SELinux hosts

Nothing to configure. With SELinux enforcing (Fedora, RHEL, CentOS and derivatives), the container must be allowed to read its bind-mounted files. So the mounts in docker-compose.prod.yml and the Ansible template (nginx.conf, nginx/certs, /etc/letsencrypt) carry the :z relabel option, a no-op elsewhere.

Edit this page on GitHub