Compliance Operator in OpenShift fails basic checks even with new installation
Issue
- Compliance Operator running CIS report shows vulnerabilities that cannot be easily remediated on Red Hat Enterprise Linux CoreOS (RHCOS).
- There are no automated remediations available for these vulnerabilities.
- Since RHCOS is immutable, it would be best to have out-of-the-box remediations.
- Most of the commands shown in the remediations would only work on RHEL systems; for RHCOS the changes wouldn't be persistent unless done via machine config.
- Each new OCP version seems to bring new failed tests.
Environment
- Red Hat OpenShift Container Platform 4
- Compliance Operator 0.1.32
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.