#include profile haproxy /usr/sbin/haproxy { #include #include #include #include #include capability net_bind_service, capability setgid, capability setuid, capability kill, capability sys_resource, capability sys_chroot, capability net_admin, # those are needed for the stats socket creation capability chown, capability fowner, capability fsetid, network inet, network inet6, /etc/haproxy/* r, /usr/sbin/haproxy rmix, /dev/shm/haproxy_startup_logs_* rwlk, # old stats socket location, for compatibility /var/lib/haproxy/stats rwl, /var/lib/haproxy/stats.*.bak rwl, /var/lib/haproxy/stats.*.tmp rwl, # new stats socket location /run/haproxy/stats*.sock{,*.{bak,tmp}} rwl, /{,var/}run/haproxy/pid rw, /{,var/}run/haproxy/master.sock* rwlk, /sys/devices/system/node/ r, # Site-specific additions and overrides. See local/README for details. #include if exists #include if exists }