Tailoring the Compliance Operator
Although the Compliance Operator includes ready-to-use profiles, you must modify the profiles to fit your organization’s requirements. The process of modifying a profile is called tailoring.
The Compliance Operator provides the TailoredProfile object to help tailor profiles.
Create a new tailored profile
You can write a tailored profile from scratch by using the TailoredProfile object. Set an appropriate title and description and leave the extends field empty.
Indicate to the Compliance Operator what type of scan this custom profile will generate:
- Node scan: Scans the operating system.
- Platform scan: Scans the OpenShift Container Platform configuration.
Procedure
-
Set the following annotation on the
TailoredProfileobject:Example new-profile.yamlapiVersion: compliance.openshift.io/v1alpha1kind: TailoredProfilemetadata:name: new-profileannotations:compliance.openshift.io/product-type: Nodespec:extends: ocp4-cis-nodedescription: My custom profiletitle: Custom profileenableRules:- name: ocp4-etcd-unique-carationale: We really need to enable thisdisableRules:- name: ocp4-file-groupowner-cni-confrationale: This does not apply to the clusterwhere:
metadata.annotations.compliance.openshift.io/product-type- Sets
NodeorPlatformaccordingly. spec.extends- Optional field to specify the base profile.
spec.description- Specifies the function of the new
TailoredProfileobject. spec.title- Specifies a title for the
TailoredProfileobject.
Adding the -node suffix to the name field of the TailoredProfile object is similar to adding the Node product type annotation and generates an operating system scan.
Use tailored profiles to extend existing ProfileBundles
Although the TailoredProfile CR enables the most common tailoring operations, you can use the XCCDF (Extensible Configuration Checklist Description Format) standard for even more flexibility in tailoring OpenSCAP profiles.
In addition, if your organization has been using OpenScap previously, you might have an existing XCCDF tailoring file and can reuse it.
The ComplianceSuite object has an optional TailoringConfigMap attribute that you can point to a custom tailoring file. The value of the TailoringConfigMap attribute is a name of a config map, which must contain a key called tailoring.xml and the value of this key is the tailoring contents.
Procedure
- Browse the available rules for the Red Hat Enterprise Linux CoreOS (RHCOS)
ProfileBundle:$ oc get rules.compliance -n openshift-compliance -l compliance.openshift.io/profile-bundle=rhcos4 - Browse the available variables in the same
ProfileBundle:$ oc get variables.compliance -n openshift-compliance -l compliance.openshift.io/profile-bundle=rhcos4 - Create a tailored profile named
nist-moderate-modified:-
Choose which rules you want to add to the
nist-moderate-modifiedtailored profile. This example extends therhcos4-moderateprofile by disabling two rules and changing one value. Use therationalevalue to describe why these changes were made:Example new-profile-node.yamlapiVersion: compliance.openshift.io/v1alpha1kind: TailoredProfilemetadata:name: nist-moderate-modifiedspec:extends: rhcos4-moderatedescription: NIST moderate profiletitle: My modified NIST moderate profiledisableRules:- name: rhcos4-file-permissions-var-log-messagesrationale: The file contains logs of error messages in the system- name: rhcos4-account-disable-post-pw-expirationrationale: No need to check this as it comes from the IdPsetValues:- name: rhcos4-var-selinux-staterationale: Organizational requirementsvalue: permissiveAttributes for spec variables
-
| Attribute | Description |
|---|---|
extends |
Name of the Profile object upon which this TailoredProfile is built. |
title |
Human-readable title of the TailoredProfile. |
disableRules |
A list of name and rationale pairs. Each name refers to a name of a rule object that is to be disabled. The rationale value is human-readable text describing why the rule is disabled. |
manualRules |
A list of name and rationale pairs. When a manual rule is added, the check result status will always be manual and remediation will not be generated. This attribute is automatic and by default has no values when set as a manual rule. |
enableRules |
A list of name and rationale pairs. Each name refers to a name of a rule object that is to be enabled. The rationale value is human-readable text describing why the rule is enabled. |
description |
Human-readable text describing the TailoredProfile. |
setValues |
A list of name, rationale, and value groupings. Each name refers to a name of the value set. The rationale is human-readable text describing the set. The value is the actual setting. |
1. Add the `tailoredProfile.spec.manualRules` attribute:
```yaml title="Example tailoredProfile.spec.manualRules.yaml"
apiVersion: compliance.openshift.io/v1alpha1
kind: TailoredProfile
metadata:
name: ocp4-manual-scc-check
spec:
extends: ocp4-cis
description: This profile extends ocp4-cis by forcing the SCC check to always return MANUAL
title: OCP4 CIS profile with manual SCC check
manualRules:
- name: ocp4-scc-limit-container-allowed-capabilities
rationale: We use third party software that installs its own SCC with extra privileges
```
1. Create the `TailoredProfile` object:
```terminal
$ oc create -n openshift-compliance -f new-profile-node.yaml
```
* The `TailoredProfile` object is created in the default `openshift-compliance` namespace.
```terminal title="Example output"
tailoredprofile.compliance.openshift.io/nist-moderate-modified created
```
-
Define the
ScanSettingBindingobject to bind the newnist-moderate-modifiedtailored profile to the defaultScanSettingobject.Example new-scansettingbinding.yamlapiVersion: compliance.openshift.io/v1alpha1kind: ScanSettingBindingmetadata:name: nist-moderate-modifiedprofiles:- apiGroup: compliance.openshift.io/v1alpha1kind: Profilename: ocp4-moderate- apiGroup: compliance.openshift.io/v1alpha1kind: TailoredProfilename: nist-moderate-modifiedsettingsRef:apiGroup: compliance.openshift.io/v1alpha1kind: ScanSettingname: default -
Create the
ScanSettingBindingobject:$ oc create -n openshift-compliance -f new-scansettingbinding.yamlExample outputscansettingbinding.compliance.openshift.io/nist-moderate-modified created