Uploaded image for project: 'Red Hat Advanced Cluster Management'
  1. Red Hat Advanced Cluster Management
  2. ACM-4438

Add native Gatekeeper constraint support in the Policy Generator

XMLWordPrintable

    • 2
    • False
    • None
    • False
    • Hide

      Provide the required acceptance criteria using this template.
      * ...
      Show
      Provide the required acceptance criteria using this template. * ...
    • ACM-2707 - ACM Gatekeeper Enhancements
    • GRC Sprint 2023-05, GRC Sprint 2023-06
    • No

      Value Statement

      As a Policy Generator user, I'd like to generate policies which utilize the new native Gatekeeper constraint support in ACM so that I can just deploy my existing Gatekeeper constraints using ACM policies.

      Definition of Done for Engineering Story Owner (Checklist)

      • Create a new Policy Generator release branch since this will include a change in default behavior.
      • The Policy Generator's informGatekeeperPolicies field should default to false (currently true).
      • When informGatekeeperPolicies is set to false, treat input manifests that are Gatekeeper ConstraintTemplates and constraints as we do for policy manifests (e.g. a ConfigurationPolicy or CertificatePolicy). In other words, directly insert them in the generated policy's "policy-templates" array.

      Development Complete

      • The code is complete.
      • Functionality is working.
      • Any required downstream Docker file changes are made.

      Tests Automated

      • [x] Unit/function tests have been automated and incorporated into the
        build.
      • [x] 100% automated unit/function test coverage for new or changed APIs.

      Secure Design

      • [x] Security has been assessed and incorporated into your threat model.

      Multidisciplinary Teams Readiness

      Support Readiness

      • [x] The must-gather script has been updated.

              dhaiduce Dale Haiducek
              mprahl Matthew Prahl
              Derek Ho Derek Ho
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: