-
Notifications
You must be signed in to change notification settings - Fork 32
docs: disa-stig hardening guide #1882
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It is clear a lot of effort has gone into this, thanks Louise! I like the separation of the guides. I feel they were blurring the lines a bit between their purposes. I have been playing around with a few different versions of how to present the docs and this is what I have come up with (and how that relates to this PR):
snap
|- how-to
|- install
|- how to install in FIPS mode / FIPS enabled CK8s
|- how to install DISA STIG compliant (this would be your disa-stig-hardening)
|- security
|- how to harden your cluster (basically the same as now but updated with latest from the playbook)
|- how to assess CIS (this would just be kube-bench instructions)
|- reference
|- CIS (all the CIS recommendations)
|- DISA STIGs (All stigs - your disa-stig-assessment)
|- security (update the links)
|- explanation
|- security (make this one page with disa stig and fips included)
How do you feel about this proposed layout? There would need to be a bit of rework of disa-stig-assessment to make it an install how to guide but I think the work you have done here is a massive help. The assumption would be that:
- you would have DISA STIG compliance achieved with the install guide (both host and k8s) so you won't really need a how to guide to disa stig the cluster (please tell me if Im wrong here)
- you can go to the reference if you need any specific steps audited
- you can apply the hardening guide after any install -> after this you will be CIS compliant and DISA STIG k8s only compliant
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thorough work @louiseschmidtgen, thanks, left a couple of comments
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Great work @louiseschmidtgen
Description
This PR updates the disa-stig instructions by including a disa-stig hardening page with the bootstrap/join templates as well as updates to the disa-stig assessment page.
Checklist
type: title