Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-5953

ACS operator namespace should ship with a network-policy

XMLWordPrintable

    • False
    • None
    • False
    • Rox Sprint 73B - Global, Rox Sprint 73C - Global

      CUSTOMER PROBLEM

      ACS is installed and upgraded using an operator. The ACS operator is deployed in the namespace "rhacs-operator". The OpenShift CIS compliance scan fails against all namespaces not prefixed with "openshift-" and without NetworkPolicies.

      Since the ACS operator namespace "rhacs-operator"

      1. is not prefixed with "openshift" and
      2. does not have any a network policy configured; it fails the compliance check.

      The failed compliancecheckresult is named "ocp4-cis-configure-network-policies-namespaces".

      USERS

      Security teams

      ACCEPTANCE CRITERIA

      • Out of the box ACS operator namespace "rhacs-operator" must have a network policy configured. 
      • OpenShift CIS compliance scan, of the ACS operator namespace "rhacs-operator", should not fail with compliance check named "ocp4-cis-configure-network-policies-namespaces"

              dcaspin@redhat.com Doron Caspin
              sbadve@redhat.com Shubha Badve
              Anjali Telang, Boaz Michaely, Doron Caspin, JP Jung, Maria Simon Marcos, Shubha Badve
              ACS Install
              Votes:
              1 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: