Talk describing how to bring Proactive security to your systems by ensuring that SELinux is enforcing the security policy. This process comprises of steps like relabeling files (i.e. fixing SELinux labels on the system), handling potentional SELinux denials in Permissive mode in which Security policy is not enforced. I'll explain how to have SELinux under control using our userspace tooling. The talk will conclude by showcasing how the changes done during this talk can be distributed to multiple systems using ansible.