Q: Your organization is migrating production hosts to Red Hat Enterprise Linux (RHEL 9) with SELinux in `Enforcing` mode. When running containers mounting host directories (`docker run -v /data:/data`), processes running as root (`UID 0`) fail with `Permission denied` when reading or writing files. Disabling SELinux (`setenforce 0`) is forbidden by corporate security. You must explain how SELinux MCS category labels protect containers, apply the `:z` and `:Z` volume mount flags correctly, and avoid relabeling system directories.
Fix 'Permission denied' errors on SELinux-enforcing hosts (RHEL, Rocky, Fedora). Master the SELinux volume relabeling flags `:z` (shared label) and `:Z` (private unshared label).
Want to master this scenario in a live sandbox? KodeKloud's Docker Certified Associate (DCA) Hands-On Lab Course covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Understand SELinux Multi-Category Security (MCS) Container Labels
SELinux assigns unique category pairs (e.g., `s0:c123,c456`) to each container process (`svirt_lxc_net_t`). The host directory typically has the default `system_u:object_r:default_t` label. SELinux kernel hooks block the container from accessing the files because the MCS categories do not match, regardless of Linux numeric UID permissions.
# Inspect process SELinux context inside container
docker run --rm alpine ps -eZ
# Output: system_u:system_r:container_t:s0:c12,c34 1 ...
# Inspect host directory SELinux label
ls -dZ /data
# Output: unconfined_u:object_r:default_t:s0 /data (Access Denied to container_t!)
Differentiate Between the :z and :Z Relabeling Flags
Docker provides volume relabeling suffixes: `:z` relabels the directory with the shared container label (`container_file_t`), allowing multiple containers to read and write the volume concurrently. `:Z` relabels the directory with an exclusive private label (`container_file_t` with private MCS categories), ensuring only that specific container can access the files.
<!-- SELinux Mount Flags -->
:z (Shared Label):
docker run -v /data:/data:z app1
docker run -v /data:/data:z app2 (Both containers can safely share /data)
:Z (Private Exclusive Label):
docker run -v /data:/data:Z app1 (Strictly locked to app1; other containers blocked)
Apply the Appropriate Flag in CLI and Docker Compose
Configure the bind mount with the `:z` or `:Z` modifier.
# Docker CLI with shared SELinux relabeling
docker run -d \
--name web-app \
-v /var/www/html:/usr/share/nginx/html:z \
nginx:alpine
# Docker Compose
services:
db:
image: postgres:16
volumes:
- ./pgdata:/var/lib/postgresql/data:Z # Private exclusive mount
WARNING: Never Use :z or :Z on System Root Directories
Never use `:z` or `:Z` on host system directories like `/etc`, `/usr`, `/var`, or `/home`. Doing so recursively relabels critical host system files to `container_file_t`, breaking SSH logins, systemd daemons, and host services.
# DANGEROUS DISASTER ANTI-PATTERN:
# docker run -v /etc:/host-etc:Z alpine <-- BREAKS HOST OS SELINUX LABELS!
- W
- e
- r
- e
- s
- o
- l
- v
- e
- d
- v
- o
- l
- u
- m
- e
- p
- e
- r
- m
- i
- s
- s
- i
- o
- n
- e
- r
- r
- o
- r
- s
- o
- n
- o
- u
- r
- h
- a
- r
- d
- e
- n
- e
- d
- R
- H
- E
- L
- 9
- c
- l
- u
- s
- t
- e
- r
- s
- w
- i
- t
- h
- o
- u
- t
- d
- i
- s
- a
- b
- l
- i
- n
- g
- S
- E
- L
- i
- n
- u
- x
- b
- y
- a
- p
- p
- l
- y
- i
- n
- g
- D
- o
- c
- k
- e
- r
- '
- s
- `
- :
- z
- `
- a
- n
- d
- `
- :
- Z
- `
- m
- o
- u
- n
- t
- f
- l
- a
- g
- s
- .
- A
- d
- d
- i
- n
- g
- `
- :
- z
- `
- a
- u
- t
- o
- m
- a
- t
- i
- c
- a
- l
- l
- y
- r
- e
- l
- a
- b
- e
- l
- s
- a
- p
- p
- l
- i
- c
- a
- t
- i
- o
- n
- m
- o
- u
- n
- t
- p
- o
- i
- n
- t
- s
- t
- o
- `
- c
- o
- n
- t
- a
- i
- n
- e
- r
- _
- f
- i
- l
- e
- _
- t
- `
- ,
- e
- n
- a
- b
- l
- i
- n
- g
- s
- e
- a
- m
- l
- e
- s
- s
- c
- o
- n
- t
- a
- i
- n
- e
- r
- r
- e
- a
- d
- /
- w
- r
- i
- t
- e
- a
- c
- c
- e
- s
- s
- w
- h
- i
- l
- e
- m
- a
- i
- n
- t
- a
- i
- n
- i
- n
- g
- c
- o
- m
- p
- l
- e
- t
- e
- k
- e
- r
- n
- e
- l
- -
- l
- e
- v
- e
- l
- m
- a
- n
- d
- a
- t
- o
- r
- y
- a
- c
- c
- e
- s
- s
- c
- o
- n
- t
- r
- o
- l
- .