Uploaded image for project: 'OpenShift Edge Enablement'
  1. OpenShift Edge Enablement
  2. OCPEDGE-63

LVMS FIPS Build and Delivery Compliance

XMLWordPrintable

    • LVMS FIPS Build and Delivery Compliance
    • Product / Portfolio Work
    • OCPSTRAT-700LVM Storage designed for FIPS
    • 0% To Do, 0% In Progress, 100% Done
    • False
    • Hide

      None

      Show
      None
    • False
    • Green
    • Hide
      2024-01-17:
      Dev - Green - FIPS adjustments completed, all NVRs for 4.15.0-2 and up are FIPS-compliant and can be tested on FIPS nodes
      Docs - Green - N/A
      QE - Green - QE Complete

       

      Show
      2024-01-17 : Dev - Green - FIPS adjustments completed, all NVRs for 4.15.0-2 and up are FIPS-compliant and can be tested on FIPS nodes Docs - Green - N/A QE - Green - QE Complete  
    • M

      OCP/Telco Definition of Done
      Epic Template descriptions and documentation.

      <--- Cut-n-Paste the entire contents of this description into your new Epic --->

      Epic Goal

      • FIPS Compliance should be ensured by default on LVMS, so that any OpenShift installation can use it without thinking twice about storage compliance

      Why is this important?

      • Customers targeting OpenShift / Microshift with FIPS compliance enabled will also require all downstream operators to be compliant as well. This means that LVMS is unusable if FIPS compliance is not assured

      Scenarios

      1. Have FIPS-compliant builds and releases that pass the checks defined in FIPS checks for OCP . This is especially relevant for all build artifacts
        1. LVM Operator
        2. All Sidecar Containers (if applicable)
        3. TopoLVM from upstream
      2. Allow FIPS-compliant compilation for all aforementioned sources
      3. Have all of these sources shipped by default and adjust our registered CSV to mark FIPS compliance

      Acceptance Criteria

      • CI - MUST be switched to be fully FIPS-compliant and reject non-compliant builds
      • Test Suite and Local Builds must be able to use dynamically linked FIPS enabled builds for closeness to Production builds
      • CI - MUST include a verification on builds to ensure FIPS compliance

      Dependencies (internal and external)

      1. Openshift 4.14 release out so we can start with 4.15 images on the builders

      Previous Work (Optional):

      Open questions::

      1.  

      Done Checklist

      • CI - CI is running, tests are automated and merged.
      • Release Enablement <link to Feature Enablement Presentation>
      • DEV - Upstream code and tests merged: <link to meaningful PR or GitHub Issue>
      • DEV - Upstream documentation merged: <link to meaningful PR or GitHub Issue>
      • DEV - Downstream build attached to advisory: <link to errata>
      • QE - Test plans in Polarion: <link or reference to Polarion>
      • QE - Automated tests merged: <link or reference to automated tests>
      • DOC - Downstream documentation merged: <link to meaningful PR>

              rh-ee-jmoller Jakob Moeller (Inactive)
              rhn-support-cscribne Chad Scribner
              None
              Rahul Deore Rahul Deore
              Daniel Macpherson Daniel Macpherson
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: