secubox-deb/common/apparmor/usr.lib.secubox.mail
CyberMind-FR d7c8cc19e9 Add secubox-repo and secubox-hardening modules, CI/CD workflows
New modules (35 total):
- secubox-repo v1.0.0: APT repository management
  - repoctl CLI for package management
  - GPG key generation and signing
  - Multi-distribution support (bookworm, trixie)
  - Web dashboard for repository status

- secubox-hardening v1.0.0: Kernel and system hardening
  - hardeningctl CLI for security management
  - Sysctl hardening (ASLR, kptr_restrict, SYN cookies)
  - Module blacklist (uncommon protocols, filesystems)
  - Security benchmark with 100% score on VM

CI/CD workflows:
- build-packages.yml: Dynamic matrix for all packages
- build-image.yml: 5 board images with compression
- publish-packages.yml: APT repo publishing
- release.yml: Unified release orchestration

APT repository scripts:
- export-secrets.sh: Export GPG/SSH keys for GitHub Actions
- local-publish.sh: Local test server
- install.sh: User installation script

Security (Phase 5):
- AppArmor profiles for all services
- Audit rules for SecuBox services
- build-all.sh for local builds

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-03-22 22:15:01 +01:00

48 lines
945 B
Plaintext

# AppArmor profile for secubox-mail
# Mail Server Management API (Postfix/Dovecot LXC)
#include <tunables/global>
profile secubox-mail /usr/lib/secubox/mail/** {
#include <abstractions/base>
#include <abstractions/python>
#include <abstractions/nameservice>
# SecuBox base permissions
#include <local/secubox-base>
# Mail data directory
/srv/mail/ r,
/srv/mail/** rwk,
# LXC container management
/srv/lxc/ r,
/srv/lxc/** rwk,
/usr/bin/lxc-* Ux,
/usr/sbin/lxc-* Ux,
# LXC control scripts
/usr/sbin/mailserverctl Ux,
/usr/sbin/roundcubectl Ux,
/usr/sbin/mailctl Ux,
# ACME certificates
/etc/acme/ r,
/etc/acme/** rw,
/root/.acme.sh/ r,
/root/.acme.sh/** r,
# OpenSSL for certificate operations
/usr/bin/openssl Ux,
# Process management
/proc/ r,
/proc/[0-9]*/ r,
/proc/[0-9]*/stat r,
/proc/[0-9]*/status r,
# Deny sensitive paths
deny /etc/shadow r,
deny /etc/gshadow r,
}