Skip to content

Add OCP 5.0 Gap Analysis files#2759

Open
rosa-gap-analysis-bot wants to merge 2 commits into
openshift:masterfrom
rosa-gap-analysis-bot:ocp-5.0-gap-analysis-update
Open

Add OCP 5.0 Gap Analysis files#2759
rosa-gap-analysis-bot wants to merge 2 commits into
openshift:masterfrom
rosa-gap-analysis-bot:ocp-5.0-gap-analysis-update

Conversation

@rosa-gap-analysis-bot

@rosa-gap-analysis-bot rosa-gap-analysis-bot commented May 26, 2026

Copy link
Copy Markdown

Summary

This PR adds OpenShift 5.0.0-ec.1 credential policies and acknowledgments to address gap-analysis validation failures.

Prow Job: View Job Details
HTML Report: View Full Report
Baseline: 4.22.0-rc.4
Target: 5.0.0-ec.1

Validation Failures

The gap-analysis detected the following missing resources for OCP 5.0.0-ec.1:

  • Missing credential policies and acknowledgment files for OCP 5.0

Resolution

This PR adds the following files to resolve the validation failures:

AWS STS IAM Policies (30)

- resources/sts/5.0/openshift_aws_vpce_operator_avo_aws_creds_policy.json
- resources/sts/5.0/openshift_capa_controller_manager_credentials_policy.json
- resources/sts/5.0/openshift_cloud_credential_operator_cloud_credential_operator_iam_ro_creds_policy.json
- resources/sts/5.0/openshift_cloud_ingress_operator_cloud_credentials_policy.json
- resources/sts/5.0/openshift_cloud_network_config_controller_cloud_credentials_policy.json
- resources/sts/5.0/openshift_cluster_csi_drivers_ebs_cloud_credentials_policy.json
- resources/sts/5.0/openshift_control_plane_operator_credentials_policy.json
- resources/sts/5.0/openshift_image_registry_installer_cloud_credentials_policy.json
- resources/sts/5.0/openshift_ingress_operator_cloud_credentials_policy.json
- resources/sts/5.0/openshift_kms_provider_credentials_policy.json
- resources/sts/5.0/openshift_kube_controller_manager_credentials_policy.json
- resources/sts/5.0/openshift_machine_api_aws_cloud_credentials_policy.json
- resources/sts/5.0/operator_iam_role_policy.json
- resources/sts/5.0/osd_scp_policy.json
- resources/sts/5.0/shared_vpc_openshift_ingress_operator_cloud_credentials_policy.json
- resources/sts/5.0/sts_installer_core_permission_boundary_policy.json
- resources/sts/5.0/sts_installer_permission_policy.json
- resources/sts/5.0/sts_installer_privatelink_permission_boundary_policy.json
- resources/sts/5.0/sts_installer_trust_policy.json
- resources/sts/5.0/sts_installer_vpc_permission_boundary_policy.json
- resources/sts/5.0/sts_instance_controlplane_permission_policy.json
- resources/sts/5.0/sts_instance_controlplane_trust_policy.json
- resources/sts/5.0/sts_instance_worker_permission_policy.json
- resources/sts/5.0/sts_instance_worker_trust_policy.json
- resources/sts/5.0/sts_ocm_admin_permission_policy.json
- resources/sts/5.0/sts_ocm_permission_policy.json
- resources/sts/5.0/sts_ocm_trust_policy.json
- resources/sts/5.0/sts_ocm_user_trust_policy.json
- resources/sts/5.0/sts_support_permission_policy.json
- resources/sts/5.0/sts_support_trust_policy.json

GCP Workload Identity Templates (1)

- resources/wif/5.0/vanilla.yaml

Acknowledgment Files (4)

- deploy/osd-cluster-acks/sts/5.0/config.yaml
- deploy/osd-cluster-acks/sts/5.0/osd-sts-ack_CloudCredential.yaml
- deploy/osd-cluster-acks/wif/5.0/config.yaml
- deploy/osd-cluster-acks/wif/5.0/osd-wif-ack_CloudCredential.yaml

Note: No OCP admin gates found for version 5.0 - no OCP acknowledgment files created.

Files Included

  • AWS STS Policies: 30 IAM policy files
  • GCP WIF Templates: 1 workload identity template(s)
  • Acknowledgment Files: 4 admin acknowledgment file(s)

Total: 35 files

Note: Additional files (ACM policies, hack templates) are generated by the make command after PR merge.

Testing

All files have been:

  • ✅ Validated for JSON/YAML syntax
  • ✅ Generated from official OCP release 5.0.0-ec.1
  • ✅ Verified against managed-cluster-config structure

Generated by ROSA Gap Analysis automation from Prow failure analysis.

Summary by CodeRabbit

  • New Features

    • Added OpenShift 5.0 deployment support for AWS STS and WIF credential modes with targeted selector-based rollout criteria.
    • Added cluster-level cloud credential manifests annotated for v5.0 upgradeability.
  • Chores

    • Added comprehensive AWS IAM and trust policy documents for operators, control plane, networking, storage, installer, and support roles.
    • Added WIF template and service-account credential mappings for v5.0.

- AWS STS IAM policies: 30 file(s)
- GCP WIF templates: 1 file(s)
- Acknowledgment files: 4 file(s)

Addresses gap-analysis validation failures for OCP 5.0.

Co-Authored-By: ROSA Gap Analysis Bot <rosa-gap-analysis-bot@redhat.com}
@coderabbitai

coderabbitai Bot commented May 26, 2026

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 21edab64-c1c7-47db-b1a4-df892cd091e2

📥 Commits

Reviewing files that changed from the base of the PR and between 98daa38 and 30e6b4a.

⛔ Files ignored due to path filters (3)
  • hack/00-osd-managed-cluster-config-integration.yaml.tmpl is excluded by !hack/**
  • hack/00-osd-managed-cluster-config-production.yaml.tmpl is excluded by !hack/**
  • hack/00-osd-managed-cluster-config-stage.yaml.tmpl is excluded by !hack/**
📒 Files selected for processing (5)
  • deploy/acm-policies/50-GENERATED-.Policy.yaml
  • deploy/osd-cluster-acks/sts/5.0/config.yaml
  • deploy/osd-cluster-acks/wif/5.0/config.yaml
  • resources/sts/5.0/openshift_kube_controller_manager_credentials_policy.json
  • resources/wif/5.0/vanilla.yaml
💤 Files with no reviewable changes (2)
  • resources/sts/5.0/openshift_kube_controller_manager_credentials_policy.json
  • resources/wif/5.0/vanilla.yaml
✅ Files skipped from review due to trivial changes (1)
  • deploy/osd-cluster-acks/sts/5.0/config.yaml
🚧 Files skipped from review as they are similar to previous changes (1)
  • deploy/osd-cluster-acks/wif/5.0/config.yaml

Walkthrough

This pull request adds complete infrastructure configuration for OpenShift 5.0 support using Secure Token Service (STS) for AWS and Workload Identity Federation (WIF) for GCP. It includes deployment targeting configurations, 27 AWS IAM credential policies for operators and system components, and a comprehensive GCP workload identity federation template with service account mappings.

Changes

OpenShift 5.0 STS and WIF Identity Configuration

Layer / File(s) Summary
Deployment and Cluster Targeting Configuration
deploy/osd-cluster-acks/sts/5.0/*, deploy/osd-cluster-acks/wif/5.0/*
SelectorSyncSet configurations and CloudCredential manifests target OpenShift 4.22 clusters with STS and WIF enabled, defining deployment scope and upgradeable-to annotations.
AWS IAM Foundation and Service Policies
resources/sts/5.0/openshift_cloud_credential_operator*, resources/sts/5.0/openshift_kms_provider*, resources/sts/5.0/openshift_cluster_csi_drivers*, resources/sts/5.0/openshift_control_plane_operator*, resources/sts/5.0/openshift_ingress_operator*, resources/sts/5.0/sts_installer_vpc*, resources/sts/5.0/sts_instance_worker*
Simple, focused credentials policies for core infrastructure: read-only cloud credential access, KMS encryption, EBS management, control-plane networking, ingress DNS, VPC provisioning, and worker node discovery.
AWS IAM Operator and Controller Policies
resources/sts/5.0/openshift_capa_controller_manager*, resources/sts/5.0/openshift_cloud_ingress_operator*, resources/sts/5.0/openshift_cloud_network_config_controller*, resources/sts/5.0/openshift_aws_vpce_operator*, resources/sts/5.0/openshift_image_registry_installer*, resources/sts/5.0/openshift_kube_controller_manager*, resources/sts/5.0/openshift_machine_api_aws*, resources/sts/5.0/sts_instance_controlplane*
Complex multi-service IAM policies enabling cluster operators to manage compute, networking, storage, DNS, and load balancing across EC2, ELB, Route53, and IAM services.
AWS IAM Installation, Administration, and Support Policies
resources/sts/5.0/operator_iam_role_policy.json, resources/sts/5.0/sts_installer_permission_policy.json, resources/sts/5.0/sts_installer_core_permission_boundary_policy.json, resources/sts/5.0/sts_installer_privatelink_permission_boundary_policy.json, resources/sts/5.0/sts_ocm_*, resources/sts/5.0/sts_support_*, resources/sts/5.0/shared_vpc_openshift_ingress_operator*, resources/sts/5.0/osd_scp_policy.json
Installer and OCM admin role policies, permission boundaries for privileged operations, support team access, shared VPC ingress, and service control policy allowing broad AWS service access with secret manager tagging constraints.
GCP Workload Identity Federation Template
resources/wif/5.0/vanilla.yaml
Complete WIF template defining 11 service account mappings with impersonate and WIF access methods, custom permissions for compute, networking, storage, DNS, IAM, and monitoring across GCP APIs, plus support role with operational read access.

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

🚥 Pre-merge checks | ✅ 12
✅ Passed checks (12 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main objective of the PR: adding OpenShift 5.0 gap analysis files to address validation failures.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed This PR adds 35 configuration files (30 JSON policy files and 5 YAML config files). It contains no Go test files or Ginkgo test patterns whatsoever; check is not applicable.
Test Structure And Quality ✅ Passed This PR contains no Ginkgo test code - only configuration YAML and JSON policy files. The repository contains zero Go test files, making this check not applicable.
Microshift Test Compatibility ✅ Passed PR adds only configuration files (YAML/JSON policy documents), not Ginkgo e2e tests. Check for MicroShift test compatibility is not applicable as no tests are being added.
Single Node Openshift (Sno) Test Compatibility ✅ Passed No Ginkgo e2e tests are added in this PR. All 35 added files are static configuration (YAML) and IAM policy (JSON) files with no test code, making the SNO test compatibility check not applicable.
Topology-Aware Scheduling Compatibility ✅ Passed PR adds only credential policies (JSON), acknowledgment configs, and credential templates—no deployment manifests, operator code, or controllers with scheduling constraints.
Ote Binary Stdout Contract ✅ Passed PR adds only configuration/manifest files (YAML, JSON) to managed-cluster-config repo. No Go code, binaries, or executable components present; OTE contract check not applicable.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed PR adds configuration files, IAM policies, and templates only—no Ginkgo e2e tests. Check not applicable to this PR.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@openshift-ci

openshift-ci Bot commented May 26, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: rosa-gap-analysis-bot
Once this PR has been reviewed and has the lgtm label, please assign iamkirkbater for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. label May 26, 2026
@openshift-ci

openshift-ci Bot commented May 26, 2026

Copy link
Copy Markdown
Contributor

Hi @rosa-gap-analysis-bot. Thanks for your PR.

I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@ravitri

ravitri commented May 26, 2026

Copy link
Copy Markdown
Member

/ok-to-test

@openshift-ci openshift-ci Bot added ok-to-test Indicates a non-member PR verified by an org member that is safe to test. and removed needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. labels May 26, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 6

🧹 Nitpick comments (1)
resources/sts/5.0/sts_installer_permission_policy.json (1)

69-70: 💤 Low value

Deprecated EC2-Classic actions can be removed.

ec2:DescribeVpcClassicLink and ec2:DescribeVpcClassicLinkDnsSupport reference EC2-Classic features that AWS retired in August 2022. These actions are no longer functional and can be safely removed to reduce policy clutter.

Proposed cleanup
         "ec2:DescribeVpcAttribute",
-        "ec2:DescribeVpcClassicLink",
-        "ec2:DescribeVpcClassicLinkDnsSupport",
         "ec2:DescribeVpcEndpoints",
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@resources/sts/5.0/sts_installer_permission_policy.json` around lines 69 - 70,
Remove the two deprecated EC2-Classic actions "ec2:DescribeVpcClassicLink" and
"ec2:DescribeVpcClassicLinkDnsSupport" from the JSON "Action" array in the
policy (they are the entries currently listed as ec2:DescribeVpcClassicLink and
ec2:DescribeVpcClassicLinkDnsSupport); delete those strings and adjust commas so
the JSON array remains valid (no trailing commas), then validate the policy JSON
structure and re-run any linter/formatter to ensure formatting is unchanged.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@deploy/osd-cluster-acks/sts/5.0/config.yaml`:
- Around line 1-9: Add an explicit resourceApplyMode entry at the same level as
deploymentMode (e.g., resourceApplyMode: <desired-mode>) and update the
selectorSyncSet.matchExpressions to include an exclusion for fedramp by adding a
matchExpressions item with key: api.openshift.com/fedramp, operator: NotIn,
values: ["true"]; keep the existing hive.openshift.io/version-major-minor and
api.openshift.com/sts entries unchanged so the deploymentMode, selectorSyncSet,
and resourceApplyMode (top-level) together drive targeting/apply behavior.

In `@deploy/osd-cluster-acks/wif/5.0/config.yaml`:
- Around line 1-9: Add an explicit resourceApplyMode key under the top-level
(e.g., resourceApplyMode: Sync) and extend the selectorSyncSet.matchExpressions
to include an exclusion for the FedRAMP label by adding a matchExpression with
key: api.openshift.com/fedramp, operator: NotIn, values: ["true"]; update the
existing selectorSyncSet block (which currently contains matchExpressions with
keys hive.openshift.io/version-major-minor and api.openshift.com/wif) to include
this new fedramp exclusion so rollout semantics and compliance targeting are
complete.

In `@resources/sts/5.0/openshift_aws_vpce_operator_avo_aws_creds_policy.json`:
- Around line 29-53: The policy currently grants
route53:ChangeResourceRecordSets unconditionally and again in the statement with
Sid "Route53ManageRecords" (which includes domain restrictions), making the
conditional ineffective; remove "route53:ChangeResourceRecordSets" from the
unconditional Actions array (the earlier statement that also includes
"route53:ListHostedZonesByName" and "route53:ListResourceRecordSets") so that
only the "Route53ManageRecords" statement controls ChangeResourceRecordSets with
its Condition limiting domains.

In `@resources/sts/5.0/openshift_kube_controller_manager_credentials_policy.json`:
- Around line 28-44: The policy JSON contains a duplicated action string
"elasticloadbalancing:AddTags" in the actions array; remove the redundant entry
so each IAM action appears only once (keep a single
"elasticloadbalancing:AddTags" and delete the other) within the actions list in
openshift_kube_controller_manager_credentials_policy.json to avoid the
copy-paste duplicate.

In `@resources/sts/5.0/osd_scp_policy.json`:
- Around line 35-148: The policy currently uses overly broad wildcards (e.g.,
"iam:*", "kms:*", "sts:*", "cloudwatch:*", "events:*", "logs:*", "route53:*",
"tag:*", "servicequotas:*") with Resource:"*", which violates least-privilege;
update each statement (e.g., Sids: "AllowIAM", "AllowKMS", "AllowSTS",
"AllowCloudWatch", "AllowCloudWatchEvents", "AllowCloudWatchLogs",
"AllowRoute53", "AllowTag", "AllowServiceQuotas", "AllowELB", "AllowSupport") to
enumerate only the specific actions needed and narrow Resource ARNs (or use
condition keys) instead of "*" — for example replace "iam:*" with specific calls
(ListRoles, PassRole, CreateRole, etc.) scoped to required role ARNs, restrict
"kms:*" to the specific kms:Encrypt/Decrypt on the KMS key ARNs, limit "sts:*"
to sts:AssumeRole with specific role ARNs, and similarly scope
CloudWatch/Logs/Events/Route53 actions to the exact log groups, event rules, or
hosted zones required; apply this pattern across each Sid to enforce
least-privilege.

In `@resources/wif/5.0/vanilla.yaml`:
- Around line 563-564: The permission list for the role sre_managed_support
contains a duplicate entry "logging.logEntries.list"; remove the redundant
"logging.logEntries.list" occurrence from the permissions array in the
sre_managed_support role so it only appears once (search for the permissions
block under the sre_managed_support role and delete the duplicate string).

---

Nitpick comments:
In `@resources/sts/5.0/sts_installer_permission_policy.json`:
- Around line 69-70: Remove the two deprecated EC2-Classic actions
"ec2:DescribeVpcClassicLink" and "ec2:DescribeVpcClassicLinkDnsSupport" from the
JSON "Action" array in the policy (they are the entries currently listed as
ec2:DescribeVpcClassicLink and ec2:DescribeVpcClassicLinkDnsSupport); delete
those strings and adjust commas so the JSON array remains valid (no trailing
commas), then validate the policy JSON structure and re-run any linter/formatter
to ensure formatting is unchanged.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: ac65caeb-f276-4c1d-af06-b369e48866a1

📥 Commits

Reviewing files that changed from the base of the PR and between 12ce1b8 and 98daa38.

⛔ Files ignored due to path filters (3)
  • hack/00-osd-managed-cluster-config-integration.yaml.tmpl is excluded by !hack/**
  • hack/00-osd-managed-cluster-config-production.yaml.tmpl is excluded by !hack/**
  • hack/00-osd-managed-cluster-config-stage.yaml.tmpl is excluded by !hack/**
📒 Files selected for processing (35)
  • deploy/osd-cluster-acks/sts/5.0/config.yaml
  • deploy/osd-cluster-acks/sts/5.0/osd-sts-ack_CloudCredential.yaml
  • deploy/osd-cluster-acks/wif/5.0/config.yaml
  • deploy/osd-cluster-acks/wif/5.0/osd-wif-ack_CloudCredential.yaml
  • resources/sts/5.0/openshift_aws_vpce_operator_avo_aws_creds_policy.json
  • resources/sts/5.0/openshift_capa_controller_manager_credentials_policy.json
  • resources/sts/5.0/openshift_cloud_credential_operator_cloud_credential_operator_iam_ro_creds_policy.json
  • resources/sts/5.0/openshift_cloud_ingress_operator_cloud_credentials_policy.json
  • resources/sts/5.0/openshift_cloud_network_config_controller_cloud_credentials_policy.json
  • resources/sts/5.0/openshift_cluster_csi_drivers_ebs_cloud_credentials_policy.json
  • resources/sts/5.0/openshift_control_plane_operator_credentials_policy.json
  • resources/sts/5.0/openshift_image_registry_installer_cloud_credentials_policy.json
  • resources/sts/5.0/openshift_ingress_operator_cloud_credentials_policy.json
  • resources/sts/5.0/openshift_kms_provider_credentials_policy.json
  • resources/sts/5.0/openshift_kube_controller_manager_credentials_policy.json
  • resources/sts/5.0/openshift_machine_api_aws_cloud_credentials_policy.json
  • resources/sts/5.0/operator_iam_role_policy.json
  • resources/sts/5.0/osd_scp_policy.json
  • resources/sts/5.0/shared_vpc_openshift_ingress_operator_cloud_credentials_policy.json
  • resources/sts/5.0/sts_installer_core_permission_boundary_policy.json
  • resources/sts/5.0/sts_installer_permission_policy.json
  • resources/sts/5.0/sts_installer_privatelink_permission_boundary_policy.json
  • resources/sts/5.0/sts_installer_trust_policy.json
  • resources/sts/5.0/sts_installer_vpc_permission_boundary_policy.json
  • resources/sts/5.0/sts_instance_controlplane_permission_policy.json
  • resources/sts/5.0/sts_instance_controlplane_trust_policy.json
  • resources/sts/5.0/sts_instance_worker_permission_policy.json
  • resources/sts/5.0/sts_instance_worker_trust_policy.json
  • resources/sts/5.0/sts_ocm_admin_permission_policy.json
  • resources/sts/5.0/sts_ocm_permission_policy.json
  • resources/sts/5.0/sts_ocm_trust_policy.json
  • resources/sts/5.0/sts_ocm_user_trust_policy.json
  • resources/sts/5.0/sts_support_permission_policy.json
  • resources/sts/5.0/sts_support_trust_policy.json
  • resources/wif/5.0/vanilla.yaml

Comment thread deploy/osd-cluster-acks/sts/5.0/config.yaml
Comment thread deploy/osd-cluster-acks/wif/5.0/config.yaml
Comment on lines +29 to +53
"route53:ChangeResourceRecordSets",
"route53:ListHostedZonesByName",
"route53:ListResourceRecordSets"
],
"Resource": "*"
},
{
"Sid": "Route53ManageRecords",
"Effect": "Allow",
"Action": [
"route53:ChangeResourceRecordSets"
],
"Resource": "*",
"Condition": {
"ForAllValues:StringLike": {
"route53:ChangeResourceRecordSetsNormalizedRecordNames": [
"*.openshiftapps.com",
"*.devshift.org",
"*.hypershift.local",
"*.openshiftusgov.com",
"*.devshiftusgov.com"
]
}
}
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Redundant route53:ChangeResourceRecordSets makes the conditional statement ineffective.

The action route53:ChangeResourceRecordSets is granted twice:

  1. Line 29: Unconditionally with Resource: "*"
  2. Lines 38-52: With domain restrictions via Condition

Since IAM evaluates permissions with OR logic, the unconditional grant in the first statement allows modifying any Route53 record, completely bypassing the domain restrictions in the Route53ManageRecords statement. Either remove the action from line 29 or remove the second statement entirely if unrestricted access is intended.

Proposed fix: Remove duplicate action from first statement
         "ec2:DescribeVpcEndpointServices",
         "route53:ListHostedZonesByVPC",
         "route53:ListTagsForResource",
         "route53:GetHostedZone",
         "route53:CreateHostedZone",
         "route53:DeleteHostedZone",
         "route53:ChangeTagsForResource",
-        "route53:ChangeResourceRecordSets",
         "route53:ListHostedZonesByName",
         "route53:ListResourceRecordSets"
       ],
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@resources/sts/5.0/openshift_aws_vpce_operator_avo_aws_creds_policy.json`
around lines 29 - 53, The policy currently grants
route53:ChangeResourceRecordSets unconditionally and again in the statement with
Sid "Route53ManageRecords" (which includes domain restrictions), making the
conditional ineffective; remove "route53:ChangeResourceRecordSets" from the
unconditional Actions array (the earlier statement that also includes
"route53:ListHostedZonesByName" and "route53:ListResourceRecordSets") so that
only the "Route53ManageRecords" statement controls ChangeResourceRecordSets with
its Condition limiting domains.

Comment thread resources/sts/5.0/openshift_kube_controller_manager_credentials_policy.json Outdated
Comment on lines +35 to +148
{
"Sid": "AllowIAM",
"Effect": "Allow",
"Action": [
"iam:*"
],
"Resource": [
"*"
]
},
{
"Sid": "AllowELB",
"Effect": "Allow",
"Action": [
"elasticloadbalancing:*"
],
"Resource": [
"*"
]
},
{
"Sid": "AllowCloudWatch",
"Effect": "Allow",
"Action": [
"cloudwatch:*"
],
"Resource": [
"*"
]
},
{
"Sid": "AllowCloudWatchEvents",
"Effect": "Allow",
"Action": [
"events:*"
],
"Resource": [
"*"
]
},
{
"Sid": "AllowCloudWatchLogs",
"Effect": "Allow",
"Action": [
"logs:*"
],
"Resource": [
"*"
]
},
{
"Sid": "AllowSupport",
"Effect": "Allow",
"Action": [
"support:*"
],
"Resource": [
"*"
]
},
{
"Sid": "AllowKMS",
"Effect": "Allow",
"Action": [
"kms:*"
],
"Resource": [
"*"
]
},
{
"Sid": "AllowSTS",
"Effect": "Allow",
"Action": [
"sts:*"
],
"Resource": [
"*"
]
},
{
"Sid": "AllowTag",
"Effect": "Allow",
"Action": [
"tag:*"
],
"Resource": [
"*"
]
},
{
"Sid": "AllowRoute53",
"Effect": "Allow",
"Action": [
"route53:*"
],
"Resource": [
"*"
]
},
{
"Sid": "AllowServiceQuotas",
"Effect": "Allow",
"Action": [
"servicequotas:ListServices",
"servicequotas:GetRequestedServiceQuotaChange",
"servicequotas:GetServiceQuota",
"servicequotas:RequestServiceQuotaIncrease",
"servicequotas:ListServiceQuotas"
],
"Resource": [
"*"
]
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | 🏗️ Heavy lift

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== Locate SCP policy files =="
fd -i 'osd_scp_policy.json'

echo
echo "== Find where this SCP is referenced/attached =="
rg -n --iglob '*.yaml' --iglob '*.yml' --iglob '*.json' \
  'osd_scp_policy|ServiceControlPolicy|AWS::Organizations::Policy|organizations:CreatePolicy|organizations:AttachPolicy'

echo
echo "== Inspect deny-based guardrails in policy docs =="
rg -n --iglob '*.json' '"Effect"\s*:\s*"Deny"|\"iam:\*\"|\"sts:\*\"|\"kms:\*\"|\"ec2:\*\"'

Repository: openshift/managed-cluster-config

Length of output: 815


Narrow overly broad wildcard SCP allows in resources/sts/5.0/osd_scp_policy.json

In resources/sts/5.0/osd_scp_policy.json (lines 35-148), the policy grants wide "Effect": "Allow" access using service-wide wildcard actions (e.g., iam:*, kms:*, sts:*, cloudwatch:*, events:*, logs:*, route53:*, tag:*, servicequotas:*) with Resource: "*". Scope to the minimal required actions/resources for sensitive services instead of using * service wildcards.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@resources/sts/5.0/osd_scp_policy.json` around lines 35 - 148, The policy
currently uses overly broad wildcards (e.g., "iam:*", "kms:*", "sts:*",
"cloudwatch:*", "events:*", "logs:*", "route53:*", "tag:*", "servicequotas:*")
with Resource:"*", which violates least-privilege; update each statement (e.g.,
Sids: "AllowIAM", "AllowKMS", "AllowSTS", "AllowCloudWatch",
"AllowCloudWatchEvents", "AllowCloudWatchLogs", "AllowRoute53", "AllowTag",
"AllowServiceQuotas", "AllowELB", "AllowSupport") to enumerate only the specific
actions needed and narrow Resource ARNs (or use condition keys) instead of "*" —
for example replace "iam:*" with specific calls (ListRoles, PassRole,
CreateRole, etc.) scoped to required role ARNs, restrict "kms:*" to the specific
kms:Encrypt/Decrypt on the KMS key ARNs, limit "sts:*" to sts:AssumeRole with
specific role ARNs, and similarly scope CloudWatch/Logs/Events/Route53 actions
to the exact log groups, event rules, or hosted zones required; apply this
pattern across each Sid to enforce least-privilege.

Comment thread resources/wif/5.0/vanilla.yaml Outdated
@ravitri

ravitri commented May 27, 2026

Copy link
Copy Markdown
Member

/hold

@openshift-ci openshift-ci Bot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label May 27, 2026
- Add resourceApplyMode: Sync to STS and WIF config.yaml files
- Add FedRAMP exclusion selector to STS and WIF configs
- Remove duplicate elasticloadbalancing:AddTags in kube-controller-manager policy
- Remove duplicate logging.logEntries.list in WIF vanilla.yaml template
- Regenerate hack templates via make
@openshift-ci

openshift-ci Bot commented May 27, 2026

Copy link
Copy Markdown
Contributor

@rosa-gap-analysis-bot: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/pr-check 30e6b4a link true /test pr-check

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@robpblake

Copy link
Copy Markdown
Contributor

@ravitri Can this PR please be updated to take account of changes merged in

thanks,

Rob

@ravitri

ravitri commented Jul 7, 2026

Copy link
Copy Markdown
Member

@robpblake - Thanks Rob! Sure, will consider those PRs too and rebase

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. ok-to-test Indicates a non-member PR verified by an org member that is safe to test.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants