fapolicyd from podman
podman build -t fapolicyd .
podman run --rm --name fapolicyd --privileged --systemd true -v /tmp:/deny -v $PWD/etc/simple.rules:/etc/fapolicyd/fapolicyd.rules fapolicyd
podman exec -it fapolicyd bash -c '/deny/foo.sh'
podman exec -it fapolicyd journalctl -u fapolicyd