Release notes for the Compliance Operator
The Compliance Operator lets OpenShift Container Platform administrators describe the required compliance state of a cluster and provides them with an overview of gaps and ways to remediate them.
These release notes track the development of the Compliance Operator in the OpenShift Container Platform.
Release notes for OpenShift Compliance Operator 1.10.0
OpenShift Compliance Operator 1.10.0 is now available. The stable update channel tracks and receives updates for the Compliance Operator. For more information, see Updating the Compliance Operator. The following Red Hat Security Advisory (RHSA) is available:
New features and enhancements
- With this release, the
ocp4-cisandocp4-cis-nodeprofiles align with the CIS Red Hat OpenShift Container Platform 4 Benchmark v2.0.0. Benchmark version 1.9.0 is deprecated and remains available as theocp4-cis-1-9andocp4-cis-node-1-9profiles, and the CIS 1.7 profiles are removed. For more information, see (CMP-4289). - With this release, the
ocp4-stig,ocp4-stig-node, andrhcos4-stigprofiles align with DISA STIG V2R6. A new profileocp4-stig-vm-extensionwas added to support systems with OpenShift Virtualization. Version V2R3 is deprecated and remains available as theocp4-stig-v2r3andocp4-stig-node-v2r3profiles, and the V2R2 profiles are removed. For more information, see (CMP-4615). - With this release, the Compliance Operator adds support for the CIS Red Hat OpenShift Virtual Machine Extension Benchmark v1.0.0. The
ocp4-cis-vm-extensionandocp4-cis-vm-extension-nodeprofiles are available to scan OpenShift Virtualization. For more information, see (CMP-4424). - With this release, the default
ocp4ProfileBundleincludes two Profiles using the Common Expression Language (CEL) checking engine. Both target OpenShift Virtualization settings: theocp4-cis-vm-extensionprofile for the CIS Virt benchmark and theocp4-stig-vm-extensionprofile included with the DISA STIG V2R6 update. For more information, see (CMP-4424) and (CMP-4615). - With this release, CEL
RulesandCustomRuleobjects are in General Availability (GA). CEL does not replace the existing Extensible Configuration Checklist Description Format (XCCDF) profiles but extends the ability to comply with custom security policies. For more information, see (CMP-4574). - With this release, the CEL scanner introduces support for MANUAL rules, which can be used as the basis for a
CustomRuleobject with user provided CEL check. For more information, see (CMP-4518). - With this release, the Compliance Operator creates
NetworkPolicyobjects for operand pods. Operand traffic uses a default-deny policy, with required ingress and egress allowed. For more information, see (CMP-4569). - With this release, the Compliance Operator uses the OpenShift Container Platform API server TLS configuration instead of hard-coded TLS settings. For more information, see (CMP-4147).
Fixed issues
- Before this release, the node scanner delivered the runtime kubelet configuration with a host symlink. Later scans on the same node could fail to refresh that configuration, resulting in kubelet rules failure. With this release, the operator copies the kubelet configuration into a shared
emptyDirvolume. For more information, see (CMP-4341). - Before this release, the metrics TLS endpoint could fail to start if the serving certificate was not ready, and metrics stayed unavailable for the life of the pod. With this release, the operator waits for the serving certificate before serving metrics over TLS. For more information, see (CMP-4601).
- Before this release, changing the
celContentFilefield on aProfileBundleobject did not redeploy the profile parser, so CEL profiles were not created. With this release, the operator detectscelContentFilechanges and re-parses CEL content. For more information, see (CMP-4599). - Before this release, remediating
rhcos4-moderatechrony settings could causechrony-wait.serviceto time out after node restarts. With this release, the remediation no longer breakschrony-wait.service. For more information, see (CMP-3618). - Before this release, the
banner_etc_issuerule used a hard-coded remediation that did not match configurable banner values allowed by the check, so remediation could fail. With this release, remediation uses the configured banner variable. For more information, see (CMP-3730). - Before this release, the route IP whitelist rule linked to documentation that redirected away from the route annotations topic. With this release, the rule references the current route annotations documentation. For more information, see (CMP-3922).
- Before this release, the
ncp-ocp4-cis-api-server-bind-addresscheck failed on IPv6-only clusters because it expected an IPv4 API server bind address, requiring aTailoredProfileworkaround. With this release, the check passes on IPv6-only clusters without a workaround. - Before this release, the
audit_error_alert_existscheck could fail when an emptyPrometheusRuleexisted in the cluster, reporting ajqparsing error instead of evaluating other rules. With this release, emptyPrometheusRuleresources are skipped. - Before this release, the
ocp4-file-permissions-schedulerrule required file mode0644for kube-scheduler static pod files that use0600, causing incorrect failures. With this release, the rule expects0600, matching the CIS benchmark. For more information, see (CMP-4609).
Release notes for OpenShift Compliance Operator 1.9.2
OpenShift Compliance Operator 1.9.2 is now available. The stable update channel tracks and receives updates for the Compliance Operator. For more information, see Updating the Compliance Operator. The following Red Hat Security Advisory (RHSA) is available:
Fixed issues
- Before this release, the
compliance_operator_compliance_statemetric could reportNON-COMPLIANTeven when relatedComplianceSuiteandComplianceScanresults wereCOMPLIANT, which could trigger false alerts. With this release, the Compliance Operator keeps the metric in synchronization with the relevant suite and removes it when you delete that suite. For more information, see (CMP-4373). - CVE-2026-33811 is resolved in the Compliance Operator 1.9.2 release. (CVE-2026-33811)
- CVE-2026-27145 is resolved in the Compliance Operator 1.9.2 release. (CVE-2026-27145)
- CVE-2026-42504 is resolved in the Compliance Operator 1.9.2 release. (CVE-2026-42504)
Release notes for OpenShift Compliance Operator 1.9.1
Release notes for OpenShift Compliance Operator 1.9.1.
The following Red Hat Security Advisory (RHSA) is available for the OpenShift Compliance Operator 1.9.1:
Bug fixes
- Before this release, when you created a
TailoredProfileobject that extended a base profile, you could only enable rules that were available in the XCCDF groups in the base profile. With this release,TailoredProfileobjects can enable any rule available. For more information, see (CMP-4283). - Before this release, the Compliance Operator rule,
ocp4-cis-file-permissions-cni-conf, checked file permissions for every file under the/etc/cni/net.d/directory, including the runtimecni.lockfile, which could cause incorrect fail results. With this release, the rule checks permissions only for CNI configuration files (.conf,.conflist,.json). For more information, see (CMP-4323). - Before this release, the Compliance Operator defaulted to an
imagePullPolicyofAlways, which could cause unnecessary container image pulls from the registry on every pod start. With this release, the default isIfNotPresent. For more information, see (CMP-4313). - Before this release, updated DISA STIG reference URLs caused the profile parser to omit STIG reference annotations on
Rulecustom resources. With this release, the parser recognizes the updated URLs and restores those annotations. For more information, see (CMP-4333). - Before this release, updated NERC-CIP reference URLs caused the profile parser to omit NERC-CIP annotations on
Rulecustom resources. With this release, the parser recognizes the updated URLs and restores those annotations. For more information, see (CMP-4349).
Release notes for OpenShift Compliance Operator 1.9.0
Release notes for OpenShift Compliance Operator 1.9.0.
The following Red Hat Security Advisory (RHSA) is available for the OpenShift Compliance Operator 1.9.0:
New features and enhancements
- With this update, the Compliance Operator has extended the Common Expression Language (CEL) scanner to
Rules, in Technology Preview status. CEL does not replace the existing Extensible Configuration Checklist Description Format (XCCDF) profiles but extends the ability to comply with custom security policies. For more information, see (CMP-4134). - With this release, the Compliance Operator now allows custom attributes defined in
ComplianceRuleobjects to be automatically propagated to the correspondingComplianceCheckResultobjects. For more information, see (CMP-3974). - With this release, the Compliance Operator now supports Center for Internet Security (CIS) OpenShift benchmark version 1.9.0. Version 1.7.0 is now deprecated. For more information, see (CMP-3520).
Bug fixes
- Before this release, Compliance Operator would create an unbound
ServiceAccounttoken used for metrics access. This could raise a security concern over an unused token. With this release, the unboundServiceAccounttoken is not created. For more information, see (CMP-3743). - Before this release, File Integrity Operator (FIO) would fail when you installed FIO before Compliance Operator (CO) and CO ran the first scan. With this release, FIO and CO run correctly when both are installed. For more information, see (CMP-4112).
- Before this release, if you configured
ScanSettingsto disable result storage and then ran a platform scan, the scan would hang and time out. Now, if you configureScanSettingsto disable result storage, the platform scan continues to completion. For more information, see (CMP-4116). - Before this release,
ProfileBundleobjects could become stuck in a PENDING state indefinitely during Operator upgrades or content image changes. This would require manual intervention to resolve, such as deleting theprofileparserdeployment or restarting the Operator. With this release, theProfileBundlecontroller now detects and automatically recovers from this condition with no user action required. This improvement is transparent and does not affect any APIs, custom resources, or configuration. For more information, see (CMP-4117). - Before this release, Compliance Operator rules did not add the proper annotation for rules selected in CIS profiles, which resulted in absence of the annotation and results not appearing in Red Hat Advanced Cluster Security (ACS). Now, when annotations are added, the checks appear in the final ACS report and the compliance dashboard with the correct control tag. For more information, see (CMP-4120).
Release notes for OpenShift Compliance Operator 1.8.2
Release notes for OpenShift Compliance Operator 1.8.2.
The following Red Hat Security Advisory (RHSA) is available for the OpenShift Compliance Operator 1.8.2:
Bug fixes
- Red Hat recommends that customers upgrade to version 1.8.2 of Compliance Operator. For more information, see (CVE-2025-68973).
Release notes for OpenShift Compliance Operator 1.8.1
Release notes for OpenShift Compliance Operator 1.8.1.
The following Red Hat Security Advisory (RHSA) is available for the OpenShift Compliance Operator 1.8.1:
Bug fixes
- Before this release, Compliance Operator could cause a privilege escalation due to incorrect permissions on
/etc/passwd. With this release, the permissions have been corrected. For more information, see (CVE-2025-7195). - Previously, Compliance Operator scans using rhcos4 profile would incorrectly return
NOT-APPLICABLEscan results when using Red Hat Enterprise Linux CoreOS (RHCOS) 10 systems. With this release, scans using rhcos4 profiles returnCOMPLIANTandNON-COMPLIANTresults. For more information, see (CMP-4034).
Release notes for OpenShift Compliance Operator 1.8.0
Release notes for OpenShift Compliance Operator 1.8.0.
The following Red Hat Security Advisory (RHSA) is available for the OpenShift Compliance Operator 1.8.0:
New features and enhancements
- With this update, the Compliance Operator provides the Common Expression Language (CEL) scanner in TECH PREVIEW status. The CEL scanner implements a new
CustomRuleCustom Resource Definition (CRD) that allows administrators to define and enforce custom security policies using CEL expressions. This new content format does not replace the existing XCCDF (Extensible Configuration Checklist Description Format) profiles but extends the ability to comply with custom security policies. For more information, see (CMP-3118). - Previously, Compliance Operator required persistent storage to save raw scan results, which presented challenges for edge deployments and environments without storage infrastructure. With this release, Compliance Operator supports running scans without persistent storage. Administrators can set
rawResultStorage.enabled: falseinScanSettingresources to disable storage of scan result files, allowing compliance scans to run in storage-constrained environments such as edge deployments and single-node OpenShift. Compliance check results remain fully available throughComplianceCheckResultresources. Raw result storage remains enabled by default for backward compatibility. For more information, see (CMP-1225). - Previously, Compliance Operator provided
ocp4-bsiandocp4-bsi-nodeprofiles for BSI compliance scanning. With this release, therhcos4-bsiprofile is now available, extending BSI standard coverage to RHCOS systems. For more information, see (CMP-3720). - This release removes the deprecated CIS 1.4.0, CIS 1.5.0, DISA STIG V1R1 and DISA STIG V2R1 profiles. The newer versions have replaced these obsolete profiles for customer use. For more information, see (CMP-3712).
- With this release, PCI-DSS profiles 3.2.1 and 4.0.0 are now supported on ARM architecture systems. For more information, see (CMP-3723).
Bug fixes
- With this release, automatic remediation for API server encryption now applies the appropriate encryption mode based on OpenShift version: AES-GCM for OpenShift 4.13.0 and higher versions, AES-CBC for earlier versions. Both encryption modes remain compliant across all OpenShift versions. For more information, see (CMP-3248).
- Before this release, Compliance Operator would remediate SSH settings on RHCOS hosts by deploying a fixed sshd_config file containing all SSH hardening settings. If the scan for corresponding rules failed, this could result in unintended configuration changes to SSH. With this release, Compliance Operator applies very specific remediations to SSH according to the ComplianceAsCode shared Kubernetes macros. For more information, see (CMP-3553).
- For prior versions of Compliance Operator, the log rotation function depended on finding the
logrotatefile in the/etc/cron.dailyfolder. With this release, Compliance Operator works with thelogrotate.timerservice. This provides reliable log rotation behavior from Compliance Operator. - For previous versions of Compliance Operator, it is possible for the
STIG IDto be omitted from the compliance report. These omissions were caused by missingstigrefandstigidvalues. With this release, the omissions have been corrected and nowSTIG IDreliably shows up in the compliance report. - Before this release, Compliance Operator STIG control
CNTR-OS-000720selected rulerhcos4-audit-rules-suid-privilege-function, but since the rule was not available in Compliance Operator, no output was generated. With this release, the rule,rhcos4-audit-rules-suid-privilege-functionis now available in Compliance Operator and listed in the scan output. For more information, see (CMP-3558). - In previous versions of Compliance Operator, scanning with the
ocp4-stigprofile would fail for the ruleocp4-stig-modified-audit-log-forwarding-uses-tlseven if TLS is enabled correctly. This would occur because thetls://field is no longer required by theClusterLogForwarderresource, causing the scan output to show an incorrectFAILresult. With this release, the protocol prefix is not required and the scan output produces correct results. For more information, see (routes-protected-by-tls compliance check failing when Red Hat OpenShift Data Foundation 4.11 is installed). - Previously, there was no automated method to check if API servers were using unsupported configuration overrides as recommended by CIS Benchmark control 1.2.31 or 1.2.33. This release provides dedicated rules for checking for unsupported configuration overrides.
- For prior releases of Compliance Operator, some rules were missing a variable reference in the annotation, such as rule
resource-requests-limits. With this release, the variable reference is available for rules and the erroneous output is eliminated. For more information, see (CMP-3582). - Previously, the
ocp4-routes-rate-limitrule required setting rate limits for all routes outside theopenshiftandkubenamespaces. However, using the feature and scanning for it presented problems because other namespaces managed by critical Operators should not be modified and not be scanned for the modification by Compliance Operator. With this release, routes managed by critical Operators are not flagged as errors by the Compliance Operator. - In prior versions of Compliance Operator, a
ComplianceScanreported the warningSDN not foundwhen theopenshift-sdnnetworking provider was not found. In this release, Compliance Operator suppresses the warning when OpenShift-SDN is not the active networking provider. For more information, see (CMP-3591). - Previously, duplicate variables could be accidentally created in
TailoredProfileand were not correctly detected by Compliance Operator. With this release, duplicatesetValuesinTailoredProfileare identified and trigger a warning event from a compliance scan. - In previous releases of Compliance Operator, the rule ocp4-audit-log-forwarding-uses-tls failed when the
clusterlogforwarderoutput configuration contained maps without a URL key. With this release, the rule correctly filters for outputs that have a URL field, showingPASSwhen TLS is properly enabled forclusterlogforwarder. For more information, see (CMP-3597). - In prior versions of Compliance Operator, for the rule
rhcos4-service-systemd-coredump-disabled, no remediation was generated after scanning the cluster. In this release, remediation is provided forrhcos4-service-systemd-coredump-disabled. - In prior versions of Compliance Operator, the rule to check the setting of
imagestream.spec.tags.importPolicy.scheduledwould returnFAILeven when the configuration was correct. With this release, the rule now correctly excludes imagestreams managed by the samples operator and those owned by ClusterVersion, resulting in accurate compliance status reporting. - In prior releases, Compliance Operator included outdated TLS cipher suite rules which used unsupported configuration overrides with defective remediations. With this release, these outdated rules have been removed from the default profile. Also, the
ocp4-kubelet-configure-tls-cipher-suites-ingresscontrollerrule has been renamed toocp4-ingress-controller-tls-cipher-suitesfor better organization. For more information, see (CMP-3606). - In prior versions of Compliance Operator, creating
ComplianceScansdirectly with custom content images failed during the profile deprecation check. With this release, Compliance Operator gracefully handles cases where theProfileBundlecannot be determined, logging an informational message instead of failing the scan. For more information, see (CMP-3613). - Previously, Compliance Operator scanned incorrectly flagged passthrough routes as noncompliant with the
ocp4-routes-protected-by-tlsrule. With this release, passthrough routes are properly excluded from this rule because they delegate TLS termination to the backend application.