Hide Forgot
We need to have /var/lib/kubelet labeled as svirt_sandbox_file_t because we do container data storage under that location.
Guys, Please make deal which label is better and right for /var/lib/kubelet. Dan, If this solution is wrong, please switch it to ASSIGNED. Thanks.
one label works, one label just flat is impossible to use. We go with my way to solve the (many) real customer issues now. pmorie/dwalsh can work this week to look for a better long term solution which is likely to require extensive userspace rewrites. Which take a long time to get upstream. But for now, I know Dan doesn't like it, but sandbox_file_t:s0 on /var/lib/kubelet.
Paul Morie and I had a talk on bluejeans, and I believe just changing kubernetes to always specify the :Z will fix the issue.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2016-2283.html