From 5edb864acfc5bbfd0d34dad93e4bb0ab25be61a5 Mon Sep 17 00:00:00 2001 From: degenaro Date: Fri, 22 Jan 2021 14:45:40 -0500 Subject: [PATCH] Enhancement to handle arboretum fetcher-built OSCO evidence as input Signed-off-by: Lou Degenaro --- .../osco/demo-osco-to-oscal-fetcher.config | 5 + .../osco/input-fetcher/cluster_resource.json | 64 + .../cluster_resource_no_data.json | 39 + .../cluster_resource_no_kind0.json | 39 + .../cluster_resource_no_kind1.json | 39 + .../cluster_resource_no_metadata.json | 39 + .../cluster_resource_no_metadata_name.json | 39 + .../cluster_resource_no_resources.json | 39 + .../cluster_resource_no_results.json | 39 + .../osco/input-fetcher/oscal-metadata.yaml | 55 + .../ssg-ocp4-ds-cis-111.222.333.444-pod.json | 8754 +++++++++++++++++ .../ssg-ocp4-ds-cis-111.222.333.555-pod.json | 8754 +++++++++++++++++ tests/trestle/tasks/osco_to_oscal_test.py | 33 +- trestle/tasks/osco_to_oscal.py | 168 +- 14 files changed, 18040 insertions(+), 66 deletions(-) create mode 100644 tests/data/tasks/osco/demo-osco-to-oscal-fetcher.config create mode 100644 tests/data/tasks/osco/input-fetcher/cluster_resource.json create mode 100644 tests/data/tasks/osco/input-fetcher/cluster_resource_no_data.json create mode 100644 tests/data/tasks/osco/input-fetcher/cluster_resource_no_kind0.json create mode 100644 tests/data/tasks/osco/input-fetcher/cluster_resource_no_kind1.json create mode 100644 tests/data/tasks/osco/input-fetcher/cluster_resource_no_metadata.json create mode 100644 tests/data/tasks/osco/input-fetcher/cluster_resource_no_metadata_name.json create mode 100644 tests/data/tasks/osco/input-fetcher/cluster_resource_no_resources.json create mode 100644 tests/data/tasks/osco/input-fetcher/cluster_resource_no_results.json create mode 100644 tests/data/tasks/osco/input-fetcher/oscal-metadata.yaml create mode 100644 tests/data/tasks/osco/output-fetcher/ssg-ocp4-ds-cis-111.222.333.444-pod.json create mode 100644 tests/data/tasks/osco/output-fetcher/ssg-ocp4-ds-cis-111.222.333.555-pod.json diff --git a/tests/data/tasks/osco/demo-osco-to-oscal-fetcher.config b/tests/data/tasks/osco/demo-osco-to-oscal-fetcher.config new file mode 100644 index 000000000..2d277e8b9 --- /dev/null +++ b/tests/data/tasks/osco/demo-osco-to-oscal-fetcher.config @@ -0,0 +1,5 @@ +[task.osco-to-oscal] + +input-dir = tests/data/tasks/osco/input-fetcher +output-dir = tests/data/tasks/osco/runtime +output-overwrite = true \ No newline at end of file diff --git a/tests/data/tasks/osco/input-fetcher/cluster_resource.json b/tests/data/tasks/osco/input-fetcher/cluster_resource.json new file mode 100644 index 000000000..a4bdb72b5 --- /dev/null +++ b/tests/data/tasks/osco/input-fetcher/cluster_resource.json @@ -0,0 +1,64 @@ +{ + "iks": { + "demo2020": [ + { + "account": "demo2020", + "name": "compliance-dev-dal10", + "region": "us-south", + "resources": [ + { + "apiVersion": "v1", + "data": { + "exit-code": "2", + "results": "\n\n \n OSCAP Scan Result\n \n kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp\n \n chroot:///host\n OpenSCAP\n 1.3.3\n \n \n \n \n /kubernetes-api-resources\n Webhook\n 5m\n \n notselected\n CCE-84209-6\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n pass\n \n \n \n \n \n pass\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n pass\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n notselected\n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n pass\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n pass\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n pass\n \n \n \n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n pass\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n pass\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n pass\n \n \n \n \n \n fail\n \n \n \n \n \n pass\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n pass\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n pass\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n 15.670996\n \n" + }, + "kind": "ConfigMap", + "metadata": { + "annotations": { + "compliance-remediations/processed": "", + "compliance.openshift.io/scan-error-msg": "", + "compliance.openshift.io/scan-result": "NON-COMPLIANT", + "openscap-scan-result/node": "111.222.333.444" + }, + "creationTimestamp": "2020-08-03T02:26:34Z", + "labels": { + "compliance-scan": "ssg-ocp4-ds-cis" + }, + "name": "ssg-ocp4-ds-cis-111.222.333.444-pod", + "namespace": "openshift-compliance", + "resourceVersion": "22693328", + "selfLink": "/api/v1/namespaces/openshift-compliance/configmaps/ssg-ocp4-ds-cis-111.222.333.444-pod", + "uid": "1da3ea81-0a25-4512-ad86-7ac360246b5d" + } + }, + { + "apiVersion": "v1", + "data": { + "exit-code": "2", + "results": "\n\n \n OSCAP Scan Result\n \n kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp\n \n chroot:///host\n OpenSCAP\n 1.3.3\n \n \n \n \n /kubernetes-api-resources\n Webhook\n 5m\n \n notselected\n CCE-84209-6\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n pass\n \n \n \n \n \n pass\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n pass\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n notselected\n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n pass\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n pass\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n fail\n \n \n \n \n \n pass\n \n \n \n \n \n fail\n \n \n \n \n \n notchecked\n No candidate or applicable check found.\n \n \n notchecked\n No candidate or applicable check found.\n \n \n pass\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n pass\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n pass\n \n \n \n \n \n fail\n \n \n \n \n \n pass\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n pass\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n pass\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n \n fail\n \n \n \n \n 15.670996\n \n" + }, + "kind": "ConfigMap", + "metadata": { + "annotations": { + "compliance-remediations/processed": "", + "compliance.openshift.io/scan-error-msg": "", + "compliance.openshift.io/scan-result": "NON-COMPLIANT", + "openscap-scan-result/node": "111.222.333.555" + }, + "creationTimestamp": "2020-08-03T02:26:34Z", + "labels": { + "compliance-scan": "ssg-ocp4-ds-cis" + }, + "name": "ssg-ocp4-ds-cis-111.222.333.555-pod", + "namespace": "openshift-compliance", + "resourceVersion": "22693329", + "selfLink": "/api/v1/namespaces/openshift-compliance/configmaps/ssg-ocp4-ds-cis-111.222.333.555-pod", + "uid": "4e85fc58-06a6-4de1-b738-7bb0788a7d11" + } + } + ] + } + ] + } +} + \ No newline at end of file diff --git a/tests/data/tasks/osco/input-fetcher/cluster_resource_no_data.json b/tests/data/tasks/osco/input-fetcher/cluster_resource_no_data.json new file mode 100644 index 000000000..f82d15c0e --- /dev/null +++ b/tests/data/tasks/osco/input-fetcher/cluster_resource_no_data.json @@ -0,0 +1,39 @@ +{ + "iks": { + "demo2020": [ + { + "account": "demo2020", + "name": "compliance-dev-dal10", + "region": "us-south", + "resources": [ + { + "apiVersion": "v1", + "bogus": { + "exit-code": "2", + "results": "" + }, + "kind": "ConfigMap", + "metadata": { + "annotations": { + "compliance-remediations/processed": "", + "compliance.openshift.io/scan-error-msg": "", + "compliance.openshift.io/scan-result": "NON-COMPLIANT", + "openscap-scan-result/node": "111.222.333.444" + }, + "creationTimestamp": "2020-08-03T02:26:34Z", + "labels": { + "compliance-scan": "ssg-ocp4-ds-cis" + }, + "name": "ssg-ocp4-ds-cis-111.222.333.444-pod", + "namespace": "openshift-compliance", + "resourceVersion": "22693328", + "selfLink": "/api/v1/namespaces/openshift-compliance/configmaps/ssg-ocp4-ds-cis-111.222.333.444-pod", + "uid": "1da3ea81-0a25-4512-ad86-7ac360246b5d" + } + } + ] + } + ] + } +} + \ No newline at end of file diff --git a/tests/data/tasks/osco/input-fetcher/cluster_resource_no_kind0.json b/tests/data/tasks/osco/input-fetcher/cluster_resource_no_kind0.json new file mode 100644 index 000000000..557a74a90 --- /dev/null +++ b/tests/data/tasks/osco/input-fetcher/cluster_resource_no_kind0.json @@ -0,0 +1,39 @@ +{ + "iks": { + "demo2020": [ + { + "account": "demo2020", + "name": "compliance-dev-dal10", + "region": "us-south", + "resources": [ + { + "apiVersion": "v1", + "data": { + "exit-code": "2", + "results": "" + }, + "bogus": "ConfigMap", + "metadata": { + "annotations": { + "compliance-remediations/processed": "", + "compliance.openshift.io/scan-error-msg": "", + "compliance.openshift.io/scan-result": "NON-COMPLIANT", + "openscap-scan-result/node": "111.222.333.444" + }, + "creationTimestamp": "2020-08-03T02:26:34Z", + "labels": { + "compliance-scan": "ssg-ocp4-ds-cis" + }, + "name": "ssg-ocp4-ds-cis-111.222.333.444-pod", + "namespace": "openshift-compliance", + "resourceVersion": "22693328", + "selfLink": "/api/v1/namespaces/openshift-compliance/configmaps/ssg-ocp4-ds-cis-111.222.333.444-pod", + "uid": "1da3ea81-0a25-4512-ad86-7ac360246b5d" + } + } + ] + } + ] + } +} + \ No newline at end of file diff --git a/tests/data/tasks/osco/input-fetcher/cluster_resource_no_kind1.json b/tests/data/tasks/osco/input-fetcher/cluster_resource_no_kind1.json new file mode 100644 index 000000000..0953540a4 --- /dev/null +++ b/tests/data/tasks/osco/input-fetcher/cluster_resource_no_kind1.json @@ -0,0 +1,39 @@ +{ + "iks": { + "demo2020": [ + { + "account": "demo2020", + "name": "compliance-dev-dal10", + "region": "us-south", + "resources": [ + { + "apiVersion": "v1", + "data": { + "exit-code": "2", + "results": "" + }, + "kind": "bogus", + "metadata": { + "annotations": { + "compliance-remediations/processed": "", + "compliance.openshift.io/scan-error-msg": "", + "compliance.openshift.io/scan-result": "NON-COMPLIANT", + "openscap-scan-result/node": "111.222.333.444" + }, + "creationTimestamp": "2020-08-03T02:26:34Z", + "labels": { + "compliance-scan": "ssg-ocp4-ds-cis" + }, + "name": "ssg-ocp4-ds-cis-111.222.333.444-pod", + "namespace": "openshift-compliance", + "resourceVersion": "22693328", + "selfLink": "/api/v1/namespaces/openshift-compliance/configmaps/ssg-ocp4-ds-cis-111.222.333.444-pod", + "uid": "1da3ea81-0a25-4512-ad86-7ac360246b5d" + } + } + ] + } + ] + } +} + \ No newline at end of file diff --git a/tests/data/tasks/osco/input-fetcher/cluster_resource_no_metadata.json b/tests/data/tasks/osco/input-fetcher/cluster_resource_no_metadata.json new file mode 100644 index 000000000..e3cc8c9c2 --- /dev/null +++ b/tests/data/tasks/osco/input-fetcher/cluster_resource_no_metadata.json @@ -0,0 +1,39 @@ +{ + "iks": { + "demo2020": [ + { + "account": "demo2020", + "name": "compliance-dev-dal10", + "region": "us-south", + "resources": [ + { + "apiVersion": "v1", + "data": { + "exit-code": "2", + "results": "" + }, + "kind": "ConfigMap", + "bogus": { + "annotations": { + "compliance-remediations/processed": "", + "compliance.openshift.io/scan-error-msg": "", + "compliance.openshift.io/scan-result": "NON-COMPLIANT", + "openscap-scan-result/node": "111.222.333.444" + }, + "creationTimestamp": "2020-08-03T02:26:34Z", + "labels": { + "compliance-scan": "ssg-ocp4-ds-cis" + }, + "name": "ssg-ocp4-ds-cis-111.222.333.444-pod", + "namespace": "openshift-compliance", + "resourceVersion": "22693328", + "selfLink": "/api/v1/namespaces/openshift-compliance/configmaps/ssg-ocp4-ds-cis-111.222.333.444-pod", + "uid": "1da3ea81-0a25-4512-ad86-7ac360246b5d" + } + } + ] + } + ] + } +} + \ No newline at end of file diff --git a/tests/data/tasks/osco/input-fetcher/cluster_resource_no_metadata_name.json b/tests/data/tasks/osco/input-fetcher/cluster_resource_no_metadata_name.json new file mode 100644 index 000000000..e6e1c44f9 --- /dev/null +++ b/tests/data/tasks/osco/input-fetcher/cluster_resource_no_metadata_name.json @@ -0,0 +1,39 @@ +{ + "iks": { + "demo2020": [ + { + "account": "demo2020", + "name": "compliance-dev-dal10", + "region": "us-south", + "resources": [ + { + "apiVersion": "v1", + "data": { + "exit-code": "2", + "results": "" + }, + "kind": "ConfigMap", + "metadata": { + "annotations": { + "compliance-remediations/processed": "", + "compliance.openshift.io/scan-error-msg": "", + "compliance.openshift.io/scan-result": "NON-COMPLIANT", + "openscap-scan-result/node": "111.222.333.444" + }, + "creationTimestamp": "2020-08-03T02:26:34Z", + "labels": { + "compliance-scan": "ssg-ocp4-ds-cis" + }, + "bogus": "ssg-ocp4-ds-cis-111.222.333.444-pod", + "namespace": "openshift-compliance", + "resourceVersion": "22693328", + "selfLink": "/api/v1/namespaces/openshift-compliance/configmaps/ssg-ocp4-ds-cis-111.222.333.444-pod", + "uid": "1da3ea81-0a25-4512-ad86-7ac360246b5d" + } + } + ] + } + ] + } +} + \ No newline at end of file diff --git a/tests/data/tasks/osco/input-fetcher/cluster_resource_no_resources.json b/tests/data/tasks/osco/input-fetcher/cluster_resource_no_resources.json new file mode 100644 index 000000000..5ffa247c6 --- /dev/null +++ b/tests/data/tasks/osco/input-fetcher/cluster_resource_no_resources.json @@ -0,0 +1,39 @@ +{ + "iks": { + "demo2020": [ + { + "account": "demo2020", + "name": "compliance-dev-dal10", + "region": "us-south", + "bogus": [ + { + "apiVersion": "v1", + "data": { + "exit-code": "2", + "results": "" + }, + "kind": "ConfigMap", + "metadata": { + "annotations": { + "compliance-remediations/processed": "", + "compliance.openshift.io/scan-error-msg": "", + "compliance.openshift.io/scan-result": "NON-COMPLIANT", + "openscap-scan-result/node": "111.222.333.444" + }, + "creationTimestamp": "2020-08-03T02:26:34Z", + "labels": { + "compliance-scan": "ssg-ocp4-ds-cis" + }, + "name": "ssg-ocp4-ds-cis-111.222.333.444-pod", + "namespace": "openshift-compliance", + "resourceVersion": "22693328", + "selfLink": "/api/v1/namespaces/openshift-compliance/configmaps/ssg-ocp4-ds-cis-111.222.333.444-pod", + "uid": "1da3ea81-0a25-4512-ad86-7ac360246b5d" + } + } + ] + } + ] + } +} + \ No newline at end of file diff --git a/tests/data/tasks/osco/input-fetcher/cluster_resource_no_results.json b/tests/data/tasks/osco/input-fetcher/cluster_resource_no_results.json new file mode 100644 index 000000000..19f68e21a --- /dev/null +++ b/tests/data/tasks/osco/input-fetcher/cluster_resource_no_results.json @@ -0,0 +1,39 @@ +{ + "iks": { + "demo2020": [ + { + "account": "demo2020", + "name": "compliance-dev-dal10", + "region": "us-south", + "resources": [ + { + "apiVersion": "v1", + "data": { + "exit-code": "2", + "bogus": "" + }, + "kind": "ConfigMap", + "metadata": { + "annotations": { + "compliance-remediations/processed": "", + "compliance.openshift.io/scan-error-msg": "", + "compliance.openshift.io/scan-result": "NON-COMPLIANT", + "openscap-scan-result/node": "111.222.333.444" + }, + "creationTimestamp": "2020-08-03T02:26:34Z", + "labels": { + "compliance-scan": "ssg-ocp4-ds-cis" + }, + "name": "ssg-ocp4-ds-cis-111.222.333.444-pod", + "namespace": "openshift-compliance", + "resourceVersion": "22693328", + "selfLink": "/api/v1/namespaces/openshift-compliance/configmaps/ssg-ocp4-ds-cis-111.222.333.444-pod", + "uid": "1da3ea81-0a25-4512-ad86-7ac360246b5d" + } + } + ] + } + ] + } +} + \ No newline at end of file diff --git a/tests/data/tasks/osco/input-fetcher/oscal-metadata.yaml b/tests/data/tasks/osco/input-fetcher/oscal-metadata.yaml new file mode 100644 index 000000000..6c90efcfa --- /dev/null +++ b/tests/data/tasks/osco/input-fetcher/oscal-metadata.yaml @@ -0,0 +1,55 @@ + +ssg-ocp4-ds-cis-111.222.333.444-pod: + locker: https://github.mycorp.com/degenaro/evidence-locker + namespace: xccdf + subject-references: + component: + uuid-ref: 56666738-0f9a-4e38-9aac-c0fad00a5821 + type: component + title: Red Hat OpenShift Kubernetes + inventory-item: + uuid-ref: 46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e + type: inventory-item + title: Pod + properties: + target: kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp + cluster-name: ROKS-OpenSCAP-1 + cluster-type: openshift + cluster-region: us-south + +ssg-ocp4-ds-cis-111.222.333.555-pod: + locker: https://github.mycorp.com/degenaro/evidence-locker + namespace: xccdf + subject-references: + component: + uuid-ref: 3e42fa6b-a819-4f58-b073-a04a0b3c828d + type: component + title: Red Hat OpenShift Kubernetes + inventory-item: + uuid-ref: 285d87c2-aab0-4935-b28b-c4dab131cf88 + type: inventory-item + title: Pod + properties: + target: kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp + cluster-name: ROKS-OpenSCAP-1 + cluster-type: openshift + cluster-region: us-south + +ssg-rhel7-ds-cis-111.222.333.444-pod: + locker: https://github.mycorp.com/degenaro/evidence-locker + namespace: xccdf + subject-references: + component: + uuid-ref: 89cfe7a7-ce6b-4699-aa7b-2f5739c72001 + type: component + title: RedHat Enterprise Linux 7.8 + inventory-item: + uuid-ref: 46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e + type: inventory-item + title: VM + properties: + target: kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp + cluster-name: ROKS-OpenSCAP-1 + cluster-type: openshift + cluster-region: us-south + \ No newline at end of file diff --git a/tests/data/tasks/osco/output-fetcher/ssg-ocp4-ds-cis-111.222.333.444-pod.json b/tests/data/tasks/osco/output-fetcher/ssg-ocp4-ds-cis-111.222.333.444-pod.json new file mode 100644 index 000000000..0b1d58067 --- /dev/null +++ b/tests/data/tasks/osco/output-fetcher/ssg-ocp4-ds-cis-111.222.333.444-pod.json @@ -0,0 +1,8754 @@ +{ + "observations": [ + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_ocp_idp_no_htpasswd", + "description": "xccdf_org.ssgproject.content_rule_ocp_idp_no_htpasswd", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_ocp_idp_no_htpasswd" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notselected" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_accounts_restrict_service_account_tokens", + "description": "xccdf_org.ssgproject.content_rule_accounts_restrict_service_account_tokens", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_accounts_restrict_service_account_tokens" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_accounts_unique_service_account", + "description": "xccdf_org.ssgproject.content_rule_accounts_unique_service_account", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_accounts_unique_service_account" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_configure_network_policies", + "description": "xccdf_org.ssgproject.content_rule_configure_network_policies", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_configure_network_policies" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_configure_network_policies_namespaces", + "description": "xccdf_org.ssgproject.content_rule_configure_network_policies_namespaces", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_configure_network_policies_namespaces" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scheduler_profiling_argument", + "description": "xccdf_org.ssgproject.content_rule_scheduler_profiling_argument", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scheduler_profiling_argument" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_secrets_no_environment_variables", + "description": "xccdf_org.ssgproject.content_rule_secrets_no_environment_variables", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_secrets_no_environment_variables" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_worker_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_worker_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_worker_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_worker_service", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_worker_service", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_worker_service" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_proxy_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_proxy_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_proxy_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_worker_ca", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_worker_ca", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_worker_ca" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_worker_service", + "description": "xccdf_org.ssgproject.content_rule_file_owner_worker_service", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_worker_service" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_worker_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_worker_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_worker_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_kubelet_conf", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_kubelet_conf", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_kubelet_conf" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_worker_service", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_worker_service", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_worker_service" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_proxy_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_proxy_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_proxy_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_worker_ca", + "description": "xccdf_org.ssgproject.content_rule_file_owner_worker_ca", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_worker_ca" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_proxy_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_owner_proxy_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_proxy_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_worker_ca", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_worker_ca", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_worker_ca" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_worker_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_owner_worker_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_worker_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_kubelet_conf", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_kubelet_conf", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_kubelet_conf" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_kubelet_conf", + "description": "xccdf_org.ssgproject.content_rule_file_owner_kubelet_conf", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_kubelet_conf" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_controller_use_service_account", + "description": "xccdf_org.ssgproject.content_rule_controller_use_service_account", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_controller_use_service_account" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_controller_bind_address", + "description": "xccdf_org.ssgproject.content_rule_controller_bind_address", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_controller_bind_address" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_controller_service_account_private_key", + "description": "xccdf_org.ssgproject.content_rule_controller_service_account_private_key", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_controller_service_account_private_key" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_controller_service_account_ca", + "description": "xccdf_org.ssgproject.content_rule_controller_service_account_ca", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_controller_service_account_ca" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_controller_rotate_kubelet_server_certs", + "description": "xccdf_org.ssgproject.content_rule_controller_rotate_kubelet_server_certs", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_controller_rotate_kubelet_server_certs" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scc_limit_process_id_namespace", + "description": "xccdf_org.ssgproject.content_rule_scc_limit_process_id_namespace", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scc_limit_process_id_namespace" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scc_limit_root_containers", + "description": "xccdf_org.ssgproject.content_rule_scc_limit_root_containers", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scc_limit_root_containers" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scc_limit_privilege_escalation", + "description": "xccdf_org.ssgproject.content_rule_scc_limit_privilege_escalation", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scc_limit_privilege_escalation" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scc_limit_ipc_namespace", + "description": "xccdf_org.ssgproject.content_rule_scc_limit_ipc_namespace", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scc_limit_ipc_namespace" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scc_limit_container_allowed_capabilities", + "description": "xccdf_org.ssgproject.content_rule_scc_limit_container_allowed_capabilities", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scc_limit_container_allowed_capabilities" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scc_limit_net_raw_capability", + "description": "xccdf_org.ssgproject.content_rule_scc_limit_net_raw_capability", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scc_limit_net_raw_capability" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scc_limit_network_namespace", + "description": "xccdf_org.ssgproject.content_rule_scc_limit_network_namespace", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scc_limit_network_namespace" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scc_drop_container_capabilities", + "description": "xccdf_org.ssgproject.content_rule_scc_drop_container_capabilities", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scc_drop_container_capabilities" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scc_limit_privileged_containers", + "description": "xccdf_org.ssgproject.content_rule_scc_limit_privileged_containers", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scc_limit_privileged_containers" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_general_configure_imagepolicywebhook", + "description": "xccdf_org.ssgproject.content_rule_general_configure_imagepolicywebhook", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_general_configure_imagepolicywebhook" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_rbac_limit_secrets_access", + "description": "xccdf_org.ssgproject.content_rule_rbac_limit_secrets_access", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_rbac_limit_secrets_access" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_rbac_wildcard_use", + "description": "xccdf_org.ssgproject.content_rule_rbac_wildcard_use", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_rbac_wildcard_use" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_rbac_pod_creation_access", + "description": "xccdf_org.ssgproject.content_rule_rbac_pod_creation_access", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_rbac_pod_creation_access" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_rbac_limit_cluster_admin", + "description": "xccdf_org.ssgproject.content_rule_rbac_limit_cluster_admin", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_rbac_limit_cluster_admin" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_configure_client_ca", + "description": "xccdf_org.ssgproject.content_rule_kubelet_configure_client_ca", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_configure_client_ca" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_disable_readonly_port", + "description": "xccdf_org.ssgproject.content_rule_kubelet_disable_readonly_port", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_disable_readonly_port" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_anonymous_auth", + "description": "xccdf_org.ssgproject.content_rule_kubelet_anonymous_auth", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_anonymous_auth" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_enable_server_cert_rotation", + "description": "xccdf_org.ssgproject.content_rule_kubelet_enable_server_cert_rotation", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_enable_server_cert_rotation" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_configure_tls_key", + "description": "xccdf_org.ssgproject.content_rule_kubelet_configure_tls_key", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_configure_tls_key" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_enable_streaming_connections", + "description": "xccdf_org.ssgproject.content_rule_kubelet_enable_streaming_connections", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_enable_streaming_connections" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_authorization_mode", + "description": "xccdf_org.ssgproject.content_rule_kubelet_authorization_mode", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_authorization_mode" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_configure_event_creation", + "description": "xccdf_org.ssgproject.content_rule_kubelet_configure_event_creation", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_configure_event_creation" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_enable_client_cert_rotation", + "description": "xccdf_org.ssgproject.content_rule_kubelet_enable_client_cert_rotation", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_enable_client_cert_rotation" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_configure_tls_cert", + "description": "xccdf_org.ssgproject.content_rule_kubelet_configure_tls_cert", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_configure_tls_cert" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_ocp_allowed_registries_for_import", + "description": "xccdf_org.ssgproject.content_rule_ocp_allowed_registries_for_import", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_ocp_allowed_registries_for_import" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notselected" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_etcd_client_cert_auth", + "description": "xccdf_org.ssgproject.content_rule_etcd_client_cert_auth", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_etcd_client_cert_auth" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_etcd_peer_key_file", + "description": "xccdf_org.ssgproject.content_rule_etcd_peer_key_file", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_etcd_peer_key_file" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_etcd_peer_cert_file", + "description": "xccdf_org.ssgproject.content_rule_etcd_peer_cert_file", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_etcd_peer_cert_file" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_etcd_unique_ca", + "description": "xccdf_org.ssgproject.content_rule_etcd_unique_ca", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_etcd_unique_ca" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_etcd_peer_auto_tls", + "description": "xccdf_org.ssgproject.content_rule_etcd_peer_auto_tls", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_etcd_peer_auto_tls" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_etcd_peer_client_cert_auth", + "description": "xccdf_org.ssgproject.content_rule_etcd_peer_client_cert_auth", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_etcd_peer_client_cert_auth" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_etcd_cert_file", + "description": "xccdf_org.ssgproject.content_rule_etcd_cert_file", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_etcd_cert_file" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_etcd_auto_tls", + "description": "xccdf_org.ssgproject.content_rule_etcd_auto_tls", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_etcd_auto_tls" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_etcd_key_file", + "description": "xccdf_org.ssgproject.content_rule_etcd_key_file", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_etcd_key_file" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_cni_conf", + "description": "xccdf_org.ssgproject.content_rule_file_owner_cni_conf", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_cni_conf" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_etcd_member", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_etcd_member", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_etcd_member" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_etcd_member", + "description": "xccdf_org.ssgproject.content_rule_file_owner_etcd_member", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_etcd_member" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_kube_scheduler", + "description": "xccdf_org.ssgproject.content_rule_file_owner_kube_scheduler", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_kube_scheduler" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_kube_apiserver", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_kube_apiserver", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_kube_apiserver" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_kube_apiserver", + "description": "xccdf_org.ssgproject.content_rule_file_owner_kube_apiserver", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_kube_apiserver" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_openvswitch", + "description": "xccdf_org.ssgproject.content_rule_file_owner_openvswitch", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_openvswitch" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_kube_controller_manager", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_kube_controller_manager", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_kube_controller_manager" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_controller_manager_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_controller_manager_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_controller_manager_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_scheduler_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_scheduler_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_scheduler_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_openvswitch", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_openvswitch", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_openvswitch" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_var_lib_etcd", + "description": "xccdf_org.ssgproject.content_rule_file_owner_var_lib_etcd", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_var_lib_etcd" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_var_lib_etcd", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_var_lib_etcd", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_var_lib_etcd" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_controller_manager_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_owner_controller_manager_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_controller_manager_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_scheduler_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_scheduler_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_scheduler_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_kube_controller_manager", + "description": "xccdf_org.ssgproject.content_rule_file_owner_kube_controller_manager", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_kube_controller_manager" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_kube_scheduler", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_kube_scheduler", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_kube_scheduler" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_owner_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_kube_controller_manager", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_kube_controller_manager", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_kube_controller_manager" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_kube_apiserver", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_kube_apiserver", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_kube_apiserver" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_cni_conf", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_cni_conf", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_cni_conf" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_kube_scheduler", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_kube_scheduler", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_kube_scheduler" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_controller_manager_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_controller_manager_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_controller_manager_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_cni_conf", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_cni_conf", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_cni_conf" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_openvswitch", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_openvswitch", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_openvswitch" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_etcd_member", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_etcd_member", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_etcd_member" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_scheduler_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_owner_scheduler_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_scheduler_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_insecure_port", + "description": "xccdf_org.ssgproject.content_rule_api_server_insecure_port", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_insecure_port" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_tls_private_key", + "description": "xccdf_org.ssgproject.content_rule_api_server_tls_private_key", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_tls_private_key" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_tls_cert", + "description": "xccdf_org.ssgproject.content_rule_api_server_tls_cert", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_tls_cert" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_client_ca", + "description": "xccdf_org.ssgproject.content_rule_api_server_client_ca", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_client_ca" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_audit_log_path", + "description": "xccdf_org.ssgproject.content_rule_api_server_audit_log_path", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_audit_log_path" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_tls_cipher_suites", + "description": "xccdf_org.ssgproject.content_rule_api_server_tls_cipher_suites", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_tls_cipher_suites" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_EventRateLimit", + "description": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_EventRateLimit", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_EventRateLimit" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_authorization_mode", + "description": "xccdf_org.ssgproject.content_rule_api_server_authorization_mode", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_authorization_mode" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_audit_log_maxage", + "description": "xccdf_org.ssgproject.content_rule_api_server_audit_log_maxage", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_audit_log_maxage" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_profiling", + "description": "xccdf_org.ssgproject.content_rule_api_server_profiling", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_profiling" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_ServiceAccount", + "description": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_ServiceAccount", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_ServiceAccount" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_AlwaysAdmit", + "description": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_AlwaysAdmit", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_AlwaysAdmit" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_encryption_provider_cipher", + "description": "xccdf_org.ssgproject.content_rule_api_server_encryption_provider_cipher", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_encryption_provider_cipher" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_token_auth", + "description": "xccdf_org.ssgproject.content_rule_api_server_token_auth", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_token_auth" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_anonymous_auth", + "description": "xccdf_org.ssgproject.content_rule_api_server_anonymous_auth", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_anonymous_auth" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_etcd_ca", + "description": "xccdf_org.ssgproject.content_rule_api_server_etcd_ca", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_etcd_ca" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_encryption_provider_config", + "description": "xccdf_org.ssgproject.content_rule_api_server_encryption_provider_config", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_encryption_provider_config" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_request_timeout", + "description": "xccdf_org.ssgproject.content_rule_api_server_request_timeout", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_request_timeout" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_audit_log_maxsize", + "description": "xccdf_org.ssgproject.content_rule_api_server_audit_log_maxsize", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_audit_log_maxsize" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_NodeRestriction", + "description": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_NodeRestriction", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_NodeRestriction" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_SecurityContextDeny", + "description": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_SecurityContextDeny", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_SecurityContextDeny" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_PodSecurityPolicy", + "description": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_PodSecurityPolicy", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_PodSecurityPolicy" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_basic_auth", + "description": "xccdf_org.ssgproject.content_rule_api_server_basic_auth", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_basic_auth" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_kubelet_client_key", + "description": "xccdf_org.ssgproject.content_rule_api_server_kubelet_client_key", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_kubelet_client_key" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_service_account_public_key", + "description": "xccdf_org.ssgproject.content_rule_api_server_service_account_public_key", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_service_account_public_key" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_etcd_key", + "description": "xccdf_org.ssgproject.content_rule_api_server_etcd_key", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_etcd_key" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_AlwaysPullImages", + "description": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_AlwaysPullImages", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_AlwaysPullImages" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_kubelet_client_cert", + "description": "xccdf_org.ssgproject.content_rule_api_server_kubelet_client_cert", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_kubelet_client_cert" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_audit_log_maxbackup", + "description": "xccdf_org.ssgproject.content_rule_api_server_audit_log_maxbackup", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_audit_log_maxbackup" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_kubelet_https", + "description": "xccdf_org.ssgproject.content_rule_api_server_kubelet_https", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_kubelet_https" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_etcd_cert", + "description": "xccdf_org.ssgproject.content_rule_api_server_etcd_cert", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_etcd_cert" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_insecure_bind_address", + "description": "xccdf_org.ssgproject.content_rule_api_server_insecure_bind_address", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_insecure_bind_address" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_kubelet_certificate_authority", + "description": "xccdf_org.ssgproject.content_rule_api_server_kubelet_certificate_authority", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_kubelet_certificate_authority" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_NamespaceLifecycle", + "description": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_NamespaceLifecycle", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_NamespaceLifecycle" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_secure_port", + "description": "xccdf_org.ssgproject.content_rule_api_server_secure_port", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "46aADFAC-A1fd-4Cf0-a6aA-d1AfAb3e0d3e", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_secure_port" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:26+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-0000026b.iks.mycorp" + } + ] + } + ] + } + ] +} \ No newline at end of file diff --git a/tests/data/tasks/osco/output-fetcher/ssg-ocp4-ds-cis-111.222.333.555-pod.json b/tests/data/tasks/osco/output-fetcher/ssg-ocp4-ds-cis-111.222.333.555-pod.json new file mode 100644 index 000000000..5e774056c --- /dev/null +++ b/tests/data/tasks/osco/output-fetcher/ssg-ocp4-ds-cis-111.222.333.555-pod.json @@ -0,0 +1,8754 @@ +{ + "observations": [ + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_ocp_idp_no_htpasswd", + "description": "xccdf_org.ssgproject.content_rule_ocp_idp_no_htpasswd", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_ocp_idp_no_htpasswd" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notselected" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_accounts_restrict_service_account_tokens", + "description": "xccdf_org.ssgproject.content_rule_accounts_restrict_service_account_tokens", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_accounts_restrict_service_account_tokens" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_accounts_unique_service_account", + "description": "xccdf_org.ssgproject.content_rule_accounts_unique_service_account", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_accounts_unique_service_account" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_configure_network_policies", + "description": "xccdf_org.ssgproject.content_rule_configure_network_policies", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_configure_network_policies" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_configure_network_policies_namespaces", + "description": "xccdf_org.ssgproject.content_rule_configure_network_policies_namespaces", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_configure_network_policies_namespaces" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scheduler_profiling_argument", + "description": "xccdf_org.ssgproject.content_rule_scheduler_profiling_argument", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scheduler_profiling_argument" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_secrets_no_environment_variables", + "description": "xccdf_org.ssgproject.content_rule_secrets_no_environment_variables", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_secrets_no_environment_variables" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_worker_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_worker_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_worker_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_worker_service", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_worker_service", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_worker_service" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_proxy_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_proxy_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_proxy_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_worker_ca", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_worker_ca", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_worker_ca" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_worker_service", + "description": "xccdf_org.ssgproject.content_rule_file_owner_worker_service", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_worker_service" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_worker_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_worker_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_worker_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_kubelet_conf", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_kubelet_conf", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_kubelet_conf" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_worker_service", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_worker_service", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_worker_service" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_proxy_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_proxy_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_proxy_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_worker_ca", + "description": "xccdf_org.ssgproject.content_rule_file_owner_worker_ca", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_worker_ca" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_proxy_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_owner_proxy_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_proxy_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_worker_ca", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_worker_ca", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_worker_ca" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_worker_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_owner_worker_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_worker_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_kubelet_conf", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_kubelet_conf", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_kubelet_conf" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_kubelet_conf", + "description": "xccdf_org.ssgproject.content_rule_file_owner_kubelet_conf", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_kubelet_conf" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_controller_use_service_account", + "description": "xccdf_org.ssgproject.content_rule_controller_use_service_account", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_controller_use_service_account" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_controller_bind_address", + "description": "xccdf_org.ssgproject.content_rule_controller_bind_address", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_controller_bind_address" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_controller_service_account_private_key", + "description": "xccdf_org.ssgproject.content_rule_controller_service_account_private_key", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_controller_service_account_private_key" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_controller_service_account_ca", + "description": "xccdf_org.ssgproject.content_rule_controller_service_account_ca", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_controller_service_account_ca" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_controller_rotate_kubelet_server_certs", + "description": "xccdf_org.ssgproject.content_rule_controller_rotate_kubelet_server_certs", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_controller_rotate_kubelet_server_certs" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scc_limit_process_id_namespace", + "description": "xccdf_org.ssgproject.content_rule_scc_limit_process_id_namespace", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scc_limit_process_id_namespace" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scc_limit_root_containers", + "description": "xccdf_org.ssgproject.content_rule_scc_limit_root_containers", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scc_limit_root_containers" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scc_limit_privilege_escalation", + "description": "xccdf_org.ssgproject.content_rule_scc_limit_privilege_escalation", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scc_limit_privilege_escalation" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scc_limit_ipc_namespace", + "description": "xccdf_org.ssgproject.content_rule_scc_limit_ipc_namespace", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scc_limit_ipc_namespace" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scc_limit_container_allowed_capabilities", + "description": "xccdf_org.ssgproject.content_rule_scc_limit_container_allowed_capabilities", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scc_limit_container_allowed_capabilities" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scc_limit_net_raw_capability", + "description": "xccdf_org.ssgproject.content_rule_scc_limit_net_raw_capability", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scc_limit_net_raw_capability" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scc_limit_network_namespace", + "description": "xccdf_org.ssgproject.content_rule_scc_limit_network_namespace", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scc_limit_network_namespace" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scc_drop_container_capabilities", + "description": "xccdf_org.ssgproject.content_rule_scc_drop_container_capabilities", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scc_drop_container_capabilities" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_scc_limit_privileged_containers", + "description": "xccdf_org.ssgproject.content_rule_scc_limit_privileged_containers", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_scc_limit_privileged_containers" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_general_configure_imagepolicywebhook", + "description": "xccdf_org.ssgproject.content_rule_general_configure_imagepolicywebhook", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_general_configure_imagepolicywebhook" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_rbac_limit_secrets_access", + "description": "xccdf_org.ssgproject.content_rule_rbac_limit_secrets_access", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_rbac_limit_secrets_access" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_rbac_wildcard_use", + "description": "xccdf_org.ssgproject.content_rule_rbac_wildcard_use", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_rbac_wildcard_use" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_rbac_pod_creation_access", + "description": "xccdf_org.ssgproject.content_rule_rbac_pod_creation_access", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_rbac_pod_creation_access" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_rbac_limit_cluster_admin", + "description": "xccdf_org.ssgproject.content_rule_rbac_limit_cluster_admin", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_rbac_limit_cluster_admin" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_configure_client_ca", + "description": "xccdf_org.ssgproject.content_rule_kubelet_configure_client_ca", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_configure_client_ca" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_disable_readonly_port", + "description": "xccdf_org.ssgproject.content_rule_kubelet_disable_readonly_port", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_disable_readonly_port" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_anonymous_auth", + "description": "xccdf_org.ssgproject.content_rule_kubelet_anonymous_auth", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_anonymous_auth" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_enable_server_cert_rotation", + "description": "xccdf_org.ssgproject.content_rule_kubelet_enable_server_cert_rotation", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_enable_server_cert_rotation" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_configure_tls_key", + "description": "xccdf_org.ssgproject.content_rule_kubelet_configure_tls_key", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_configure_tls_key" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_enable_streaming_connections", + "description": "xccdf_org.ssgproject.content_rule_kubelet_enable_streaming_connections", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_enable_streaming_connections" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_authorization_mode", + "description": "xccdf_org.ssgproject.content_rule_kubelet_authorization_mode", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_authorization_mode" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_configure_event_creation", + "description": "xccdf_org.ssgproject.content_rule_kubelet_configure_event_creation", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_configure_event_creation" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_enable_client_cert_rotation", + "description": "xccdf_org.ssgproject.content_rule_kubelet_enable_client_cert_rotation", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_enable_client_cert_rotation" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_kubelet_configure_tls_cert", + "description": "xccdf_org.ssgproject.content_rule_kubelet_configure_tls_cert", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_kubelet_configure_tls_cert" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_ocp_allowed_registries_for_import", + "description": "xccdf_org.ssgproject.content_rule_ocp_allowed_registries_for_import", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_ocp_allowed_registries_for_import" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notselected" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_etcd_client_cert_auth", + "description": "xccdf_org.ssgproject.content_rule_etcd_client_cert_auth", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_etcd_client_cert_auth" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_etcd_peer_key_file", + "description": "xccdf_org.ssgproject.content_rule_etcd_peer_key_file", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_etcd_peer_key_file" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_etcd_peer_cert_file", + "description": "xccdf_org.ssgproject.content_rule_etcd_peer_cert_file", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_etcd_peer_cert_file" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_etcd_unique_ca", + "description": "xccdf_org.ssgproject.content_rule_etcd_unique_ca", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_etcd_unique_ca" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_etcd_peer_auto_tls", + "description": "xccdf_org.ssgproject.content_rule_etcd_peer_auto_tls", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_etcd_peer_auto_tls" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_etcd_peer_client_cert_auth", + "description": "xccdf_org.ssgproject.content_rule_etcd_peer_client_cert_auth", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_etcd_peer_client_cert_auth" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_etcd_cert_file", + "description": "xccdf_org.ssgproject.content_rule_etcd_cert_file", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_etcd_cert_file" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_etcd_auto_tls", + "description": "xccdf_org.ssgproject.content_rule_etcd_auto_tls", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_etcd_auto_tls" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_etcd_key_file", + "description": "xccdf_org.ssgproject.content_rule_etcd_key_file", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_etcd_key_file" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_cni_conf", + "description": "xccdf_org.ssgproject.content_rule_file_owner_cni_conf", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_cni_conf" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_etcd_member", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_etcd_member", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_etcd_member" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_etcd_member", + "description": "xccdf_org.ssgproject.content_rule_file_owner_etcd_member", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_etcd_member" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_kube_scheduler", + "description": "xccdf_org.ssgproject.content_rule_file_owner_kube_scheduler", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_kube_scheduler" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_kube_apiserver", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_kube_apiserver", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_kube_apiserver" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_kube_apiserver", + "description": "xccdf_org.ssgproject.content_rule_file_owner_kube_apiserver", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_kube_apiserver" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_openvswitch", + "description": "xccdf_org.ssgproject.content_rule_file_owner_openvswitch", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_openvswitch" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_kube_controller_manager", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_kube_controller_manager", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_kube_controller_manager" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_controller_manager_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_controller_manager_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_controller_manager_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_scheduler_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_scheduler_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_scheduler_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_openvswitch", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_openvswitch", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_openvswitch" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_var_lib_etcd", + "description": "xccdf_org.ssgproject.content_rule_file_owner_var_lib_etcd", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_var_lib_etcd" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_var_lib_etcd", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_var_lib_etcd", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_var_lib_etcd" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_controller_manager_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_owner_controller_manager_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_controller_manager_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_scheduler_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_scheduler_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_scheduler_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_kube_controller_manager", + "description": "xccdf_org.ssgproject.content_rule_file_owner_kube_controller_manager", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_kube_controller_manager" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_kube_scheduler", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_kube_scheduler", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_kube_scheduler" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_owner_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_kube_controller_manager", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_kube_controller_manager", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_kube_controller_manager" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_kube_apiserver", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_kube_apiserver", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_kube_apiserver" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_cni_conf", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_cni_conf", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_cni_conf" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_kube_scheduler", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_kube_scheduler", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_kube_scheduler" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_permissions_controller_manager_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_permissions_controller_manager_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_permissions_controller_manager_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_cni_conf", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_cni_conf", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_cni_conf" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_openvswitch", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_openvswitch", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_openvswitch" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_groupowner_etcd_member", + "description": "xccdf_org.ssgproject.content_rule_file_groupowner_etcd_member", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_groupowner_etcd_member" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_file_owner_scheduler_kubeconfig", + "description": "xccdf_org.ssgproject.content_rule_file_owner_scheduler_kubeconfig", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_file_owner_scheduler_kubeconfig" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "notchecked" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_insecure_port", + "description": "xccdf_org.ssgproject.content_rule_api_server_insecure_port", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_insecure_port" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_tls_private_key", + "description": "xccdf_org.ssgproject.content_rule_api_server_tls_private_key", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_tls_private_key" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_tls_cert", + "description": "xccdf_org.ssgproject.content_rule_api_server_tls_cert", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_tls_cert" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_client_ca", + "description": "xccdf_org.ssgproject.content_rule_api_server_client_ca", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_client_ca" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_audit_log_path", + "description": "xccdf_org.ssgproject.content_rule_api_server_audit_log_path", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_audit_log_path" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_tls_cipher_suites", + "description": "xccdf_org.ssgproject.content_rule_api_server_tls_cipher_suites", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_tls_cipher_suites" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_EventRateLimit", + "description": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_EventRateLimit", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_EventRateLimit" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_authorization_mode", + "description": "xccdf_org.ssgproject.content_rule_api_server_authorization_mode", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_authorization_mode" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_audit_log_maxage", + "description": "xccdf_org.ssgproject.content_rule_api_server_audit_log_maxage", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_audit_log_maxage" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_profiling", + "description": "xccdf_org.ssgproject.content_rule_api_server_profiling", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_profiling" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_ServiceAccount", + "description": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_ServiceAccount", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_ServiceAccount" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_AlwaysAdmit", + "description": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_AlwaysAdmit", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_AlwaysAdmit" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_encryption_provider_cipher", + "description": "xccdf_org.ssgproject.content_rule_api_server_encryption_provider_cipher", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_encryption_provider_cipher" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_token_auth", + "description": "xccdf_org.ssgproject.content_rule_api_server_token_auth", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_token_auth" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_anonymous_auth", + "description": "xccdf_org.ssgproject.content_rule_api_server_anonymous_auth", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_anonymous_auth" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_etcd_ca", + "description": "xccdf_org.ssgproject.content_rule_api_server_etcd_ca", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_etcd_ca" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_encryption_provider_config", + "description": "xccdf_org.ssgproject.content_rule_api_server_encryption_provider_config", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_encryption_provider_config" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_request_timeout", + "description": "xccdf_org.ssgproject.content_rule_api_server_request_timeout", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_request_timeout" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_audit_log_maxsize", + "description": "xccdf_org.ssgproject.content_rule_api_server_audit_log_maxsize", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_audit_log_maxsize" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_NodeRestriction", + "description": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_NodeRestriction", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_NodeRestriction" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_SecurityContextDeny", + "description": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_SecurityContextDeny", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_SecurityContextDeny" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_PodSecurityPolicy", + "description": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_PodSecurityPolicy", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_PodSecurityPolicy" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_basic_auth", + "description": "xccdf_org.ssgproject.content_rule_api_server_basic_auth", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_basic_auth" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_kubelet_client_key", + "description": "xccdf_org.ssgproject.content_rule_api_server_kubelet_client_key", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_kubelet_client_key" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_service_account_public_key", + "description": "xccdf_org.ssgproject.content_rule_api_server_service_account_public_key", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_service_account_public_key" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_etcd_key", + "description": "xccdf_org.ssgproject.content_rule_api_server_etcd_key", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_etcd_key" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_AlwaysPullImages", + "description": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_AlwaysPullImages", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_AlwaysPullImages" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_kubelet_client_cert", + "description": "xccdf_org.ssgproject.content_rule_api_server_kubelet_client_cert", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_kubelet_client_cert" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_audit_log_maxbackup", + "description": "xccdf_org.ssgproject.content_rule_api_server_audit_log_maxbackup", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_audit_log_maxbackup" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_kubelet_https", + "description": "xccdf_org.ssgproject.content_rule_api_server_kubelet_https", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_kubelet_https" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_etcd_cert", + "description": "xccdf_org.ssgproject.content_rule_api_server_etcd_cert", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_etcd_cert" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_insecure_bind_address", + "description": "xccdf_org.ssgproject.content_rule_api_server_insecure_bind_address", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_insecure_bind_address" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "pass" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_kubelet_certificate_authority", + "description": "xccdf_org.ssgproject.content_rule_api_server_kubelet_certificate_authority", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_kubelet_certificate_authority" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_NamespaceLifecycle", + "description": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_NamespaceLifecycle", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_admission_control_plugin_NamespaceLifecycle" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + }, + { + "uuid": "56666738-0f9a-4e38-9aac-c0fad00a5821", + "title": "xccdf_org.ssgproject.content_rule_api_server_secure_port", + "description": "xccdf_org.ssgproject.content_rule_api_server_secure_port", + "methods": [ + "TEST-AUTOMATED" + ], + "subjects": [ + { + "uuid-ref": "3e42fa6b-a819-4f58-b073-a04a0b3c828d", + "type": "component", + "title": "Red Hat OpenShift Kubernetes" + }, + { + "uuid-ref": "285d87c2-aab0-4935-b28b-c4dab131cf88", + "type": "inventory-item", + "title": "Pod", + "props": [ + { + "name": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + }, + { + "name": "cluster-name", + "value": "ROKS-OpenSCAP-1" + }, + { + "name": "cluster-type", + "value": "openshift" + }, + { + "name": "cluster-region", + "value": "us-south" + } + ] + } + ], + "relevant-evidence": [ + { + "href": "https://github.mycorp.com/degenaro/evidence-locker", + "description": "Evidence location.", + "props": [ + { + "name": "rule", + "ns": "dns://xccdf", + "class": "id", + "value": "xccdf_org.ssgproject.content_rule_api_server_secure_port" + }, + { + "name": "time", + "ns": "dns://xccdf", + "class": "timestamp", + "value": "2020-08-03T02:26:28+00:00" + }, + { + "name": "result", + "ns": "dns://xccdf", + "class": "result", + "value": "fail" + }, + { + "name": "target", + "ns": "dns://xccdf", + "class": "target", + "value": "kube-br7qsa3d0vceu2so1a90-roksopensca-default-000001fe.iks.mycorp" + } + ] + } + ] + } + ] +} \ No newline at end of file diff --git a/tests/trestle/tasks/osco_to_oscal_test.py b/tests/trestle/tasks/osco_to_oscal_test.py index cc2f1cb11..320b04e2e 100644 --- a/tests/trestle/tasks/osco_to_oscal_test.py +++ b/tests/trestle/tasks/osco_to_oscal_test.py @@ -123,7 +123,19 @@ def test_simulate_no_ouput_dir(tmpdir): retval = tgt.simulate() assert retval == TaskOutcome.SIM_FAILURE assert len(os.listdir(str(tmpdir))) == 0 - + +def test_simulate_input_fetcher(tmpdir): + """Test simulate call OSCO fetcher json data.""" + config = configparser.ConfigParser() + config_path = pathlib.Path('tests/data/tasks/osco/demo-osco-to-oscal-fetcher.config') + config.read(config_path) + section = config['task.osco-to-oscal'] + section['output-dir'] = str(tmpdir) + tgt = osco_to_oscal.OscoToOscal(section) + retval = tgt.simulate() + assert retval == TaskOutcome.SIM_SUCCESS + assert len(os.listdir(str(tmpdir))) == 0 + @patch(target='uuid.uuid4', new=uuid_mock1) def test_execute(tmpdir): """Test execute call.""" @@ -238,3 +250,22 @@ def test_execute_no_ouput_dir(tmpdir): retval = tgt.execute() assert retval == TaskOutcome.FAILURE assert len(os.listdir(str(tmpdir))) == 0 + +@patch(target='uuid.uuid4', new=uuid_mock1) +def test_execute_input_fetcher(tmpdir): + """Test execute call OSCO fetcher json data.""" + config = configparser.ConfigParser() + config_path = pathlib.Path('tests/data/tasks/osco/demo-osco-to-oscal-fetcher.config') + config.read(config_path) + section = config['task.osco-to-oscal'] + section['output-dir'] = str(tmpdir) + tgt = osco_to_oscal.OscoToOscal(section) + retval = tgt.execute() + assert retval == TaskOutcome.SUCCESS + assert len(os.listdir(str(tmpdir))) == 2 + f_expected = pathlib.Path('tests/data/tasks/osco/output-fetcher/') / 'ssg-ocp4-ds-cis-111.222.333.444-pod.json' + f_produced = tmpdir / 'ssg-ocp4-ds-cis-111.222.333.444-pod.json' + assert [row for row in open(f_produced)] == [row for row in open(f_expected)] + f_expected = pathlib.Path('tests/data/tasks/osco/output-fetcher/') / 'ssg-ocp4-ds-cis-111.222.333.555-pod.json' + f_produced = tmpdir / 'ssg-ocp4-ds-cis-111.222.333.555-pod.json' + assert [row for row in open(f_produced)] == [row for row in open(f_expected)] diff --git a/trestle/tasks/osco_to_oscal.py b/trestle/tasks/osco_to_oscal.py index 08f63bb52..594a7b11e 100644 --- a/trestle/tasks/osco_to_oscal.py +++ b/trestle/tasks/osco_to_oscal.py @@ -55,17 +55,18 @@ def print_info(self) -> None: """Print the help string.""" logger.info(f'Help information for {self.name} task.') logger.info('') - logger.info('Purpose: Transform OpenShift Compliance Operator (OSCO) produced .yaml files into Open Security Controls Assessment Language (OSCAL) .json partial results files.') + logger.info('Purpose: Transform OpenShift Compliance Operator (OSCO) files into Open Security Controls Assessment Language (OSCAL) partial results files.') logger.info('') logger.info('Configuration flags sit under [task.osco-to-oscal]:') - logger.info(' input-dir = (required) the path of the input directory comprising osco .yaml files.') + logger.info(' input-dir = (required) the path of the input directory comprising OSCO .yaml and/or .json files.') logger.info(' input-metadata = (optional) the name of the input directory metadata .yaml file, default = oscal-metadata.yaml.') logger.info(' output-dir = (required) the path of the output directory comprising synthesized OSCAL .json files.') logger.info(' output-overwrite = (optional) true [default] or false; replace existing output when true.') logger.info(' quiet = (optional) true or false [default]; display file creations and rules analysis when false.') logger.info('') - logger.info('Operation: All the .yaml files in the input-dir are processed, each producing a corresponding .json output-dir file.') - logger.info('The exception is the input-metadata .yaml file which, if present, is used to augment all produced .json output directory files.') + logger.info('Operation: A transformation is performed on one or more OSCO input files to produce corresponding output files in OSCAL partial results format. Input files are typically OSCO .yaml files or Arboretum .json files, the latter constructed by a fetcher/check (see https://github.com/ComplianceAsCode/auditree-arboretum).') + logger.info('') + logger.info('All the .yaml files in the input-dir are processed, each producing a corresponding .json output-dir file. The exception is the input-metadata .yaml file which, if present, is used to augment all produced .json output directory files. Similarly, all the .json files in the input-dir are processed, each producing one or more corresponding .json output-dir files.') logger.info('') logger.info('The format of the input-metadata .yaml file comprises one or more entries as follows:') logger.info(':') @@ -119,33 +120,30 @@ def simulate(self) -> TaskOutcome: # skip enhancing oscal metadata if ifile.name == imeta: continue - # ignore non-yaml files - if ifile.suffix not in ['.yml', '.yaml']: - logger.debug(f'[simluate] skipping {ifile.name}') - continue - # calculate the output file, including path - ofile = opth / pathlib.Path(ifile.stem+'.json') - # only allow writing output file if either: - # a) it does not already exist, or - # b) output-overwrite flag is True - if not overwrite: - if ofile.exists(): - logger.error(f'simluate: file exists: {ofile}') - return TaskOutcome('simulated-failure') - if not quiet: - logger.debug(f'[simluate] create {ofile}') - # fetch the contents of the subject OSCO .yaml/.yml file - idata = self._read_content(ifile) - # create the OSCAL .json file from the OSCO and the optional osco-metadata files - observations, analysis = osco.get_observations(idata, metadata) - # write the OSCAL to the output file - self._write_content(ofile, observations, True) - # display analysis - if not quiet: - logger.debug(f'[simluate] Rules Analysis:') - logger.debug(f'[simluate] config_maps: {analysis["config_maps"]}') - logger.debug(f'[simluate] dispatched rules: {analysis["dispatched_rules"]}') - logger.debug(f'[simluate] result types: {analysis["result_types"]}') + # assemble collection comprising output file name to unprocessed content + collection = self._assemble(ifile) + # formulate each output OSCAL partial results file + for oname in collection.keys(): + ofile = opth / pathlib.Path(oname) + # only allow writing output file if either: + # a) it does not already exist, or + # b) output-overwrite flag is True + if not overwrite: + if ofile.exists(): + logger.error(f'file exists: {ofile}') + return TaskOutcome('simulated-failure') + if not quiet: + logger.debug(f'create: {ofile}') + # create the OSCAL .json file from the OSCO and the optional osco-metadata files + observations, analysis = osco.get_observations(collection[oname], metadata) + # write the OSCAL to the output file + self._write_content(ofile, observations, True) + # display analysis + if not quiet: + logger.debug(f'[simluate] Rules Analysis:') + logger.debug(f'[simluate] config_maps: {analysis["config_maps"]}') + logger.debug(f'[simluate] dispatched rules: {analysis["dispatched_rules"]}') + logger.debug(f'[simluate] result types: {analysis["result_types"]}') return TaskOutcome('simulated-success') logger.error(f'config missing') return TaskOutcome('simulated-failure') @@ -181,44 +179,84 @@ def execute(self) -> TaskOutcome: # skip enhancing oscal metadata if ifile.name == imeta: continue - # ignore non-yaml files - if ifile.suffix not in ['.yml', '.yaml']: - logger.debug(f'skipping {ifile.name}') - continue - # calculate the output file, including path - ofile = opth / pathlib.Path(ifile.stem+'.json') - # only allow writing output file if either: - # a) it does not already exist, or - # b) output-overwrite flag is True - if not overwrite: - if ofile.exists(): - logger.error(f'file exists: {ofile}') - return TaskOutcome('failure') - if not quiet: - logger.info(f'create: {ofile}') - # fetch the contents of the subject OSCO .yaml/.yml file - idata = self._read_content(ifile) - # create the OSCAL .json file from the OSCO and the optional osco-metadata files - observations, analysis = osco.get_observations(idata, metadata) - # write the OSCAL to the output file - self._write_content(ofile, observations) - # display analysis - if not quiet: - logger.info(f'Rules Analysis:') - logger.info(f'config_maps: {analysis["config_maps"]}') - logger.info(f'dispatched rules: {analysis["dispatched_rules"]}') - logger.info(f'result types: {analysis["result_types"]}') + # assemble collection comprising output file name to unprocessed content + collection = self._assemble(ifile) + # formulate each output OSCAL partial results file + for oname in collection.keys(): + ofile = opth / pathlib.Path(oname) + # only allow writing output file if either: + # a) it does not already exist, or + # b) output-overwrite flag is True + if not overwrite: + if ofile.exists(): + logger.error(f'file exists: {ofile}') + return TaskOutcome('failure') + if not quiet: + logger.info(f'create: {ofile}') + # create the OSCAL .json file from the OSCO and the optional osco-metadata files + observations, analysis = osco.get_observations(collection[oname], metadata) + # write the OSCAL to the output file + self._write_content(ofile, observations) + # display analysis + if not quiet: + logger.info(f'Rules Analysis:') + logger.info(f'config_maps: {analysis["config_maps"]}') + logger.info(f'dispatched rules: {analysis["dispatched_rules"]}') + logger.info(f'result types: {analysis["result_types"]}') return TaskOutcome('success') logger.error(f'config missing') return TaskOutcome('failure') - def _read_content(self, ifile: pathlib.Path) -> osco.t_osco: - """Read the contents of a yaml file.""" - content = yaml.load(ifile.open('r+'), Loader=yaml.Loader) - logger.debug('========== ==========') - logger.debug(content) - logger.debug('========== ==========') - return content + def _assemble(self, ifile: pathlib.Path) -> Dict[str, osco.t_osco]: + """Formulate collection comprising output file name to unprocessed content.""" + collection = {} + # handle OSCO individual yaml files (just one pairing) + if ifile.suffix in ['.yml', '.yaml']: + ydict = yaml.load(ifile.open('r+'), Loader=yaml.Loader) + oname = ifile.stem+'.json' + logger.debug(f'========== <{oname}> ==========') + logger.debug(ydict) + logger.debug(f'========== ==========') + collection[oname] = ydict + # handle arboretum OSCO fetcher/check composite json files (one or more pairings) + elif ifile.suffix in ['.jsn', '.json']: + idata = json.load(ifile.open('r+')) + if idata is not None: + for key in idata.keys(): + for group in idata[key]: + # for each cluster create an individual yaml-like unprocessed data set + for cluster in idata[key][group]: + if 'resources' not in cluster.keys(): + continue + for resource in cluster['resources']: + if 'kind' not in resource.keys(): + continue + if resource['kind'] != 'ConfigMap': + continue + if 'data' not in resource.keys(): + continue + if 'results' not in resource['data'].keys(): + continue + if 'metadata' not in resource.keys(): + continue + if 'name' not in resource['metadata'].keys(): + continue + # add yaml-like data set to collection indexed by ConfigMap identity + ydict = {} + ydict['kind'] = resource['kind'] + data = {} + data['results'] = resource['data']['results'] + ydict['data'] = data + ydict['metadata'] = resource['metadata'] + oname = resource['metadata']['name']+'.json' + collection[oname] = ydict + logger.debug(f'========== <{oname}> ==========') + logger.debug(ydict) + logger.debug(f'========== ==========') + else: + logger.debug(f'skipping {ifile.name}') + logger.debug(f'collection: {len(collection)}') + return collection def _write_content(self, ofile: pathlib.Path, observations: osco.AssessmentResultsPartial, simulate:bool=False) -> None: """Write the contents of a json file."""