-
Sub-task
-
Resolution: Done
-
Undefined
-
None
-
None
-
None
-
False
-
None
-
False
-
CFE Sprint 216, CFE Sprint 217, CFE Sprint 218
Overview
Use custom SCC associated with an selinux policy without being privilege.
Investigate using the tool "Udica" creator - Lukas Vrabec (redhat).
Time box this task to 4 days (max)
Outcome
From the investigation find out :
- Is this at all feasible
- If it is feasible have a recommended work around and how to implement it in the operator code base.
- Example code etc
- Create the necessary JIRA story/stories with estimates (high level) of what the effort of work will be and link it to the Node Observability Epic https://issues.redhat.com/browse/CFE-240
- Unit tests to be completed and working
- Update documentation if needed
- Integration testing (ensure it works on baremetal cluster as well as aws. gcp if time permits)
- Update the security audit document (mitigation) https://docs.google.com/document/d/1D6Asw-dg1d6oii_ofThZiROnmvOl2XH8b559NnszCtk/edit#
- Liaise with the security audit team