Move RHV4 product to be el8 based#5352
Conversation
a45de90 to
ee5ed7d
Compare
|
I'd appreciate feedback on contents of I have realized now that the Maybe |
ee5ed7d to
f4a3de0
Compare
|
For easy of review, I've dropped ee5ed7d, and will propose it separately. The commit just did bulk labeling, any rule that applied to |
f4a3de0 to
c1de382
Compare
|
So, I think it makes sense to update the profile to be based on RHEL8 versions. Unfortunately this makes 0665267 mandatory, as it now enables a few rules needed by the profile. |
@redhatrises, @shawndwells Would appreciate your feedback here |
|
Can one of the admins verify this patch? |
|
A couple of thoughts:
|
|
Also don't create a separate README integrate the comments into the main README or in the docs. |
9ae8bf9 to
d966a7f
Compare
|
Ok, dropped commits that migrate profiles and all rules to el8.
I don't know where would be a good place for such information to be. I moved it to be in the User Guide. |
d966a7f to
7cd2141
Compare
Changes selection of FIPS related rules in RHV4 product to the appropriate RHEL8 equivalent. Also migrates rule prodtypes and platforms to rhel8.
And unselect rules made obsolete by them Also migrates rule prodtypes and platforms to rhel8.
Rules that configure audispd plugin are failing due to missing config files.
And migrate their prodtypes and platforms to rhel8.
As the node becomes rhel8 based, the gpg keys become the same as rhel8 keys.
As RHV4 moves to be rhel8 based, this doesn't apply anymore to rhv4.
These packages are not present in rhel8.
Make rhv4 product applicable to version 4.4 and newer.
7cd2141 to
9f4652c
Compare
|
Conflicts resolved. |
|
/test all ocp4 e2e test flake |
|
/test all |
|
I have no idea how to interpret error in Is it a deal breaker? |
redhatrises
left a comment
There was a problem hiding this comment.
Looks good to me. As this is draft content, all these changes are fine.
|
/retest |
|
@yuumasato: The following test failed, say
Full PR test history. Your PR dashboard. Please help us cut down on flakes by linking to an open issue when you hit one in your PR. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
|
The PR has been approved, and those failing tests don't indicate that there is something wrong with it, so I am merging it. |
Description:
rhv4product applies to el8 based hosts[ ] Update prodtype in other rules.Rationale:
rhel7productrhv4productRelated to: https://lists.fedoraproject.org/archives/list/scap-security-guide@lists.fedorahosted.org/thread/CSNMJJWYPAUVBCQFCRIJHJ7PHOBE6SDB/
References