The openstack-selinux rpm package has a bunch of operations being
done
within a transaction, including setting network ports, booleans and
default file labeling.
Dan, would you mind sharing the URL/git repo link? I was only able to
find the policy itself, I'd like to see the SPEC file. I don't see any
content in the fedora distgit.
We (Satellite 6 / Foreman) team take several approach, which was
initially inspired from Satellite 5 / Spacewalk. We also put things into
transactions and stuff. I'd like to compare with OpenStack if we can
improve.
https://github.com/theforeman/foreman-selinux
Thanks!
--
Later,
Lukas #lzap Zapletal