Uploaded image for project: 'Cloud Infrastructure Security & Compliance'
  1. Cloud Infrastructure Security & Compliance
  2. CMP-1016

[SC-6]: CaC rule that checks workloads for resource requests/limits

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Normal Normal
    • None
    • None
    • None
    • 1
    • False
    • False
    • OCPPLAN-6104 - FedRAMP moderate controls
    • Undefined
    • CMP Sprint 41

      To cover SC-6, we should create a CaC rule that checks that all workloads (maybe except those in openshift- namespaces?) have resource requests and limits set.

       

      This needs a bit more brainstorming, but the idea was to:

       - scan all namespaces but openshift-* and kube-*

       - create an enforcement rule for CO/OPA that would prevent creating new workloads without resource requests and limits

       - the rule should skip any namespaces labeled with a special label to be able to special-case namespaces that should be exempt or add a variable that would list the exempt namespaces--

              wenshen@redhat.com Vincent Shen
              jhrozek@redhat.com Jakub Hrozek (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: