-
Notifications
You must be signed in to change notification settings - Fork 709
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add initial C2S Docker Profile #2422
Conversation
As it is this profile brings no value to users, I propose we implement at least some of the rules before we merge it. |
That's correct. Would like to get this in so people can start helping contributing towards it. |
Hmm. Could we perhaps start a branch that we will merge after the profiles have rules in them? We have an SSG release scheduled for end of the month, I don't want it to contain empty profiles. |
@mpreisler I selected at least one rule; otherwise, it would not have built. ;-P |
We already started a Docker profile for RHEL7. It's here https://github.com/OpenSCAP/scap-security-guide/blob/master/rhel7/profiles/docker-host.xml . The profile was also meant to follow the CIS Docker Community Edition Benchmark. I remember I studied the document that time. However soon we didn't see a value in implementing a profile for Docker. What has changed? And why to have 2 profiles that are going to implement the same baseline? |
Not sure where this confusion is coming from here, but it is valuable for implementing a Docker profile. |
AFAIK we definitely saw value in it, we just prioritized content for containers and container images over content for docker host. There is value in docker host content for sure. |
I think we can merge and introduce this Profile to SSG. |
Merging, let the Profile grow and bloom! |
I will reiterate that IMO this shouldn't have been merged. There is nothing in this profile, no value for users. Now it's in a release and will show up in installers, SCAP Workbench, guides, ... |
@mpreisler Sorry for overlooking your review. With #2422 (comment) I thought your comment was addressed. Maybe it was a joke and I didn't get it. I get your point. This Profile may be extreme example, with just one rule selected. But Profiles like ANSSI or HIPAA were also in very initial state. (though, thanks to #2650, HIPAA has much more content). |
Description:
Rationale: