Skip to main content

Requirements

ACM Foil expects an ACM hub that can place policies onto managed OpenShift clusters.

RequirementWhy it matters
Red Hat Advanced Cluster ManagementProvides Governance Policy, PolicySet, Placement, and managed-cluster policy distribution.
ACM OperatorPolicy supportInstalls the Security Profiles Operator through the governance framework.
OpenShift GitOps / Argo CD on the ACM hubSyncs this repository into the ACM policy namespace.
Managed OpenShift clustersReceives the ACM policies selected by placement.
OLM and Red Hat operator catalog access on target clustersRequired for the SPO OperatorPolicy to install the Security Profiles Operator.
Managed cluster label spo=trueOpts a cluster into the active ACM placement.

ACM Foil installs the Security Profiles Operator in openshift-security-profiles on selected managed clusters. If a cluster cannot reach the redhat-operators catalog, the install policy remains noncompliant and SPO-backed policies do not become ready.

For Red Hat's explanation of SPO, see Understanding the Security Profiles Operator.

Quick Checks​

Run these from the ACM hub:

oc get ns openshift-gitops
oc api-resources | grep policy.open-cluster-management.io
oc get managedcluster

Check that the target cluster is labeled:

oc get managedcluster <cluster-name> --show-labels

Label a target cluster:

oc label managedcluster <cluster-name> spo=true --overwrite