Skip to main content

ACM Foil

ACM Foil is inspired by Greg Procunier's (gprocunier) Blastwall project. Blastwall demonstrates hardened fleet management for RHEL with IdM, with a path for bringing that same hardened disposition to OpenShift workloads. ACM Foil extends that model into ACM-driven OpenShift fleet management.

Use ACM Foil when you want GitOps and ACM to deliver stricter workload confinement, controlled cluster placement, and compliance evidence across selected OpenShift clusters. See Blastwall Workload Confinement for the benefits and adoption boundary.

License: Apache-2.0

Quick Start​

oc apply -f apps/hub/argocd-application.yaml

Current Policy Flow​

ACM policy delivery flow from GitOps source to hub sync, placement, SPO install and profiles, DaemonSet mitigation, and compliance proof.

What It Deploys​

PolicySetPurpose
policyset-blastwall-testDeploys Blastwall SPO profiles, waits for status.usage, and applies status-derived SCC/RBAC bindings.
policyset-spo-testInstalls the Security Profiles Operator and deploys a Red Hat CVE mitigation policy.

ACM Foil installs the Security Profiles Operator on selected managed clusters through ACM OperatorPolicy. Clusters must have OLM and access to the Red Hat operator catalog.

Explore​