Skip to content

Commit

Permalink
Create an ACM policy set for Advanced Cluster Security Secured Clusters
Browse files Browse the repository at this point in the history
This takes part of the OPP Policy Set and organizes a solution that
only applies the ACS Secured Clusters to ACM OpenShift managed clusters.

Refs:
 - https://issues.redhat.com/browse/ACM-8934

Signed-off-by: Gus Parvin <[email protected]>
  • Loading branch information
gparvin committed May 16, 2024
1 parent 906671e commit b376786
Show file tree
Hide file tree
Showing 10 changed files with 263 additions and 0 deletions.
1 change: 1 addition & 0 deletions policygenerator/policy-sets/community/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ on using the policy generator.

Policy | Description | Prerequisites
------- | ----------- | -------------
[Advanced Cluster Security Secured Clusters](./acs-secure) | Applies the Advanced Cluster Security Secured Cluster operator to all managed clusters | The default placement applies the Secured Cluster resources to all OpenShift clusters except the hub cluster.
[OpenShift Best Practices](./ocp-best-practices) | Applies the OpenShift management best practices to OpenShift clusters. | Requires placement on OpenShift 4.6 clusters or newer. The `PolicySet` uses cluster `Placement` and not the `PlacementRule` placement mechanism.
[OpenShift Platform Plus (moved to stable)](../stable/openshift-plus) | The OpenShift Platform Plus policy set applies several policies that installs the OpenShift Platform Plus products using best practices that allow them to work well together. | The OpenShift Platform Plus policy set works with OpenShift managed clusters and installs many components to the hub cluster. See the policy set [README.md](../stable/openshift-plus/README.md) for more information on prerequisites. The `PolicySet` uses cluster `Placement` and not the `PlacementRule` placement mechanism.
[Kyverno Policy Sets](./kyverno) | The Kyverno policy sets are provided to help you apply best practices around security, multitenancy and applications. See the details for each each of the policy sets in the `kyverno` subdirectories. | The Kyverno `PolicySets` require the Kyverno helm chart to be installed on each managed cluster where you want to install the `PolicySets`. Use the policy [`policy-install-kyverno`](https://raw.githubusercontent.com/open-cluster-management-io/policy-collection/main/community/CM-Configuration-Management/policy-install-kyverno.yaml) to install kyverno and the policy [`policy-kyverno-config-exclude-resources`](https://raw.githubusercontent.com/open-cluster-management-io/policy-collection/main/community/CM-Configuration-Management/policy-kyverno-config-exclude-resources.yaml) to update Kyverno resource filters. The `PolicySet` uses cluster `Placement` and not the `PlacementRule` placement mechanism. For more details on Kyverno `PolicySet` installation, see the [README.md](./kyverno/README.md).
Expand Down
47 changes: 47 additions & 0 deletions policygenerator/policy-sets/community/acs-secure/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
# Advanced Cluster Security PolicySet for Secured Clusters

## Prerequisites
To install Advanced Cluster Security Secured Clusters using this PolicySet,
you must first have already installed your Advanced Cluster Security Central Server.
The policies make the following assumptions:

- RHACS is installed on the RHACM hub and the ACS init bundle secrets are created
in the `stackrox` namespace.
- RHACS is installed on the RHACM hub and the ACS Central Server `Route` resource
exists in the `stackrox` namespace.
- An install of Red Hat Advanced Cluster Management for Kubernetes version 2.8
or newer is required.


## Installation

The ACS PolicySet for Secured Clusters contains two `PolicySets` that will be deployed.i
The `PolicySets` install RHACS Secured Clusters onto all OpenShift clusters that are
managed by RHACM except for the RHACM hub cluster. If you want to install the RHACS
Secured Cluster component to the RHACM hub, that must be done separately.

Prior to applying the `PolicySet`, perform these steps:

1. To allow for subscriptions to be applied below you must apply and set to enforce the policy [policy-configure-subscription-admin-hub.yaml](https://github.com/open-cluster-management-io/policy-collection/blob/main/community/CM-Configuration-Management/policy-configure-subscription-admin-hub.yaml).
2. Install the Policy generator Kustomize plugin by following the [installation instructions](https://github.com/stolostron/policy-generator-plugin#installation). It is recommended to use Kustomize v4.5+.
3. Policies are installed to the `policies` namespace. i
Make sure the placement bindings match this namespace for the hub and other managed clusters.
Example yaml to apply a ManagedClusterSetBinding for the policies namespace.
```apiVersion: cluster.open-cluster-management.io/v1beta2
kind: ManagedClusterSetBinding
metadata:
name: default
namespace: policies
spec:
clusterSet: default
```
```bash
oc apply -f managed-cluster.yaml
```
Apply the policies using the kustomize command or subscribing to a fork of the repository and pointing to this directory. See the details for using the Policy Generator for [more information](https://github.com/stolostron/policy-collection/tree/main/policygenerator). The command to run is `kustomize build --enable-alpha-plugins | oc apply -f -`
**Note**: If the RHACS `Route` or certificate bundles are not available on the RHACM
hub cluster, you must edit the policy resources to make sure these resources are
available in the `policies` namespace.
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
apiVersion: policy.open-cluster-management.io/v1
kind: CertificatePolicy
metadata:
name: acs-bundle-certificates
spec:
namespaceSelector:
include: ["policies"]
remediationAction: inform
severity: high
minimumDuration: 720h
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
apiVersion: v1
data: '{{ copySecretData "stackrox" "admission-control-tls" }}'
kind: Secret
metadata:
labels:
certificate_key_name: admission-control-cert.pem
name: admission-control-tls
namespace: policies
type: Opaque
---
apiVersion: v1
data: '{{ copySecretData "stackrox" "collector-tls" }}'
kind: Secret
metadata:
labels:
certificate_key_name: collector-cert.pem
name: collector-tls
namespace: policies
type: Opaque
---
apiVersion: v1
data: '{{ copySecretData "stackrox" "sensor-tls" }}'
kind: Secret
metadata:
labels:
certificate_key_name: sensor-cert.pem
name: sensor-tls
namespace: policies
type: Opaque
---
apiVersion: v1
data:
acs-host: '{{ (lookup "route.openshift.io/v1" "Route" "stackrox" "central").spec.host }}:443'
kind: ConfigMap
metadata:
name: acs-config
namespace: policies
Original file line number Diff line number Diff line change
@@ -0,0 +1,73 @@
apiVersion: v1
kind: Namespace
metadata:
name: stackrox
---
apiVersion: v1
kind: Namespace
metadata:
name: rhacs-operator
---
apiVersion: operators.coreos.com/v1
kind: OperatorGroup
metadata:
name: rhacs-operator-group
namespace: rhacs-operator
spec: {}
---
apiVersion: operators.coreos.com/v1alpha1
kind: Subscription
metadata:
name: rhacs-operator
namespace: rhacs-operator
spec:
channel: stable
installPlanApproval: Automatic
name: rhacs-operator
source: redhat-operators
sourceNamespace: openshift-marketplace
---
apiVersion: v1
data: '{{hub copySecretData "policies" "admission-control-tls" hub}}'
kind: Secret
metadata:
name: admission-control-tls
namespace: stackrox
type: Opaque
---
apiVersion: v1
data: '{{hub copySecretData "policies" "collector-tls" hub}}'
kind: Secret
metadata:
name: collector-tls
namespace: stackrox
type: Opaque
---
apiVersion: v1
data: '{{hub copySecretData "policies" "sensor-tls" hub}}'
kind: Secret
metadata:
name: sensor-tls
namespace: stackrox
type: Opaque
---
apiVersion: platform.stackrox.io/v1alpha1
kind: SecuredCluster
metadata:
namespace: stackrox
name: stackrox-secured-cluster-services
spec:
clusterName: |
{{ fromSecret "open-cluster-management-agent" "hub-kubeconfig-secret" "cluster-name" | base64dec }}
auditLogs:
collection: Auto
centralEndpoint: '{{hub fromConfigMap "" "acs-config" "acs-host" hub}}'
admissionControl:
listenOnCreates: false
listenOnEvents: true
listenOnUpdates: false
perNode:
collector:
collection: EBPF
imageFlavor: Regular
taintToleration: TolerateTaints
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: sensor
namespace: stackrox
status:
conditions:
- status: "True"
type: Available
---
apiVersion: apps/v1
kind: DaemonSet
metadata:
name: collector
namespace: stackrox
status:
numberMisscheduled: 0
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
generators:
- ./policyGenerator.yaml
commonLabels:
open-cluster-management.io/policy-set: acs-sensors
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
apiVersion: cluster.open-cluster-management.io/v1beta1
kind: Placement
metadata:
name: placement-sensor-clusters
namespace: policies
spec:
predicates:
- requiredClusterSelector:
labelSelector:
matchExpressions:
- {key: vendor, operator: In, values: ["OpenShift"]}
- {key: name, operator: NotIn, values: ["local-cluster"]}
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
apiVersion: cluster.open-cluster-management.io/v1beta1
kind: Placement
metadata:
name: placement-sensors-hub-info
namespace: policies
spec:
predicates:
- requiredClusterSelector:
labelSelector:
matchExpressions:
- {key: name, operator: In, values: ["local-cluster"]}
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
apiVersion: policy.open-cluster-management.io/v1
kind: PolicyGenerator
metadata:
name: policy-acs-sensors
placementBindingDefaults:
name: binding-policy-sensor-clusters
policyDefaults:
categories:
- SI System and Information Integrity
controls:
- SI-5 Security Alerts Advisories and Directives
namespace: policies
policySets:
- acs-sensors-hub-info
remediationAction: enforce
severity: medium
standards:
- NIST SP 800-53
policies:
- name: policy-acs-sync-resources
consolidateManifests: false
manifests:
- path: input-sensor/policy-acs-sync-resources.yaml
- name: policy-acs-monitor-certs
dependencies:
- name: policy-acs-sync-resources
manifests:
- path: input-sensor/acs-check-certificates.yaml
- name: policy-advanced-managed-cluster-security
consolidateManifests: false
manifests:
- path: input-sensor/policy-advanced-managed-cluster-security.yaml
policySets:
- acs-sensor-clusters
- name: policy-advanced-managed-cluster-status
manifests:
- path: input-sensor/policy-advanced-managed-cluster-status.yaml
policySets:
- acs-sensor-clusters
remediationAction: inform
policySets:
- description: The Advanced Cluster Security components to setup the hub for securing
each managed cluster.
name: acs-sensors-hub-info
placement:
placementPath: placement/hub-placement.yaml
- description: The Advanced Cluster Security components distributed to all OpenShift
managed clusters to secure the clusters.
name: acs-sensor-clusters
placement:
placementPath: placement/clusters-placement.yaml

0 comments on commit b376786

Please sign in to comment.