-
Feature Request
-
Resolution: Unresolved
-
Normal
-
None
-
None
-
None
-
Red Hat OpenShift Service on Amazon
1. Proposed title of this feature request: Support for End-point detection and response (EDR) capabilities on ROSA clusters
**
2. What is the nature and description of the request?: Customer (IBM) on this case 04038002 asked about how ROSA meets an IBM policy requirement to implement a centrally controlled, monitored, and updated end point detection and response (EDR) capability.
3. Why does the customer need this? (List the business requirements here):
Customer mentioned that they went through the security policy documents but they couldn't find information about End-point detection and response (EDR) capability which is the heart of IBM security.
They want to know how ROSA meets an IBM policy requirement to implement a centrally controlled, monitored, and updated endpoint detection and response (EDR) capability. Otherwise, they would have to install Crowdstrike-like daemonsets on ROSA.
Additionally, the Customer mentioned that, keeping Crowdstrike on Master nodes gives them the issue of limited support from the ROSA side, but not keeping Crowdstrike will impact business as it is prone to security issues.
We asked about this on a Jira ticket (https://issues.redhat.com/browse/OHSS-40635) but the SRE engineer informed that this is not something that they support or can provide a support exception for. An RFE for this was requested instead.