Closed hgbarreto closed 10 months ago
Sitting at 91.7 SCCD Score after the following events:
Next steps: Find permanent fix for SELinux context being lost in the AMI build. This should resolve multiple issues like, audit service failing on startup + BESclient becoming unconfined daemon.
@hgbarreto - I quickly checked the BigFix console, and it looks like one of the EKS cluster nodes is reporting at 89%! This is super exciting. 🎉
Screenshot from BigFix console this morning:
Screenshot from AWS console for the host from BigFix above:
As you mentioned in your comment above, do you expect those changes to be deployed to other hosts in production soon? I don't want to rush your progress, but I'm just curious. :)
Currently have the Base AMI sitting at a true 90.4% Score.
Closing this effort to begin optimization and eks node ami hardening.
Description
Once the Base AMI SCCD score is reported, we can generate new reports on rule failures for the image. With this information we can then split the rules between "rules we can fix" and "rules we can submit remediation requests for"
Resources
Acceptance Criteria
dsva-vagov-sccd-compliance-prod
Refinement Guidance - Check the following before working on this issue: