openshift / compliance-operator

Operator providing OpenShift cluster compliance checks
Apache License 2.0
110 stars 110 forks source link

Modify the api-resource-collector to fetch network operator resources #815

Closed rhmdnd closed 2 years ago

rhmdnd commented 2 years ago

The CIS benchmarks recommends using a CNI that supports network policies. Previously, this was a manual check in the profile, but it's actually something we can check by querying the K8S operator API.

This commit adds the network resource to the operator.openshift.io API group so that the api-resource container can fetch that resource. This change is required to automate this check and used in:

https://github.com/ComplianceAsCode/content/pull/8524

Partial-Fix: https://bugzilla.redhat.com/show_bug.cgi?id=2072431

openshift-ci[bot] commented 2 years ago

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: jhrozek, rhmdnd

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files: - ~~[OWNERS](https://github.com/openshift/compliance-operator/blob/master/OWNERS)~~ [jhrozek,rhmdnd] Approvers can indicate their approval by writing `/approve` in a comment Approvers can cancel approval by writing `/approve cancel` in a comment
openshift-bot commented 2 years ago

/retest-required

Please review the full test history for this PR and help us cut down flakes.

rhmdnd commented 2 years ago

/retest

openshift-ci[bot] commented 2 years ago

@rhmdnd: all tests passed!

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes/test-infra](https://github.com/kubernetes/test-infra/issues/new?title=Prow%20issue:) repository. I understand the commands that are listed [here](https://go.k8s.io/bot-commands).