Uploaded image for project: 'OpenShift Container Platform (OCP) Strategy'
  1. OpenShift Container Platform (OCP) Strategy
  2. OCPSTRAT-2225

Improve Compliance Operator to Run Control Plane Checks Only on Master Nodes

XMLWordPrintable

    • Icon: Feature Feature
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • Future Sustainability
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      When using the Compliance Operator with the OCP4-CIS profile, some rules meant for control plane components (like API server or etcd) are being checked on all nodes, including worker nodes. Since these components don’t exist on worker nodes, the scan shows the result as NOT APPLICABLE for those rules.

      While this is correct, it can confuse users and clutter the compliance reports. The customer expects the operator to automatically run control plane checks only on master nodes, and not evaluate them at all on worker nodes.

      Currently, this behavior can only be achieved by:

      • Creating separate scan settings for master and worker nodes
      • Using tailored profiles to manually disable rules

      This setup requires extra effort and isn't ideal for customers using the operator.

      The customer is requesting a built-in enhancement where the Compliance Operator:

      • Detects node roles (master/worker)
      • Applies rules only to the appropriate nodes
      • Avoids showing NOT APPLICABLE results

              Unassigned Unassigned
              rhn-support-sakkulka Sakshi Kulkarni
              None
              None
              None
              None
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: