Documentation reorg for v4.6.0

Signed-off-by: Jonathon Anderson <janderson@ciq.com>
This commit is contained in:
Jonathon Anderson
2025-02-18 16:26:05 -07:00
parent 98695cbbff
commit 9e41378e1c
65 changed files with 3493 additions and 4654 deletions

View File

@@ -0,0 +1,29 @@
.. _selinux_images:
======================
SELinux-enabled Images
======================
Warewulf supports booting SELinux-enabled images, though nodes using SELinux
must be configured to use tmpfs for their image file system. ("ramfs," often
used by default, does not support extended file attributes, which are required
for SELinux context labeling.)
.. code-block:: bash
wwctl profile set default --root tmpfs
.. note::
Versions of Warewulf prior to v4.5.8 also required a kernel argument
"rootfstype=ramfs" in order for wwinit to copy the node image to tmpfs; but
this is no longer required.
Once that is done, enable SELinux in ``/etc/sysconfig/selinux`` and install the
appropriate packages in the image. `An example`_ of such an image is available
in the warewulf-node-images repository.
.. _An example: https://github.com/warewulf/warewulf-node-images/tree/main/examples/rockylinux-9-selinux
SELinux requires extended attributes, which aren't supported on a default
``initrootfs``. Nodes using SELinux should specify ``--root=tmpfs``.