Bug 1400633

Summary: [RFE] Docker/OpenShift/Kubernetes Security benchmark
Product: OpenShift Container Platform Reporter: Javier Ramirez <javier.ramirez>
Component: RFEAssignee: Brenton Leanhardt <bleanhar>
Status: CLOSED DEFERRED QA Contact: Xiaoli Tian <xtian>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 3.5.0CC: aos-bugs, javier.ramirez, jialiu, jokerman, lmeyer, mbarrett, mmccomas, sjr
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-03-12 13:54:36 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Javier Ramirez 2016-12-01 16:44:07 UTC
1. Proposed title of this feature request  
	RFE Docker/OpenShift/Kubernetes Security benchmark
      
	2. Who is the customer behind the request?  
	Account: Produban #1596976
      
	TAM customer: yes  
	SRM customer: yes  
	Strategic: yes  
      
	3. What is the nature and description of the request?  

 We would like to have a security benchmark script such as https://github.com/docker/docker-bench-security, 

This script should checks the best-practices around deploying Docker containers in production, this script should support security checking for the following componentes:

1 - Docker
2- OpenSHift
3- Kubernetes.

In order to self-assess our docker host  against an specific benchmark for OpenShift, we need an official security benchmark script.

	8. Does the customer have any specific timeline dependencies and which release would they like to target (i.e. RHEL5, RHEL6)?  
	  No
	
	11. Would the customer be able to assist in testing this functionality if implemented?  
	Yes

Comment 4 Eric Rich 2018-03-12 13:54:36 UTC
This bug has been identified as a dated (created more than 3 months ago) bug. 
This bug has been triaged (has a trello card linked to it), or reviewed by Engineering/PM and has been put into the product backlog, 
however this bug has not been slated for a currently planned release (3.9, 3.10 or 3.11), which cover our releases for the rest of the calendar year. 

As a result of this bugs age, state on the current roadmap and PM Score (being below 70), this bug is being Closed - Differed, 
as it is currently not part of the products immediate priorities.

Please see: https://docs.google.com/document/d/1zdqF4rB3ea8GmVIZ7qWCVYUaQ7-EexUrQEF0MTwdDkw/edit for more details.