Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-7143

Request for a Global Bypass for ACS Policy

XMLWordPrintable

    • None
    • Product / Portfolio Work
    • None
    • False
    • Hide

      None

      Show
      None
    • Red Hat Advanced Cluster Security for Kubernetes
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      1. Proposed title of this feature request: Global Bypass for ACS Policy

      2. What is the nature and description of the request? Customer is asking for a way to define a Global Bypass to exclude specific system related Namespaces from the scope of policies. If a container falls within this bypass scope, no Policy is applied to that container. Although they know that there is a way to exclude or include certain namespaces or cluster on each policy, the customer is looking for a mechanism that exclude specific containers/namespace/cluster from all policy scope rules, without having to change the scope definition in each individual policy.

      3. Why does the customer need this? (List the business requirements here): For each policy the customer has to go one by one and exclude the openshift-* namespaces, so if ACS has 250 policies, he has to do that 250 times. They would like a way that they write the exclusion once and choose if they want to apply in one, a few or all policies in ACS

      4. List any affected packages or components. Red Hat Advanced Cluster Security

              bmichael@redhat.com Boaz Michaely
              rhn-support-oariasol Omar Arias Olave
              None
              Votes:
              1 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                None
                None