Skip to content

Conversation

@nhennigan
Copy link
Contributor

@nhennigan nhennigan commented Oct 6, 2025

Description

We need to update our docs to include the latest info on DISA STIG and FIPS. This is the first PR where I will tackle the reference pages.

Solution

  • I have moved the CIS manual audit to reference
  • I have moved the DISA STIG manual audit to reference. This is taken from @louiseschmidtgen PR docs: disa-stig hardening guide #1882 disa-stig-assessment.md
  • I have updated the links in the security reference page (There are TODOs but I will fill those in once I have all PRs up)

Issue

N/A

Backport

1.34 only

Checklist

  • PR title formatted as type: title
  • Covered by unit tests
  • Covered by integration tests
  • Documentation updated
  • CLA signed
  • Backport label added if necessary

If any item on the checklist is not complete, please provide justification why.

@nhennigan nhennigan requested a review from a team as a code owner October 6, 2025 21:48
Copy link
Contributor

@louiseschmidtgen louiseschmidtgen left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the auditing should stay in the how-to section. While there are many rules to reference we're still making users apply some of these commands. In that sense it is more of a how to in my opinion. Wdyt?

Moving this page from a how to reference means updating some of the language. I also updated the references to disa-stig-hardening
@louiseschmidtgen louiseschmidtgen changed the base branch from main to KU-4397/fips-stig-docs-release-branch October 16, 2025 09:13
@louiseschmidtgen
Copy link
Contributor

Changed the base branch to the feature branch KU-4397/fips-stig-docs-release-branch where we will collect all PRs for the docs release.

@louiseschmidtgen
Copy link
Contributor

I think the auditing should stay in the how-to section. While there are many rules to reference we're still making users apply some of these commands. In that sense it is more of a how to in my opinion. Wdyt?

We discussed this async. TAs think this should be more of a reference page. We can work in the future on bringing some of the actionable steps into the how-tos.

@louiseschmidtgen
Copy link
Contributor

louiseschmidtgen commented Oct 16, 2025

It looks like I missed one update missing for this argument:
extra-node-kube-scheduler-args: --bind-address: 127.0.0.1 and feature-gates. I will make a commit. (I will do this in the feature branch)

@louiseschmidtgen louiseschmidtgen merged commit 5f50c6d into canonical:KU-4397/fips-stig-docs-release-branch Oct 16, 2025
7 of 8 checks passed
github-actions bot pushed a commit that referenced this pull request Oct 16, 2025
@cdkbot
Copy link
Collaborator

cdkbot commented Oct 16, 2025

Successfully created backport PR for release-1.34:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants