-
Story
-
Resolution: Done
-
Normal
-
None
-
None
-
None
-
2
-
False
-
False
-
OCPPLAN-6104 - FedRAMP moderate controls
-
Undefined
-
-
CMP Sprint 31, CMP Sprint 32, CMP Sprint 33
AU-4 wants:
“The organization allocates audit record storage capacity in accordance with [Assignment: organization-defined audit record storage requirements].”
This is normally achieved by a separate partition for /var/log. We don't seem to have such rule for RHCOS (the rules are there but they are commented out).
Acceptance criteria:
- test out the partitioning (https://docs.openshift.com/container-platform/4.7/installing/installing_platform_agnostic/installing-platform-agnostic.html#installation-user-infra-machines-advanced_vardisk_installing-platform-agnostic)
- create a CaC rule that checks if /var/log, /var/log/audit, /var/log/kube-apiserver, /var/log/openshift-apiservre and /var/log/oauth-apiserver are on separate partitions (this might be an overkill? Could we get away with just /var/log?)