Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-6441

Ensure AIDE scans are disabled during cluster upgrades

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • None
    • False
    • None
    • False
    • Not Selected

      1. Proposed title of this feature request
      Ensure AIDE scans are disabled during cluster upgrades

      2. What is the nature and description of the request?
      The request is for FIO to pause all AIDE scanning during cluster upgrades to prevent any alerting due to file changes during an upgrade and prevent false alerts

      3. Why does the customer need this? (List the business requirements here)
      The File Integrity Operator (FIO) is utilized in FedRAMP ROSA clusters to ensure we are meeting requirements to monitor the security of clusters. FIO is deployed to all FedRAMP clusters shortly after completion of the cluster creation.

      Part of our requirement is to review any file system changes and ensure there are no security issues to address. During upgrades AIDE scans are still running which triggers the creation of the failed node configmaps with results. The creation of those configmaps is captured in Splunk and alerts us to review file changes as part of our requirement to review those changes. Every cluster upgrades is causing alerts and even though MUO is re-initing the AIDE configs after upgrades, we are still dealing with false poisitives during the upgrade.

      By disabling AIDE scans during an upgrade, where numerous files are expected to change, it reduces alerting noise, and also reduces the number of configmaps with failed results created on clusters which is manually cleaned up as part of our review process.

      4. List any affected packages or components.
      File Integrity Operator only

            wenshen@redhat.com Vincent Shen
            anatale.openshift Antony Natale
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: