mirror of
https://github.com/CyberMind-FR/secubox-deb.git
synced 2026-07-28 21:17:36 +00:00
New modules (35 total): - secubox-repo v1.0.0: APT repository management - repoctl CLI for package management - GPG key generation and signing - Multi-distribution support (bookworm, trixie) - Web dashboard for repository status - secubox-hardening v1.0.0: Kernel and system hardening - hardeningctl CLI for security management - Sysctl hardening (ASLR, kptr_restrict, SYN cookies) - Module blacklist (uncommon protocols, filesystems) - Security benchmark with 100% score on VM CI/CD workflows: - build-packages.yml: Dynamic matrix for all packages - build-image.yml: 5 board images with compression - publish-packages.yml: APT repo publishing - release.yml: Unified release orchestration APT repository scripts: - export-secrets.sh: Export GPG/SSH keys for GitHub Actions - local-publish.sh: Local test server - install.sh: User installation script Security (Phase 5): - AppArmor profiles for all services - Audit rules for SecuBox services - build-all.sh for local builds Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
48 lines
945 B
Plaintext
48 lines
945 B
Plaintext
# AppArmor profile for secubox-mail
|
|
# Mail Server Management API (Postfix/Dovecot LXC)
|
|
|
|
#include <tunables/global>
|
|
|
|
profile secubox-mail /usr/lib/secubox/mail/** {
|
|
#include <abstractions/base>
|
|
#include <abstractions/python>
|
|
#include <abstractions/nameservice>
|
|
|
|
# SecuBox base permissions
|
|
#include <local/secubox-base>
|
|
|
|
# Mail data directory
|
|
/srv/mail/ r,
|
|
/srv/mail/** rwk,
|
|
|
|
# LXC container management
|
|
/srv/lxc/ r,
|
|
/srv/lxc/** rwk,
|
|
/usr/bin/lxc-* Ux,
|
|
/usr/sbin/lxc-* Ux,
|
|
|
|
# LXC control scripts
|
|
/usr/sbin/mailserverctl Ux,
|
|
/usr/sbin/roundcubectl Ux,
|
|
/usr/sbin/mailctl Ux,
|
|
|
|
# ACME certificates
|
|
/etc/acme/ r,
|
|
/etc/acme/** rw,
|
|
/root/.acme.sh/ r,
|
|
/root/.acme.sh/** r,
|
|
|
|
# OpenSSL for certificate operations
|
|
/usr/bin/openssl Ux,
|
|
|
|
# Process management
|
|
/proc/ r,
|
|
/proc/[0-9]*/ r,
|
|
/proc/[0-9]*/stat r,
|
|
/proc/[0-9]*/status r,
|
|
|
|
# Deny sensitive paths
|
|
deny /etc/shadow r,
|
|
deny /etc/gshadow r,
|
|
}
|