Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SYS.1.6.A22 #22

Open
sluetze opened this issue Nov 7, 2023 · 3 comments
Open

SYS.1.6.A22 #22

sluetze opened this issue Nov 7, 2023 · 3 comments
Assignees
Labels
not-checkable Requirement can not be checked with Compliance Operator

Comments

@sluetze
Copy link

sluetze commented Nov 7, 2023

No description provided.

@sluetze
Copy link
Author

sluetze commented Jul 17, 2024

In order to have containers available for later investigation if necessary, an image of the state SHOULD be created according to defined rules.

The OpenShift container runtime environment used does not provide a function for creating a memory image of a running container. The running containers can be listed and different parameters can be queried and saved for them. Further data (such as running processes) can be queried via the host. Using the operating system, memory dumps (core dump) or file system data (ephemeral and persistent) can also be backed up. The memory dumps can also be created with third-party operators [CoreDump].

@benruland benruland self-assigned this Sep 6, 2024
@benruland
Copy link

benruland commented Oct 4, 2024

I would argue to assess this control partial. Some functionality is inherently provided by OpenShift (and linux), others is missing.

The notes pretty much sum up the current state. To fully adress the the requirement (automatic creation of "state images" according to rules", we would imho need a 3rd party solution.

@benruland benruland added the not-checkable Requirement can not be checked with Compliance Operator label Oct 4, 2024
@benruland
Copy link

PR: ComplianceAsCode#12470

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
not-checkable Requirement can not be checked with Compliance Operator
Projects
Status: Upstream PR
Development

No branches or pull requests

2 participants