department-of-veterans-affairs / va.gov-team

Public resources for building on and in support of VA.gov. Visit complete Knowledge Hub:
https://depo-platform-documentation.scrollhelp.site/index.html
281 stars 202 forks source link

[SCCD] New SCCD evaluation using the results of the Base AMI SCCD scans #70177

Closed hgbarreto closed 10 months ago

hgbarreto commented 10 months ago

Description

Once the Base AMI SCCD score is reported, we can generate new reports on rule failures for the image. With this information we can then split the rules between "rules we can fix" and "rules we can submit remediation requests for"

Resources

Acceptance Criteria

Refinement Guidance - Check the following before working on this issue:

hgbarreto commented 10 months ago

Sitting at 91.7 SCCD Score after the following events:

Next steps: Find permanent fix for SELinux context being lost in the AMI build. This should resolve multiple issues like, audit service failing on startup + BESclient becoming unconfined daemon.

jhouse-solvd commented 10 months ago

@hgbarreto - I quickly checked the BigFix console, and it looks like one of the EKS cluster nodes is reporting at 89%! This is super exciting. 🎉

Screenshot from BigFix console this morning:

Screenshot 2023-11-27 at 10 55 37

Screenshot from AWS console for the host from BigFix above:

Screenshot 2023-11-27 at 10 57 13

As you mentioned in your comment above, do you expect those changes to be deployed to other hosts in production soon? I don't want to rush your progress, but I'm just curious. :)

hgbarreto commented 10 months ago

Currently have the Base AMI sitting at a true 90.4% Score.

image.png
hgbarreto commented 10 months ago

Closing this effort to begin optimization and eks node ami hardening.