Skip to content

Add Draft OCP4 STIG profile #8799

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 2 commits into from
Jun 1, 2022

Conversation

DhritiShikhar
Copy link
Contributor

Description:

  • Adds OCP4 STIG profile

Rationale:

@openshift-ci openshift-ci bot added the needs-ok-to-test Used by openshift-ci bot. label May 19, 2022
@openshift-ci
Copy link

openshift-ci bot commented May 19, 2022

Hi @DhritiShikhar. Thanks for your PR.

I'm waiting for a ComplianceAsCode member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@github-actions
Copy link

Start a new ephemeral environment with changes proposed in this pull request:

Open in Gitpod

Copy link
Collaborator

@jhrozek jhrozek left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Some nits inline about the metadata, but the profile itself looks good, thank you!


reference: https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Container_Platform_V1R3_SRG.zip

title: 'DISA STIG for Red Hat OpenShift Container Platform 4'
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you put a [DRAFT] into the title?

title: '[DRAFT] DISA STIG for Red Hat OpenShift Container Platform 4'

description: |-
This is a draft profile for experimental purposes. It is not based on the DISA STIG for OCP4, because one was not available at the time yet. This profile contains configuration checks that align to the DISA STIG for Red Hat OpenShift Container Platform 4.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, one more nit (my fault), can you keep the text within ~80 columns? (!fmt -80 in vim does the trick for me)

@codeclimate
Copy link

codeclimate bot commented May 19, 2022

Code Climate has analyzed commit a791d1f and detected 0 issues on this pull request.

View more on Code Climate.

Copy link
Collaborator

@jhrozek jhrozek left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jhrozek
Copy link
Collaborator

jhrozek commented May 19, 2022

@Mab879 hey, can you quickly scan the profile metadata if it aligns with what you've been using for RHEL STIG drafts?

Copy link
Member

@Mab879 Mab879 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overall, this looks good—just a couple of minor things.

@Mab879 Mab879 self-assigned this May 23, 2022
@Mab879 Mab879 added the OpenShift OpenShift product related. label May 23, 2022
@Mab879 Mab879 added this to the 0.1.63 milestone May 23, 2022
@Mab879 Mab879 merged commit 49d84d2 into ComplianceAsCode:master Jun 1, 2022
@yuumasato yuumasato changed the title Add OCP4 STIG profile Add Draft OCP4 STIG profile Jul 29, 2022
@yuumasato yuumasato added the Highlight This PR/Issue should make it to the featured changelog. label Jul 29, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Highlight This PR/Issue should make it to the featured changelog. needs-ok-to-test Used by openshift-ci bot. OpenShift OpenShift product related.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants