Uploaded image for project: 'MicroShift'
  1. MicroShift
  2. USHIFT-1344

selinux and workload isolation audit

XMLWordPrintable

    • selinux audit
    • Strategic Product Work
    • False
    • Hide

      None

      Show
      None
    • False
    • Green
    • Done
    • OCPSTRAT-230 - General Availability of MicroShift X86
    • 0% To Do, 0% In Progress, 100% Done
    • Hide

      08/24/2023

      Only CI code reviews pending.

      Show
      08/24/2023 Only CI code reviews pending.

      Epic Goal

      • audit the selinux settings for MicroShift to ensure all binaries, data, and configuration files are using the correct labels, as close to the same as is possible with OpenShift
      • ensure that workloads in different namespaces run as different UIDs

      Why is this important?

      • security

      Scenarios

      1. ...

      Acceptance Criteria

      • CI - MUST be running successfully with tests automated
      • Release Technical Enablement - Provide necessary release enablement details and documents.
      • ...

      Dependencies (internal and external)

      1. ...

      Previous Work (Optional):

      Open questions::

      Done Checklist

      • CI - CI is running, tests are automated and merged.
      • Release Enablement <link to Feature Enablement Presentation>
      • DEV - Upstream code and tests merged: <link to meaningful PR or GitHub Issue>
      • DEV - Upstream documentation merged: <link to meaningful PR or GitHub Issue>
      • DEV - Downstream build attached to advisory: <link to errata>
      • QE - Test plans in Polarion: <link or reference to Polarion>
      • QE - Automated tests merged: <link or reference to automated tests>
      • DOC - Downstream documentation merged: <link to meaningful PR>

              ehila@redhat.com Egli Hila
              dhellman@redhat.com Doug Hellmann
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: