Skip to content
Open
Show file tree
Hide file tree
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,88 @@
apiVersion: policy.open-cluster-management.io/v1
kind: Policy
metadata:
name: policy-node-image-lifecycle
annotations:
policy.open-cluster-management.io/standards: NIST SP 800-53
policy.open-cluster-management.io/categories: CM Configuration Management
policy.open-cluster-management.io/controls: CM-2 Baseline Configuration, SI-2 Flaw Remediation
spec:
remediationAction: inform
disabled: false
Comment thread
coderabbitai[bot] marked this conversation as resolved.
policy-templates:
- objectDefinition:
apiVersion: policy.open-cluster-management.io/v1
kind: ConfigurationPolicy
metadata:
name: policy-kubelet-image-gc
spec:
remediationAction: inform
severity: medium
object-templates:
- complianceType: musthave
objectDefinition:
apiVersion: machineconfiguration.openshift.io/v1
kind: KubeletConfig
metadata:
name: image-gc-policy
spec:
machineConfigPoolSelector:
matchLabels:
pools.operator.machineconfiguration.openshift.io/worker: ""
kubeletConfig:
imageGCHighThresholdPercent: 65
imageGCLowThresholdPercent: 50
imageMinimumGCAge: 5m
- objectDefinition:
apiVersion: policy.open-cluster-management.io/v1
kind: ConfigurationPolicy
metadata:
name: policy-image-prune-timer
spec:
remediationAction: inform
severity: medium
object-templates:
- complianceType: musthave
objectDefinition:
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
metadata:
name: 99-worker-image-gc-prune
labels:
machineconfiguration.openshift.io/role: worker
spec:
config:
ignition:
version: 3.2.0
storage:
files:
- path: /usr/local/bin/image-gc-prune.sh
mode: 0755
contents:
source: data:text/plain;charset=utf-8;base64,IyEvYmluL2Jhc2gKIyBQcnVuZSB1bnJlZmVyZW5jZWQgY29udGFpbmVyIGltYWdlcyBvbGRlciB0aGFuIE1BWF9BR0VfREFZUwpNQVhfQUdFX0RBWVM9NwpOT1c9JChkYXRlICslcykKQ1VUT0ZGPSQoKE5PVyAtIE1BWF9BR0VfREFZUyAqIDg2NDAwKSkKUkVNT1ZFRD0wClNLSVBQRUQ9MApSRUZFUkVOQ0VEPTAKVU5QQVJTQUJMRT0wCgojIEJ1aWxkIHNldCBvZiBpbWFnZSBJRHMgcmVmZXJlbmNlZCBieSBhbnkgY29udGFpbmVyIChvbmUgY2FsbCwgbm90IE4pCkNPTlRBSU5FUl9JTUFHRVM9JChjcmljdGwgcHMgLWEgLW8ganNvbiAyPi9kZXYvbnVsbCBcCiAgfCBweXRob24zIC1jICIKaW1wb3J0IHN5cywganNvbgp0cnk6CiAgICBkID0ganNvbi5sb2FkKHN5cy5zdGRpbikKICAgIGZvciBjIGluIGQuZ2V0KCdjb250YWluZXJzJywgW10pOgogICAgICAgIHByaW50KGMuZ2V0KCdpbWFnZVJlZicsICcnKSkKZXhjZXB0IEV4Y2VwdGlvbjoKICAgIHBhc3MKIiAyPi9kZXYvbnVsbCB8IHNvcnQgLXUpCgpmb3IgSU1HX0lEIGluICQoY3JpY3RsIGltYWdlcyAtcSk7IGRvCiAgaWYgZWNobyAiJENPTlRBSU5FUl9JTUFHRVMiIHwgZ3JlcCAtcUYgIiRJTUdfSUQiOyB0aGVuCiAgICBSRUZFUkVOQ0VEPSQoKFJFRkVSRU5DRUQgKyAxKSkKICAgIGNvbnRpbnVlCiAgZmkKCiAgIyBFeHRyYWN0IGNyZWF0aW9uIHRpbWVzdGFtcCAocHl0aG9uMyBmb3IgSlNPTiwgZGF0ZSAtZCBmb3IgcGFyc2luZykKICBUUz0kKGNyaWN0bCBpbnNwZWN0aSAiJElNR19JRCIgMj4vZGV2L251bGwgXAogICAgfCBweXRob24zIC1jICIKaW1wb3J0IHN5cywganNvbgp0cnk6CiAgICBkID0ganNvbi5sb2FkKHN5cy5zdGRpbikKICAgIHByaW50KGQuZ2V0KCdpbmZvJywge30pLmdldCgnaW1hZ2VTcGVjJywge30pLmdldCgnY3JlYXRlZCcsICcnKSBvciBkLmdldCgnc3RhdHVzJywge30pLmdldCgnY3JlYXRlZEF0JywgJycpKQpleGNlcHQgRXhjZXB0aW9uOgogICAgcGFzcwoiIDI+L2Rldi9udWxsKQogIENSRUFURURfVFM9JChkYXRlIC1kICIkVFMiICslcyAyPi9kZXYvbnVsbCB8fCBlY2hvIDApCgogIGlmIFsgIiRDUkVBVEVEX1RTIiAtZXEgMCBdOyB0aGVuCiAgICBVTlBBUlNBQkxFPSQoKFVOUEFSU0FCTEUgKyAxKSkKICAgIGNvbnRpbnVlCiAgZmkKCiAgaWYgWyAiJENSRUFURURfVFMiIC1sdCAiJENVVE9GRiIgXTsgdGhlbgogICAgY3JpY3RsIHJtaSAiJElNR19JRCIgMj4mMSB8fCB0cnVlCiAgICBSRU1PVkVEPSQoKFJFTU9WRUQgKyAxKSkKICBlbHNlCiAgICBTS0lQUEVEPSQoKFNLSVBQRUQgKyAxKSkKICBmaQpkb25lCgpsb2dnZXIgLXQgaW1hZ2UtZ2MtcHJ1bmUgInJlZmVyZW5jZWQ9JFJFRkVSRU5DRUQgcmVtb3ZlZD0kUkVNT1ZFRCBza2lwcGVkPSRTS0lQUEVEIHVucGFyc2FibGU9JFVOUEFSU0FCTEUiCg==
Comment thread
coderabbitai[bot] marked this conversation as resolved.
Outdated
systemd:
units:
- name: image-gc-prune.service
enabled: false
contents: |
[Unit]
Description=Prune unreferenced container images older than 7 days
Wants=crio.service
After=crio.service

[Service]
Type=oneshot
ExecStart=/usr/local/bin/image-gc-prune.sh
- name: image-gc-prune.timer
enabled: true
contents: |
[Unit]
Description=Weekly container image prune

[Timer]
OnCalendar=Sun *-*-* 02:00:00
RandomizedDelaySec=3600
Persistent=true

[Install]
WantedBy=timers.target
1 change: 1 addition & 0 deletions community/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -115,6 +115,7 @@ Policy | Description | Prerequisites
[Install OpenShift-Gitops](./CM-Configuration-Management/policy-openshift-gitops.yaml) | Use this policy to install the Red Hat OpenShift GitOps operator which can be used to install and configure Gitops, Tekton and ArgoCD | Requires OpenShift 4.x. Check the [documentation](https://docs.openshift.com/container-platform/latest/cicd/gitops/gitops-release-notes.html) for more information.
[Configure OpenShift-Gitops with the Policy Generator](./CM-Configuration-Management/policy-openshift-gitops-policygenerator.yaml) | Use this policy to configure the Red Hat OpenShift GitOps operator to run the policy generator | Requires OpenShift 4.x and requires the Openshift GitOps operator to be installed. Check the [documentation](https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.7/html/governance/governance#policy-gen-install-on-openshift-gitops) for more details.
[Configure OpenShift Image-Pruner](./CM-Configuration-Management/policy-resiliency-image-pruner.yaml) | Use this policy to configure the OpenShift Image-Pruner | OpenShift 4.x is required. Check the [documentation](https://docs.openshift.com/container-platform/latest/applications/pruning-objects.html) for more information
[Configure Node Image Lifecycle](./CM-Configuration-Management/policy-node-image-lifecycle.yaml) | Use this policy to tune kubelet image garbage collection thresholds and deploy a weekly CronJob to prune unused container images from worker nodes. Prevents stale images from prior cluster versions accumulating on nodes, which can cause false positives in image-based security scanners. | OpenShift 4.8+ is required.
[Policy to configure a POD Disruption Budget](./CM-Configuration-Management/policy-engineering-pod-disruption-budget.yaml) | use this policy to configure a Pod Disruption Budget| Check Kubernetes [documentation](https://kubernetes.io/docs/tasks/run-application/configure-pdb/) for more information
[Policy to configure a cluster autoscaler](./CM-Configuration-Management/policy-autoscaler.yaml) | Use this policy to configure a `ClusterAutoscaler`. | OpenShift 4.x is required. Check the OpenShift [documentation](https://docs.openshift.com/container-platform/latest/post_installation_configuration/cluster-tasks.html#informational-resources_post-install-cluster-tasks) for more information.
[Policy to configure Ingress Controller](./CM-Configuration-Management/policy-ingress-controller.yaml) | Use this policy to configure the IngressController | OpenShift 4.x is required. Check the OpenShift [documentation](https://docs.openshift.com/container-platform/latest/post_installation_configuration/cluster-tasks.html#informational-resources_post-install-cluster-tasks) for more information on how to customize this policy.
Expand Down