Skip to content

Update SLE15 public cloud profiles#14759

Open
jgleissner wants to merge 1 commit into
ComplianceAsCode:masterfrom
jgleissner:sle15-pubcloud-update
Open

Update SLE15 public cloud profiles#14759
jgleissner wants to merge 1 commit into
ComplianceAsCode:masterfrom
jgleissner:sle15-pubcloud-update

Conversation

@jgleissner
Copy link
Copy Markdown

Description:

This PR makes the following changes to the SLE15 profiles:

  • Drop smartcard related rules
  • Drop mount_option_dev_shm_noexec from SAP profile
  • Add profile for CHOST hardening

Rationale:

  • Public cloud VMs do not have smartcard readers so smartcard related rules in the public cloud profiles are pointless
  • mount_option_dev_shm_noexec seems to expect /dev/shm being mounted via /etc/fstab which is not the case in SLES so seems incompatible
  • For SLES instances that are optimized as container host we need a STIG based profile

Drop smartcard related rules.
Drop mount_option_dev_shm_noexec from SAP profile.
Add profile for CHOST hardening.
@jgleissner jgleissner requested a review from a team as a code owner June 3, 2026 12:03
@openshift-ci openshift-ci Bot added the needs-ok-to-test Used by openshift-ci bot. label Jun 3, 2026
@openshift-ci
Copy link
Copy Markdown

openshift-ci Bot commented Jun 3, 2026

Hi @jgleissner. Thanks for your PR.

I'm waiting for a ComplianceAsCode member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@Mab879 Mab879 added this to the 0.1.82 milestone Jun 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-ok-to-test Used by openshift-ci bot.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants