Uploaded image for project: 'OpenShift Container Platform (OCP) Strategy'
  1. OpenShift Container Platform (OCP) Strategy
  2. OCPSTRAT-858

[kube-apiserver] - Minimize wildcard/privilege Usage in Cluster and Local Roles

XMLWordPrintable

    • BU Product Work
    • False
    • Hide

      None

      Show
      None
    • False
    • 50% To Do, 0% In Progress, 50% Done
    • 0
    • Backlog Refinement

      1. Proposed title of this feature request
      [kube-apiserver] - Minimize wildcard/privilege Usage in Cluster and Local Roles

      2. What is the nature and description of the request?
      According http://static.open-scap.org/ssg-guides/ssg-ocp4-guide-cis.html#xccdf_org.ssgproject.content_rule_rbac_wildcard_use the usage of wildcard in ClusterRole and Roles should be prevented as best as possible.

      Further, one should refrain from using `cluster-admin` permissions to comply with CIS security requirements.

      It's therefore requested to review the below serviceAccount and their associated Roles as they were found not to be compliant with the above and restrict permissions further to the extend possible.

      • system:serviceaccount:openshift-kube-apiserver-operator:kube-apiserver-operator
      • system:serviceaccount:openshift-kube-apiserver:installer-sa
      • system:serviceaccount:openshift-kube-apiserver:localhost-recovery-client

      3. Why does the customer need this? (List the business requirements here)
      Comply with general and recommended Kubernetes Security guidelines and therefore the platform should comply the same way as otherwise exceptions need to be requested for running OpenShift Container Platform 4.

      Also it's not clear that everything can be compliant with the common guidelines. In this case though, it's expected that these things are being documented to understand the reasoning being it.

      4. List any affected packages or components.
      kube-apiserver

              racedoro@redhat.com Ramon Acedo
              wcabanba@redhat.com William Caban
              Andrea Hoffer Andrea Hoffer
              William Caban William Caban
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: