Skip to content

Conversation

@amolnar-gh
Copy link
Contributor

@amolnar-gh amolnar-gh commented Jul 15, 2025

@openshift-ci openshift-ci bot added the size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. label Jul 15, 2025
@amolnar-gh amolnar-gh force-pushed the TELCODOCS-2171-security branch from 024562c to 610d513 Compare July 15, 2025 12:28
@openshift-ci openshift-ci bot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. labels Jul 15, 2025
@amolnar-gh
Copy link
Contributor Author

amolnar-gh commented Jul 15, 2025

Comment to peer reviewer: No files have been deleted. They've been renamed to remove telco from the file names but for some reason, they show up as deleted/new files.

@rfisher001
Copy link

LGTM

@amolnar-gh amolnar-gh force-pushed the TELCODOCS-2171-security branch from 5f3d546 to e765e29 Compare July 18, 2025 09:06
Copy link
Contributor

@rohennes rohennes left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great work, few small nits


:_mod-docs-content-type: CONCEPT
[id="security-infra_{context}"]
= Bare metal-based infrastructure
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
= Bare metal-based infrastructure
= Bare-metal infrastructure

* Cluster roles can be defined at the cluster level. They are not tied to a single namespace. They can apply across all namespaces or specific namespaces when you bind them to users, groups, or service accounts.
* Project roles can be created within a specific namespace, and they only apply to that namespace. You can assign permissions to specific users to create roles and role bindings within their namespace, ensuring they do not affect other namespaces.
Bindings:: Associations between users and/or groups with a role. You can create a role binding to connect the rules in a role to a specific user ID or group. This brings together the role and the user or group, defining what actions they can perform.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

and/or guidance from IBM style guide:

Do not use. Depending on the context, use one of the following constructions: a and b, a or b, or a, b, or both.

The construction and/or can be ambiguous and causes translation problems.

[id="security-operational-rbac-considerations_{context}"]
== Operational RBAC considerations

To reduce operational overhead, it is important to manage access through groups rather than handling individual user IDs across multiple clusters. By managing groups at an organizational level, you can streamline access control and simplify administration across your organization.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
To reduce operational overhead, it is important to manage access through groups rather than handling individual user IDs across multiple clusters. By managing groups at an organizational level, you can streamline access control and simplify administration across your organization.
To reduce operational overhead, manage access through groups rather than handling individual user IDs across multiple clusters. By managing groups at an organizational level, you can streamline access control and simplify administration across your organization.

[id="security-sec-considerations-{context}"]
= Security considerations

Corporate workloads handle sensitive data and demand high reliability. A single security vulnerability can lead to broader, cluster-wide compromises. With numerous components running on an OpenShift cluster, each component must be secured to prevent any breach from escalating. Ensuring security across the entire infrastructure, including all components, is essential to maintaining the integrity of the network and avoiding vulnerabilities.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Corporate workloads handle sensitive data and demand high reliability. A single security vulnerability can lead to broader, cluster-wide compromises. With numerous components running on an OpenShift cluster, each component must be secured to prevent any breach from escalating. Ensuring security across the entire infrastructure, including all components, is essential to maintaining the integrity of the network and avoiding vulnerabilities.
Workloads might handle sensitive data and demand high reliability. A single security vulnerability might lead to broader, cluster-wide compromises. With numerous components running on an {product-title} cluster, you must secure each component to prevent any breach from escalating. Ensuring security across the entire infrastructure, including all components, is essential to maintaining the integrity of the network and avoiding vulnerabilities.

[id="security-sec-considerations-{context}"]
= Security considerations

Corporate workloads handle sensitive data and demand high reliability. A single security vulnerability can lead to broader, cluster-wide compromises. With numerous components running on an OpenShift cluster, each component must be secured to prevent any breach from escalating. Ensuring security across the entire infrastructure, including all components, is essential to maintaining the integrity of the network and avoiding vulnerabilities.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Replace OpenShift with {product-title} globally

@amolnar-gh amolnar-gh force-pushed the TELCODOCS-2171-security branch 2 times, most recently from 361de76 to 7c92448 Compare July 21, 2025 10:46
@amolnar-gh amolnar-gh force-pushed the TELCODOCS-2171-security branch from 7c92448 to bb77e90 Compare July 22, 2025 13:19
@openshift-ci
Copy link

openshift-ci bot commented Jul 22, 2025

@amolnar-rh: all tests passed!

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@openshift-bot
Copy link

Issues go stale after 90d of inactivity.

Mark the issue as fresh by commenting /remove-lifecycle stale.
Stale issues rot after an additional 30d of inactivity and eventually close.
Exclude this issue from closing by commenting /lifecycle frozen.

If this issue is safe to close now please do so with /close.

/lifecycle stale

@openshift-ci openshift-ci bot added the lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. label Oct 21, 2025
@amolnar-gh
Copy link
Contributor Author

@rohennes Hey! Could you please help me see if these PRs are needed? Can I close them or do you want me to keep this (and the rest of the Day2Ops) PRs open?

@rohennes
Copy link
Contributor

@rohennes Hey! Could you please help me see if these PRs are needed? Can I close them or do you want me to keep this (and the rest of the Day2Ops) PRs open?

Hey, who is this external contributor I see before me!!?? :-P

Yeah you can close it if you like, Lluis CP'd it to his own PR. Hope all going well

@amolnar-gh
Copy link
Contributor Author

@rohennes Thank you, Ronan! Everything is going really great, I can't complain. Please say hi to team for me <3 <3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants