Bug 1965298

Summary: [RFE] Hardening security for insights-client
Product: Red Hat Enterprise Linux 8 Reporter: Olimp Bockowski <obockows>
Component: insights-clientAssignee: Christian Marineau <cmarinea>
Status: NEW --- QA Contact: Pavol Kotvan <pakotvan>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 8.6CC: agk, cmarinea, gmccullo, kdixon, link, pakotvan, ptoscano, robwilli
Target Milestone: betaKeywords: FutureFeature
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: Story
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Olimp Bockowski 2021-05-27 12:00:53 UTC
Description of problem:

When I look at the package insights-client, I don't see any SELinux policies, the insight-client process runs as python with unconfined_t context explanation. 
Maybe we could change it or use proper capabilities?