Created
September 6, 2016 23:24
-
-
Save apcera-code/e6a47fc6f2fcac07185d7395443ec775 to your computer and use it in GitHub Desktop.
The controlling policy, which grants admin users the ability to bind to restricted services, takes the form of the following two rules:
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
on job::/ { | |
if (PV->SvcGroups.category == restricted && | |
service == PV->SvcGroups.service && | |
role == admin) | |
{ | |
permit bind | |
} | |
} | |
on service::/ { | |
if (PV->SvcGroups.category == restricted && | |
query->target_str == PV->SvcGroups.service && | |
role == admin) | |
{ | |
permit bind | |
} | |
} |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment