Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-6742

RHACS: add option to use Cluster labels and Namespace labels in policy inclusion and exclusion

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Critical Critical
    • None
    • None
    • rhacs
    • False
    • None
    • False
    • Not Selected

      Currently, ACS policies are able to express inclusions and exclusions using:

      • cluster name
      • namespace name
      • deployment name, or deployment label key/value

      This request is to also allow label key/value on namespace and cluster, so that the supported list would look like:

      • cluster name, or cluster label key/value
      • namespace name, or namespace label key/value
      • deployment name, or deployment label key/value

       

      Why does the customer need this? (List the business requirements here)

      Customer manages security policies for monitoring 100+ clusters, and currently has to do a lot of manual work and updating to target specific deployments in particular clusters and or namespaces, which come and go out of existence. Customer is planning to move to our policy as code feature, and this request would help them with the maintainability of those policy CR files.

      List any affected packages or components.

      • Policies
      • Violations
      • config-controller

              bmichael@redhat.com Boaz Michaely
              vwilson@redhat.com Van Wilson
              Votes:
              1 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: