Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Some rules scan the hypershift management cluster

Đang mở
#14,151 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 2 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
38/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Đình trệ
Lĩnh vực
security

Hướng nghiên cứu

Bắt đầu với các định nghĩa rule được liệt kê và tài liệu về cách sử dụng management cluster của Hypershift được liên kết trong issue. Xác minh cách mỗi rule sử dụng các biến cluster và namespace-prefix, sau đó quét một hosted cluster trong đó các audit profile của management cluster và guest cluster khác nhau; hoàn tất khi các kiểm tra đánh giá guest cluster một cách nhất quán.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Description of problem:

Some rules don't respect the ocp4-hypershift-cluster and ocp4-hypershift-namespace-prefix variables, so they scan the management cluster and not the guest one, thus produce incorrect results.

List of rules:

  • ocp4-api-server-anonymous-auth
  • ocp4-api-server-oauth-https-serving-cert
  • ocp4-api-server-openshift-https-serving-cert
  • ocp4-api-server-profiling-protected-by-rbac
  • ocp4-api-server-tls-security-profile-custom-min-tls-version
  • ocp4-api-server-tls-security-profile-not-old
  • ocp4-audit-logging-enabled
  • ocp4-audit-profile-set
  • ocp4-kubelet-configure-tls-cipher-suites-ingresscontroller
  • ocp4-ocp-allowed-registries
  • ocp4-ocp-allowed-registries-for-import
  • ocp4-ocp-insecure-allowed-registries-for-import
  • ocp4-ocp-insecure-registries
  • ocp4-rbac-debug-role-protects-pprof
  • ocp4-scc-limit-container-allowed-capabilities
  • ocp4-scheduler-profiling-protected-by-rbac
  • ocp4-scheduler-service-protected-by-rbac
SCAP Security Guide Version:

0.1.78

Operating System Version:

RHCOS 9.6.20251013-1

Steps to Reproduce:
  1. Create a Hypershift hosted cluster
  2. Set for example the audit profile to "None" on the HostedCluster
  3. Make sure the audit profile is not set to "None" on the management cluster
  4. Follow the usage docs here to run a scan: https://github.com/ComplianceAsCode/compliance-operator/blob/master/doc/usage.md#how-to-use-compliance-operator-with-hypershift-management-cluster
Actual Results:

The ocp4-audit-logging-enabled check will succeed

Expected Results:

The ocp4-audit-logging-enabled check should fail

Additional Information/Debugging Steps:

N/A

Ngôn ngữ chính
Shell
Star
2.8k
Fork
829
Merge trung bình
4 ngày 6 giờ
Pull request đã merge (30 ngày)
42

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của ComplianceAsCode/content

Tất cả issue của ComplianceAsCode/content

Issue tương tự

Thêm issue về Shell/Bash

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.