Uploaded image for project: 'Cloud Infrastructure Security & Compliance'
  1. Cloud Infrastructure Security & Compliance
  2. CMP-1600

Compliance Operator CIS Benchmark conflict

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • None
    • None
    • None
    • False
    • None
    • False

      1. Compliance Operator CIS Benchmark conflict

      2. The OpenShift Compliance Operator includes a CIS Benchmark rule set that enforces the OpenSCAP CIS OpenShift 4 Benchmark which includes Kubernetes CIS Benchmark 5.1.3. Defining OperatorGroups intentionally creates ClusterRoles with wildcards which violates one of the rules.

      3. Customers using the CIS Benchmark to harden there OpenShift clusters will see RBAC policies with wildcard verbs ("*"), in violation of the ocp4-cis-rbac-wildcard-use rule.

      4. Compliance Operator profiles

            Unassigned Unassigned
            dcaspin@redhat.com Doron Caspin
            Jakub Hrozek Jakub Hrozek
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated: