Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-8423

Add lastUpdated field to list of custom policy fields

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • None
    • rhacs
    • None
    • None
    • Product / Portfolio Work
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      1. Proposed title of this feature request

      Add lastUpdated field to list of custom policy fields

      2. What is the nature and description of the request?

      We are looking to enhance our cybersecurity posture, and along with that we would like to start implementing preventative policies within ACS to deny stale images from being deployed. When trying to do that, we see the only applicable field we can use within the custom policy creation process is the "Image age" field. This does not work well with our image creation process, since we use base images and patch layers on top of them. This ends up appearing as if we are using old images when in reality they have been updated.

       

      Looking in the ImageService API, and podman inspect output, we can see that the images have a lastUpdated field. Would it be possible to add the lastUpdated field to the list of fields in the custom policy rules? Describe the impact to you or the business This would much better fit how we patch images and would greatly assist us in the enforcement of denying stale images from being deployed.

      3. Why does the customer need this? (List the business requirements here)

      This would much better fit how we patch images and would greatly assist us in the enforcement of denying stale images from being deployed.

       

      4. List any affected packages or components.

       

      None known

              dcaspin@redhat.com Doron Caspin
              rhn-support-rcullenk Robert Cullen-Keel
              None
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                None
                None