-
Notifications
You must be signed in to change notification settings - Fork 1.8k
OSDOCS-4462: Adding notice of future plans to enable PSA restricted e… #52541
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
OSDOCS-4462: Adding notice of future plans to enable PSA restricted e… #52541
Conversation
|
🤖 Updated build preview is available at: Build log: https://circleci.com/gh/ocpdocs-previewbot/openshift-docs/5419 |
16423f2 to
3ca2849
Compare
3ca2849 to
1f06eaa
Compare
1f06eaa to
812d3d5
Compare
812d3d5 to
851c88d
Compare
|
@stlaz Okay so I played with this for awhile. I incorporated some of what you provided, but I didn't want to make it too explicit of step-by-step instructions on how to resolve issues. Especially since this is just the release notes. Let me know how this looks, if this is sufficient enough information to get people started early looking at this before restricted enforcement is turned on for 4.13. For 4.13, I think we'll want to add some more explicit steps on troubleshooting/fixing these violations. But that doesn't have to be now. We could even consider adding this in a future 4.12.z update if we do want to get it earlier. But again, the details don't need to be here and now in the release notes. Let me know what you think, and if you have any feedback. Thanks! |
stlaz
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
One bit that needs improving but I think that it looks good otherwise
851c88d to
8bb4bb6
Compare
|
@xingxingxia Can you please review this update, to give customers a heads up about restricted enforcement planned for 4.13? |
|
FYI @anjaltelang |
|
@zhouying7780 could you help review? |
|
/lgtm |
|
/label peer-review-in-progress |
sheriff-rh
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
One question, otherwise looks good!
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Interestingly, there is an "Identifying pod security violations" procedure module called modules/security-context-constraints-psa-alert-eval.adoc but I don't see it rendered in your build preview. But it is in the pull request where you added it in 3 months ago in #50631.
Am I missing something?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
That's really weird, I swear I rebased and that link worked. I will try rebasing again to make sure it links properly before merging. Thanks!
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Rebased and it's good now. Thanks again!
|
/label peer-review-done |
8bb4bb6 to
f3a80a0
Compare
|
New changes are detected. LGTM label has been removed. |
…nforcement
Version(s):
4.12
Issue:
https://issues.redhat.com/browse/OSDOCS-4462
Link to docs preview:
https://52541--docspreview.netlify.app/openshift-enterprise/latest/release_notes/ocp-4-12-release-notes.html#ocp-4-12-psa-restricted-enforcement
QE review:
Additional information: