Skip to content

Conversation

@yuumasato
Copy link
Member

Description:

  • Update description mention the actual checked paths.
    These rules now check /etc/kubernetes/manifests/etcd-pod.yaml.

Rationale:

@yuumasato yuumasato added OpenShift OpenShift product related. CIS CIS Benchmark related. labels Aug 9, 2023
@yuumasato yuumasato requested review from Vincent056 and rhmdnd August 9, 2023 16:43
@github-actions
Copy link

github-actions bot commented Aug 9, 2023

Start a new ephemeral environment with changes proposed in this pull request:

Fedora Environment
Open in Gitpod

Oracle Linux 8 Environment
Open in Gitpod

These rules now check /etc/kubernetes/manifests/etcd-pod.yaml.
@yuumasato yuumasato force-pushed the update_etcd_member_rules_text branch from a32fe27 to e6dbdbd Compare August 10, 2023 13:19
Copy link
Collaborator

@rhmdnd rhmdnd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@qlty-cloud-legacy
Copy link

Code Climate has analyzed commit e6dbdbd and detected 0 issues on this pull request.

The test coverage on the diff in this pull request is 100.0% (50% is the threshold).

This pull request will bring the total coverage in the repository to 53.3% (0.0% change).

View more on Code Climate.

@rhmdnd rhmdnd merged commit 67ff2fc into ComplianceAsCode:master Aug 10, 2023
@BhargaviGudi
Copy link
Collaborator

/hold

@openshift-ci openshift-ci bot added the do-not-merge/hold Used by openshift-ci-robot bot. label Aug 11, 2023
@BhargaviGudi
Copy link
Collaborator

Verification passed on 4.14.0-0.nightly-2023-08-10-072041 + compliance-operator.v1.2.0 + code from this PR

1. Install CO 1.2.0
2. $ oc compliance bind -N test profile/upstream-ocp4-cis profile/upstream-ocp4-cis-node
Creating ScanSettingBinding test
$ oc get scan
NAME                            PHASE   RESULT
upstream-ocp4-cis               DONE    NON-COMPLIANT
upstream-ocp4-cis-node-master   DONE    NON-COMPLIANT
upstream-ocp4-cis-node-worker   DONE    NON-COMPLIANT
3. Check for rule ocp4-file-permissions-etcd-member
$ oc get ccr | grep file-permissions-etcd-membe
upstream-ocp4-cis-node-master-file-permissions-etcd-member                     PASS     medium

@BhargaviGudi
Copy link
Collaborator

/unhold
/qe-approved

@openshift-ci openshift-ci bot removed the do-not-merge/hold Used by openshift-ci-robot bot. label Aug 11, 2023
@yuumasato yuumasato deleted the update_etcd_member_rules_text branch August 11, 2023 06:58
@Mab879 Mab879 added this to the 0.1.70 milestone Sep 14, 2023
@Mab879 Mab879 added the Update Rule Issues or pull requests related to Rules updates. label Oct 12, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CIS CIS Benchmark related. OpenShift OpenShift product related. Update Rule Issues or pull requests related to Rules updates.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants