ocp4-cis-node remains non-compliant even after remediations
Issue
- When attempting to remediate the "ocp4-kubelet-enable-protect-kernel-defaults" OCP4-CIS-Node rule, the node remains non-compliant after the following remediations were done:
- added the needed sysctls to the MachineConfig
- set the protectKernelDefaults to true in the KubeletConfig
Environment
- Red Hat Advanced Cluster Security (RHACS) 4.1.1
- OpenShift (OCP) 4.11.43
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.