Uploaded image for project: 'Cloud Infrastructure Security & Compliance'
  1. Cloud Infrastructure Security & Compliance
  2. CMP-1600

Add a variable to exclude Red Hat operators from RBAC wildcard usage

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • None
    • Compliance Operator
    • Product / Portfolio Work
    • False
    • Hide

      None

      Show
      None
    • False

      1. Compliance Operator CIS Benchmark conflict

      2. The OpenShift Compliance Operator includes a CIS Benchmark rule set that enforces the OpenSCAP CIS OpenShift 4 Benchmark which includes Kubernetes CIS Benchmark 5.1.3. Defining OperatorGroups intentionally creates ClusterRoles with wildcards which violates one of the rules.

      3. Customers using the CIS Benchmark to harden there OpenShift clusters will see RBAC policies with wildcard verbs ("*"), in violation of the ocp4-cis-rbac-wildcard-use rule.

      4. Compliance Operator profiles

              Unassigned Unassigned
              dcaspin@redhat.com Doron Caspin
              Jakub Hrozek Jakub Hrozek (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: