Skip to content

Manage Image Provenance Using ImagePolicyWebhook

An XCCDF Rule

Description

OpenShift administrators can control which images can be imported, tagged, and run in a cluster. There are two facilities for this purpose: (1) Allowed Registries, allowing administrators to restrict image origins to known external registries; and (2) ImagePolicy Admission plug-in which lets administrators specify specific images which are allowed to run on the OpenShift cluster. Configure an Image policy per the Image Policy chapter in the OpenShift documentation: https://docs.openshift.com/container-platform/4.4/openshift_images/image-configuration.html

Rationale

Image Policy ensures that only approved container images are allowed to be ran on the OpenShift platform.

ID
xccdf_org.ssgproject.content_rule_general_configure_imagepolicywebhook
Severity
Medium
References
Updated