Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-6430

Create an automated check for pods (not part of a replicated controller) that are running with the default SA

XMLWordPrintable

    • None
    • Product / Portfolio Work
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None

      Description of problem:
      Compliance rule ocp4-cis-accounts-unique-service-account is reported as "MANUAL" This Request is opened to have the ability to automate this verification.

      Automated rule should be able to verify is a deployment is using the default SA or not.

      Recommendation is not to use the default SA therefor if it's the case, the rule should fail.

       
      Version-Release number of selected component (if applicable):
      1.x

      How reproducible:
      always

      Steps to Reproduce:
      1. Create the scansettingbinding with CIS Benchmark profiles to verify
      2. Check the results

      Actual results:
      Rule is not being verified in an automatic way

      Expected results:
      Rule should be able to verify if the default SA is being used or not

      Additional info:

              lbragsta@redhat.com Lance Bragstad
              rhn-support-pescorza Pamela Lizeth Escorza Gil
              None
              Votes:
              1 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                None
                None