Bug 2066664

Summary: [cluster-storage-operator] - Minimize wildcard/privilege Usage in Cluster and Local Roles
Product: OpenShift Container Platform Reporter: Simon Reber <sreber>
Component: StorageAssignee: Fabio Bertinatto <fbertina>
Storage sub component: Operators QA Contact: Rohit Patil <ropatil>
Status: CLOSED ERRATA Docs Contact:
Severity: low    
Priority: low CC: fbertina, jsafrane, mchellam, mkumatag, ropatil
Version: 4.8   
Target Milestone: ---   
Target Release: 4.13.0   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-05-17 22:46:32 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Simon Reber 2022-03-22 09:58:18 UTC
According http://static.open-scap.org/ssg-guides/ssg-ocp4-guide-cis.html#xccdf_org.ssgproject.content_rule_rbac_wildcard_use the usage of wildcard in ClusterRole and Roles should be prevented as best as possible.

Further, one should refrain from using `cluster-admin` permissions to comply with CIS security requirements.

It's therefore requested to review the below serviceAccount and their associated Roles as they were found not to be compliant with the above and restrict permissions further to the extend possible.

 - system:serviceaccount:openshift-cluster-storage-operator:cluster-storage-operator
 - system:serviceaccount:openshift-cluster-storage-operator:csi-snapshot-controller-operator

Comment 1 Jan Safranek 2022-03-22 14:34:02 UTC
We will check cluster-admin permissions, but they're hard and error prone to remove. This will take some time, even couple of releases.

Comment 2 Jan Safranek 2022-03-22 14:34:49 UTC
*** Bug 2066663 has been marked as a duplicate of this bug. ***

Comment 10 Fabio Bertinatto 2022-12-06 13:06:21 UTC
Moving back to POST in order to get another PR merged.

Comment 11 mkumatag 2022-12-07 13:09:26 UTC
I see already https://github.com/openshift/cluster-storage-operator/pull/270 merged and changes lgtm.

Comment 19 errata-xmlrpc 2023-05-17 22:46:32 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Important: OpenShift Container Platform 4.13.0 security update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2023:1326

Comment 20 Red Hat Bugzilla 2023-09-18 04:34:00 UTC
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 120 days