skip to main content

selinux_denial

low riskVersion 1.1.0Live

SELinux AVC denials: context mismatches for nginx, php-fpm, or containers; use permissive domains only as a temporary bridge with audit evidence.

Source library/selinux_denial.repair.yml

0 votes

When-rules (signature × N in M minutes → actions): 2 — see config/reflex.php for the YAML schema; evaluator wiring is tracked separately.

Tools

  • evaluate_fingerprint_dry_run
  • list_playbooks

To run remediation, sign in and use server repair flows or your chat integrations. This catalogue only lists validated YAML shipped with Reflex.