-
Feature Request
-
Resolution: Unresolved
-
Normal
-
None
-
None
1. Proposed title of this feature request
Automate scc rules for CIS Profile
2. What is the nature and description of the request?
Avoid manual intervention for rules that can be automated such as scc related rules:
ocp4-cis-scc-drop-container-capabilities MANUAL
ocp4-cis-scc-limit-ipc-namespace MANUAL
ocp4-cis-scc-limit-net-raw-capability MANUAL
ocp4-cis-scc-limit-network-namespace MANUAL
ocp4-cis-scc-limit-privilege-escalation MANUAL
ocp4-cis-scc-limit-privileged-containers MANUAL
ocp4-cis-scc-limit-process-id-namespace MANUAL
ocp4-cis-scc-limit-root-containers MANUAL
As rule:
ocp4-cis-scc-limit-container-allowed-capabilities PASS
Where the scc from cluster needs are excluded
The automation of the rules will help customer to avoid the additional tailoring configuration task and will help to get more accurate report.
3. Why does the customer need this? (List the business requirements here)
Customer is willing to deploy Compliance Operator as official reporting tool fo security purpose
4. List any affected packages or components.
CIS profile
- is cloned by
-
CMP-2128 [Compliance Operator] automate manuals scc rules for CIS Profile
- New