diff --git a/cfg/config.yaml b/cfg/config.yaml index 71699cab6e7759601c5fe7ee5ca0e02cc67ec6e7..71f1e45c23a43c72d299f9525fbe6698f05d2de5 100644 --- a/cfg/config.yaml +++ b/cfg/config.yaml @@ -25,6 +25,7 @@ master: - "hyperkube apiserver" - "hyperkube kube-apiserver" - "apiserver" + - "openshift start master api" confs: - /etc/kubernetes/manifests/kube-apiserver.yaml - /etc/kubernetes/manifests/kube-apiserver.manifest @@ -37,6 +38,7 @@ master: - "hyperkube scheduler" - "hyperkube kube-scheduler" - "scheduler" + - "openshift start master controllers" confs: - /etc/kubernetes/manifests/kube-scheduler.yaml - /etc/kubernetes/manifests/kube-scheduler.manifest @@ -50,6 +52,7 @@ master: - "hyperkube controller-manager" - "hyperkube kube-controller-manager" - "controller-manager" + - "openshift start master controllers" confs: - /etc/kubernetes/manifests/kube-controller-manager.yaml - /etc/kubernetes/manifests/kube-controller-manager.manifest @@ -172,4 +175,4 @@ version_mapping: "1.16": "cis-1.5" "1.17": "cis-1.5" "ocp-3.10": "rh-0.7" - "ocp-3.11": "rh-0.7" \ No newline at end of file + "ocp-3.11": "rh-0.7" diff --git a/cfg/rh-0.7/config.yaml b/cfg/rh-0.7/config.yaml index df1517206fc2145f1c0c1538b7804008ce9ecce4..b76332d576de18694ff3c37b073ba081c17762d9 100644 --- a/cfg/rh-0.7/config.yaml +++ b/cfg/rh-0.7/config.yaml @@ -22,6 +22,9 @@ master: - openshift start etcd node: + svcs: + - /etc/systemd/system/atomic-openshift-node.service + - /etc/systemd/system/origin-node.service proxy: bins: - openshift start network diff --git a/cfg/rh-0.7/node.yaml b/cfg/rh-0.7/node.yaml index 7fcd8eca26249f847cd4d341c546e8d17344d97f..996965dfaec110b42a102b5831d9f15eccca1fa7 100644 --- a/cfg/rh-0.7/node.yaml +++ b/cfg/rh-0.7/node.yaml @@ -254,7 +254,7 @@ groups: - id: 8.3 text: "Verify the kubelet service file permissions of 644" - audit: "stat -c %a /etc/systemd/system/atomic-openshift-node.service" + audit: "stat -c %a $nodesvc" tests: bin_op: or test_items: @@ -275,12 +275,12 @@ groups: set: true remediation: | Run the below command on each worker node. - chmod 644 /etc/systemd/system/atomic-openshift-node.service + chmod 644 $nodesvc scored: true - id: 8.4 text: "Verify the kubelet service file ownership of root:root" - audit: "stat -c %U:%G /etc/systemd/system/atomic-openshift-node.service" + audit: "stat -c %U:%G $nodesvc" tests: test_items: - flag: "root:root" @@ -290,7 +290,7 @@ groups: set: true remediation: | Run the below command on each worker node. - chown root:root /etc/systemd/system/atomic-openshift-node.service + chown root:root $nodesvc scored: true - id: 8.5