Skip to content

Guide to the Secure Configuration of Red Hat OpenShift Container Platform 4

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Configure ImagePruner so that images that are no longer needed are automatically removed

    <p> Images from the internal registry that are no longer required by the system due to age, status, or exceed limits are automatically pruned. Cluster administrators can configure th...
    Rule Medium Severity
  • Make sure the Container Security Operator is installed

    <p> Using the Red Hat Quay Container Security Operator, you can access vulnerability scan results from the OpenShift Container Platform web console for container images used in activ...
    Rule Medium Severity
  • Enable AutoApplyRemediation for at least One ScanSetting

    <a href="https://docs.openshift.com/container-platform/latest/security/compliance_operator/compliance-operator-understanding.html#compliance-operator-understanding">The Compliance Operator</a> scan...
    Rule Medium Severity
  • Limit Container Capabilities

    <p> Containers should not enable more capabilites than needed as this opens the door for malicious use. To enable only the required capabilities, the appropriate Security Context Con...
    Rule Medium Severity
  • Verify that the scheduler API service is protected by RBAC

    Do not bind the scheduler service to non-loopback insecure addresses.
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules