Skip to main content

What ACM Foil Does

It does three things:

  1. Selects managed clusters labeled spo=true.
  2. Uses OpenShift GitOps to sync ACM policy resources to the hub.
  3. Lets ACM Governance distribute and enforce those policies on selected clusters.

Current Scope​

The active deployment includes two policy sets.

PolicySetPurpose
policyset-blastwall-testChecks for the SPO RawSelinuxProfile CRD, deploys Blastwall profiles, waits for status.usage, then applies SCC and RBAC bindings.
policyset-spo-testInstalls the Security Profiles Operator and deploys the Red Hat CVE mitigation DaemonSet policy.

Cluster Selection​

Managed clusters opt in with this label:

oc label managedcluster <cluster-name> spo=true --overwrite

What Lands on Managed Clusters​

ACM Foil applies these managed-cluster resources through ACM policies:

PolicyManaged-cluster resources
policy-install-spo-operatorNamespace/openshift-security-profiles and OperatorPolicy/install-spo-operator.
policy-spo-rawselinuxprofile-crdInform-only check for the established RawSelinuxProfile CRD.
policy-blastwall-v2-raw-profilesBlastwall namespaces, RawSelinuxProfile resources, and validation ConfigMap.
policy-blastwall-v2-profile-usageInform-only gate for profile status.usage publication.
policy-blastwall-v2-runtime-bindingsBlastwall SCCs and workload RBAC with status-derived SELinux types.
policy-prevent-copy-fail-cve-dsNamespace, privileged SCC binding, and Red Hat BPF LSM mitigation DaemonSet.

What It Does Not Do​

ACM Foil does not target every managed cluster. Placement is controlled by ACM labels and the default ManagedClusterSetBinding in the policy namespace.

It also does not mirror disconnected operator catalogs. Target clusters need access to a catalog source that contains the Security Profiles Operator package.