Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-7435

Feature Request for GitOps Configurable Policies in RHACS

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Won't Do
    • Icon: Normal Normal
    • None
    • 4.7
    • rhacs, rhacs-policy
    • None
    • None
    • Product / Portfolio Work
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      The customer has requested a feature enhancement for Red Hat Advanced Cluster Security (RHACS) on an OpenShift Cluster to enable GitOps configurability for policies. They have established several policies using the RHACS Policy Engine, which are currently managed manually through the GUI. The customer seeks a solution that allows for persistent and reproducible configurations via GitOps, specifically the ability to declaratively define these policies as CustomResources. They have identified two primary use cases: disaster recovery and policy staging across clusters.However, the customer has already tested [Creating policies in code by constructing a CR] and is working as expected but the customer mentioned below use case, is it something we can help the customer with RFE request?
       
      Customers setup the process baselines for their applications and we want them to persist in the case of disasterrecovery or cluster recreation and we want to stage them from dev, to qa to prod clusters. Idealy we would like our customers to be able to stage their policy and network baselines themselves in a multitenant way, without being able to overwrite other configs.

       

      Slack thread: 

      https://redhat-internal.slack.com/archives/C01R0E7CVMX/p1744214258290069?thread_ts=1744187586.406439&cid=C01R0E7CVMX 

              bmichael@redhat.com Boaz Michaely
              rhn-support-alaxkar Ayush Laxkar
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved:
                None
                None