close 1038164 thanks The Trixie policy has the container module which covers most of this. There are some things like container_runtime_exec_t, that aren't included, it would be good to get them upstream. Currently the policy in Trixie is the upstream container policy. -- My Main Blog http://etbe.coker.com.au/ My Documents Blog http://doc.coker.com.au/