Managing SELinux with Puppet
tag1consulting.com
tag1consulting.com
For what it's worth, that system had about 60 different applications we were running that were provided by a vendor, and their official recommendation was to disable selinux. They never provided (afaik) configurations or guidance to run their apps under selinux.
https://wiki.gentoo.org/wiki/SELinux/Tutorials/What_is_this_...
It adds a whole extra step between coding a feature and deploying it. e.g. if I want to add a feature to an existing daemon to cache things in /var/cache/foo, then before deploying, I'll need to make sure the relevant SELinux policies are updated.
Also, I find SELinux gets in the way when debugging a live server. Often to solve a complex issue I'll need to ssh into a production server and inspect some sort of state or produce dumps; but if that machine has selinux installed, I end up running into it at some point or another.
Startups and small companies rarely spend enough on operations and I feel as if there is bit of a death by a thousand paper cuts across the board for productivity and security due to tools written for sysadmins, and "devops" engineers.
The devil is in the details. Things like logs, packaging, and email sound dead easy, but they get complex fast. Trivial implementations ('just on my own workstation') are always dead easy, but making actual environments that scale sensibly is difficult and rapidly run into all sorts of edge cases.
Configuration management tools are complex because configuration management is complex. You can always move with the herd and go Docker instead... but now instead of managing the configuration management tool... you're managing Docker, which is just as much overhead and has more edge cases you need to cater to.
If you want simple tools, then constrain yourself and run in a managed environment (eg AWS's Beanstalk). As soon as you want environmental flexibility, you open a can of worms that can only be dealt with using a complex tool.
2. Because the production environment didn't have SELinux, until the ops team that manages it read this blog article, and decided to enable it: but I still need to do my job.