Compliance Operator overview
The OpenShift Container Platform Compliance Operator assists users by automating the inspection of numerous technical implementations and compares those against certain aspects of industry standards, benchmarks, and baselines.
The Compliance Operator is not an auditor. To be compliant or certified under these various standards, you need to engage an authorized auditor such as a Qualified Security Assessor (QSA), Joint Authorization Board (JAB), or other industry recognized regulatory authority to assess your environment.
The Compliance Operator makes recommendations based on generally available information and practices regarding such standards and may assist with remediations, but actual compliance is your responsibility. You are required to work with an authorized auditor to achieve compliance with a standard. For more information on compliance support for all Red Hat products, see "Product Compliance".
Compliance Operator concepts
Learn about the Compliance Operator and the custom resource definitions it uses.
Understanding the Compliance Operator
Understanding the Custom Resource Definitions
Compliance Operator management
You can install, update, manage, and uninstall the Compliance Operator on your cluster.
Installing the Compliance Operator
Updating the Compliance Operator
Managing the Compliance Operator
Uninstalling the Compliance Operator
Compliance Operator scan management
You can configure, run, tailor, and troubleshoot Compliance Operator scans, and retrieve and manage their results.
Tailoring the Compliance Operator
Retrieving Compliance Operator raw results
Managing Compliance Operator remediation
Performing advanced Compliance Operator tasks
Troubleshooting the Compliance Operator
Using the oc-compliance plugin
Additional resources