-
Notifications
You must be signed in to change notification settings - Fork 1.9k
CMP-4011: Document Custom OpenShift Compliance Scans #103789
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
|
@GroceryBoyJr: This pull request references CMP-4011 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "4.21.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
@GroceryBoyJr: This pull request references CMP-4011 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "4.21.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/retest |
9a05bfc to
69cf0fc
Compare
|
@GroceryBoyJr: This pull request references CMP-4011 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "4.21.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
91a3f36 to
5b9c98b
Compare
security/compliance_operator/co-scans/compliance-operator-customrules.adoc
Outdated
Show resolved
Hide resolved
security/compliance_operator/co-scans/compliance-operator-customrules.adoc
Outdated
Show resolved
Hide resolved
security/compliance_operator/co-scans/compliance-operator-customrules.adoc
Outdated
Show resolved
Hide resolved
5452596 to
1b8a9aa
Compare
1b8a9aa to
19340db
Compare
|
@GroceryBoyJr: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
| apiVersion: observability.openshift.io/v1 | ||
| resource: clusterlogforwarders | ||
| expression: | | ||
| clusterLogForwarderList.items.items.size() > 0 && |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
should be clusterLogForwarderList.items.size() > 0 &&
| NAME STATUS SEVERITY | ||
| logging-security-checks-clusterlogforwarder-secure-endpoints FAIL High | ||
|
|
||
| Step 5: Identify and fix non-compliant resources |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think the step 5 might not needed. You put too much time on the rule details. Actually the KCS is already available. Maybe you can change to another customrule as an example. And Focus on the customrule resource itself.
| Create a file named `clusterlogforwarder-secure-endpoints.yaml:` | ||
|
|
||
| apiVersion: compliance.openshift.io/v1alpha1 | ||
| kind: CustomRule |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Maybe annotaion needed to highlight this is CustomRule.
| and do not set tls.insecureSkipVerify=true. | ||
| severity: High | ||
| checkType: Platform | ||
| scannerType: CEL |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Maybe annotaion needed to highlight the scannerType is CEL.
|
I think you also need to highlight the feature is tach preview status, only platform type customrule needed |
Version(s):
Issue: https://issues.redhat.com/browse/CMP-4011
Link to docs preview: https://103789--ocpdocs-pr.netlify.app/openshift-enterprise/latest/welcome/
QE review:
Additional information: