Skip to content

Conversation

@louiseschmidtgen
Copy link
Contributor

@louiseschmidtgen louiseschmidtgen commented Oct 1, 2025

Description

This PR updates the disa-stig instructions by including a disa-stig hardening page with the bootstrap/join templates as well as updates to the disa-stig assessment page.

Checklist

  • PR title formatted as type: title
  • Covered by unit tests
  • Covered by integration tests
  • Documentation updated
  • CLA signed
  • Backport label added if necessary

Copy link
Contributor

@nhennigan nhennigan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is clear a lot of effort has gone into this, thanks Louise! I like the separation of the guides. I feel they were blurring the lines a bit between their purposes. I have been playing around with a few different versions of how to present the docs and this is what I have come up with (and how that relates to this PR):

snap 
|- how-to 
     |- install 
          |- how to install in FIPS mode / FIPS enabled CK8s
          |- how to install DISA STIG compliant (this would be your disa-stig-hardening)
     |- security 
          |- how to harden your cluster (basically the same as now but updated with latest from the playbook)
          |- how to assess CIS (this would just be kube-bench instructions)
|- reference
     |- CIS (all the CIS recommendations)
     |- DISA STIGs (All stigs - your disa-stig-assessment)
     |- security (update the links)
|- explanation 
     |- security (make this one page with disa stig and fips included)

How do you feel about this proposed layout? There would need to be a bit of rework of disa-stig-assessment to make it an install how to guide but I think the work you have done here is a massive help. The assumption would be that:

  • you would have DISA STIG compliance achieved with the install guide (both host and k8s) so you won't really need a how to guide to disa stig the cluster (please tell me if Im wrong here)
  • you can go to the reference if you need any specific steps audited
  • you can apply the hardening guide after any install -> after this you will be CIS compliant and DISA STIG k8s only compliant

@louiseschmidtgen louiseschmidtgen marked this pull request as ready for review October 2, 2025 12:31
@louiseschmidtgen louiseschmidtgen requested a review from a team as a code owner October 2, 2025 12:31
Copy link
Contributor

@rapour rapour left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thorough work @louiseschmidtgen, thanks, left a couple of comments

Copy link
Contributor

@rapour rapour left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great work @louiseschmidtgen

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants