Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OCPBUGS-16877: Update etcd member rules texts' to align with the checks #10970

Merged

Conversation

yuumasato
Copy link
Member

Description:

  • Update description mention the actual checked paths.
    These rules now check /etc/kubernetes/manifests/etcd-pod.yaml.

Rationale:

@yuumasato yuumasato added OpenShift OpenShift product related. CIS CIS Benchmark related. labels Aug 9, 2023
@github-actions
Copy link

github-actions bot commented Aug 9, 2023

Start a new ephemeral environment with changes proposed in this pull request:

Fedora Environment
Open in Gitpod

Oracle Linux 8 Environment
Open in Gitpod

These rules now check /etc/kubernetes/manifests/etcd-pod.yaml.
@yuumasato yuumasato force-pushed the update_etcd_member_rules_text branch from a32fe27 to e6dbdbd Compare August 10, 2023 13:19
Copy link
Collaborator

@rhmdnd rhmdnd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@codeclimate
Copy link

codeclimate bot commented Aug 10, 2023

Code Climate has analyzed commit e6dbdbd and detected 0 issues on this pull request.

The test coverage on the diff in this pull request is 100.0% (50% is the threshold).

This pull request will bring the total coverage in the repository to 53.3% (0.0% change).

View more on Code Climate.

@rhmdnd rhmdnd merged commit 67ff2fc into ComplianceAsCode:master Aug 10, 2023
31 of 34 checks passed
@BhargaviGudi
Copy link
Collaborator

/hold

@openshift-ci openshift-ci bot added the do-not-merge/hold Used by openshift-ci-robot bot. label Aug 11, 2023
@BhargaviGudi
Copy link
Collaborator

Verification passed on 4.14.0-0.nightly-2023-08-10-072041 + compliance-operator.v1.2.0 + code from this PR

1. Install CO 1.2.0
2. $ oc compliance bind -N test profile/upstream-ocp4-cis profile/upstream-ocp4-cis-node
Creating ScanSettingBinding test
$ oc get scan
NAME                            PHASE   RESULT
upstream-ocp4-cis               DONE    NON-COMPLIANT
upstream-ocp4-cis-node-master   DONE    NON-COMPLIANT
upstream-ocp4-cis-node-worker   DONE    NON-COMPLIANT
3. Check for rule ocp4-file-permissions-etcd-member
$ oc get ccr | grep file-permissions-etcd-membe
upstream-ocp4-cis-node-master-file-permissions-etcd-member                     PASS     medium

@BhargaviGudi
Copy link
Collaborator

/unhold
/qe-approved

@openshift-ci openshift-ci bot removed the do-not-merge/hold Used by openshift-ci-robot bot. label Aug 11, 2023
@yuumasato yuumasato deleted the update_etcd_member_rules_text branch August 11, 2023 06:58
@Mab879 Mab879 added this to the 0.1.70 milestone Sep 14, 2023
@Mab879 Mab879 added the Update Rule Issues or pull requests related to Rules updates. label Oct 12, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CIS CIS Benchmark related. OpenShift OpenShift product related. Update Rule Issues or pull requests related to Rules updates.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants