SV-257561r1156740_rule
V-257561
SRG-APP-000384-CTR-000915
CNTR-OS-000740
CAT II
10
By default, the integrity of RH CoreOS is checked by cluster version operator on OpenShift platform. If the integrity is not verified, reinstall of the cluster is necessary.
Refer to instructions:
https://docs.openshift.com/container-platform/4.10/installing/index.html
Where OpenShift Virtualization is enabled:
Annotations must be removed from the Hyperconverged by directly editing the object with oc edit hyperconverged kubevirt-hyperconverged -n openshift-cnv or by removing the annotation with the annotate command.
Example:
$ oc annotate --overwrite -n openshift-cnv hco
kubevirt-hyperconverged
'containerizeddataimporter.kubevirt.io/jsonpatch-'
To verify integrity of the cluster version, execute the following:
oc get clusterversion version
If the Cluster Version Operator is not installed or the AVAILABLE is not set to "True", this is a finding.
Run the following command to retrieve the Cluster Version objects in the system:
oc get clusterversion version -o yaml
If 'verified: true', under status history for each item is not present, this is a finding.
Where OpenShift Virtualization is enabled:
$ oc get hyperconverged kubevirt-hyperconverged -n openshift-cnv -o
jsonpath='{.metadata.annotations}'| jq
'.|has("kubevirt.kubevirt.io/jsonpatch")'
$ oc get hyperconverged kubevirt-hyperconverged -n openshift-cnv -o
jsonpath='{.metadata.annotations}'| jq
'.|has("containerizeddataimporter.kubevirt.io/jsonpatch")'
$ oc get hyperconverged kubevirt-hyperconverged -n openshift-cnv -o
jsonpath='{.metadata.annotations}'| jq
'.|has("networkaddonsconfigs.kubevirt.io/jsonpatch")'
$ oc get hyperconverged kubevirt-hyperconverged -n openshift-cnv -o
jsonpath='{.metadata.annotations}'| jq
'.|has("ssp.kubevirt.io/jsonpatch")'
If any results are returned aside from empty strings, this is a finding.
V-257561
False
CNTR-OS-000740
To verify integrity of the cluster version, execute the following:
oc get clusterversion version
If the Cluster Version Operator is not installed or the AVAILABLE is not set to "True", this is a finding.
Run the following command to retrieve the Cluster Version objects in the system:
oc get clusterversion version -o yaml
If 'verified: true', under status history for each item is not present, this is a finding.
Where OpenShift Virtualization is enabled:
$ oc get hyperconverged kubevirt-hyperconverged -n openshift-cnv -o
jsonpath='{.metadata.annotations}'| jq
'.|has("kubevirt.kubevirt.io/jsonpatch")'
$ oc get hyperconverged kubevirt-hyperconverged -n openshift-cnv -o
jsonpath='{.metadata.annotations}'| jq
'.|has("containerizeddataimporter.kubevirt.io/jsonpatch")'
$ oc get hyperconverged kubevirt-hyperconverged -n openshift-cnv -o
jsonpath='{.metadata.annotations}'| jq
'.|has("networkaddonsconfigs.kubevirt.io/jsonpatch")'
$ oc get hyperconverged kubevirt-hyperconverged -n openshift-cnv -o
jsonpath='{.metadata.annotations}'| jq
'.|has("ssp.kubevirt.io/jsonpatch")'
If any results are returned aside from empty strings, this is a finding.
M
5547