INC-2026-03-10: vault-backup.service SELinux Failure
Incident Summary
| Field | Value |
|---|---|
Detected |
2026-03-10 ~02:21 UTC (timer run) |
Resolved |
2026-03-10 15:33 UTC |
Duration |
~13 hours (overnight, fixed in morning) |
Severity |
P3 (Medium) - Backups failing, no data loss |
Impact |
Automated Vault backups to NAS not running |
Root Cause |
SELinux |
Timeline
| Time (UTC) | Event |
|---|---|
02:21 |
vault-backup.timer triggered, service failed with exit code 14 |
14:41 |
Investigation started during worklog review |
15:19 |
Root cause identified: SELinux AVC denial |
15:22 |
First fix attempt (audit2allow) - partial, new denial appeared |
15:27 |
Second denial ( |
15:29 |
Third denial ( |
15:32 |
Set rsync_t to permissive, ran service, captured ALL denials |
15:33 |
Installed complete policy module, tested in enforcing mode - SUCCESS |
Symptoms
-
systemctl status vault-backup.serviceshowedfailed (Result: exit-code) -
Exit code 14 (rsync IPC error)
-
Error message:
rsync: [sender] Failed to exec ssh: Permission denied (13) -
Manual execution as root worked fine