Policies
policy-install-spo-operator
File:
policies/base/policy-install-spo-operator.yaml
Purpose:
Install the Security Profiles Operator on selected managed clusters by using ACM OperatorPolicy.
Creates:
Namespace/openshift-security-profiles
OperatorPolicy/install-spo-operator
The OperatorPolicy requests:
package: security-profiles-operator
channel: release-alpha-rhel-8
source: redhat-operators
sourceNamespace: openshift-marketplace
upgradeApproval: Automatic
The policy leaves operatorGroup unset so ACM can accept an existing OperatorGroup in openshift-security-profiles or create the default group when none exists.
Remediation:
enforce
Prerequisites:
ACM OperatorPolicy support
OLM available on the managed cluster
Red Hat operator catalog available to the managed cluster
Cluster selected by Placement/placement-spo-test
Validate from the hub:
oc get policy -n <cluster-name> acm-spo-policies.policy-install-spo-operator
Validate from the managed cluster:
oc get operatorpolicy -A | grep install-spo-operator
oc get namespace openshift-security-profiles
Risk:
This policy installs a cluster operator and automatically approves SPO updates from the configured channel.
policy-spo-rawselinuxprofile-crd
File:
policies/base/policy-spo-rawselinuxprofile-crd.yaml
Purpose:
Check that the Security Profiles Operator RawSelinuxProfile CRD is established before Blastwall profile resources are enforced.
Checks:
CustomResourceDefinition/rawselinuxprofiles.security-profiles-operator.x-k8s.io
status.conditions[type=Established].status=True
Remediation:
inform
Validate from the hub:
oc get policy -n <cluster-name> acm-spo-policies.policy-spo-rawselinuxprofile-crd
Risk:
This policy does not install SPO or create the CRD. It only reports whether the target cluster has the required SPO API available after the install policy runs.
policy-blastwall-v2-raw-profiles
File:
policies/base/policy-blastwall-v2-raw-profiles.yaml
Purpose:
Deploy the Blastwall OpenShift/SPO base resources that do not depend on status-derived SCC typing.
Dependency:
policy-spo-rawselinuxprofile-crd must be Compliant
Creates:
Namespace/blastwall-spo
Namespace/blastwall-workloads
RawSelinuxProfile/blastwall
RawSelinuxProfile/blastwallnested
ConfigMap/blastwall-spo-probe
Remediation:
enforce
Prerequisites:
Security Profiles Operator installed by policy-install-spo-operator or already present
RawSelinuxProfile CRD established
Cluster selected by Placement/placement-spo-test
Validate from the managed cluster:
oc get rawselinuxprofile blastwall blastwallnested
oc get ns blastwall-spo blastwall-workloads
Risk:
This policy creates namespaces, SPO raw profiles, and the validation probe ConfigMap. It does not grant workload access to the Blastwall SCCs, and ConfigMap presence does not prove runtime confinement. Treat the probe as validation material until a pod or Job executes it and the output is collected.
policy-blastwall-v2-profile-usage
File:
policies/base/policy-blastwall-v2-profile-usage.yaml
Purpose:
Gate SCC/RBAC rollout until both Blastwall RawSelinuxProfile resources publish status.usage.
Dependency:
policy-blastwall-v2-raw-profiles must be Compliant
Checks:
RawSelinuxProfile/blastwall status.usage
RawSelinuxProfile/blastwallnested status.usage
Remediation:
inform
Validate from the managed cluster:
oc get rawselinuxprofile blastwall blastwallnested \
-o custom-columns=NAME:.metadata.name,STATE:.status.state,USAGE:.status.usage
Risk:
This policy is a rollout gate. If SPO has not compiled and published usage strings, policy-blastwall-v2-runtime-bindings does not enforce SCC/RBAC bindings.
policy-blastwall-v2-runtime-bindings
File:
policies/base/policy-blastwall-v2-runtime-bindings.yaml
Purpose:
Deploy Blastwall SCC and workload RBAC bindings after profile usage is available.
Dependency:
policy-blastwall-v2-profile-usage must be Compliant
Creates:
SecurityContextConstraints/blastwall-confined
SecurityContextConstraints/blastwall-nested
ServiceAccount, Role, and RoleBinding resources for Blastwall validation workloads
The SCC SELinux types are resolved from live RawSelinuxProfile.status.usage values. ACM Foil uses the upstream default calabi-ocp420-rawprofile-underscore mode for the supported blastwall and blastwallnested profiles.
Remediation:
enforce
Validate from the managed cluster:
oc get scc blastwall-confined blastwall-nested \
-o custom-columns=NAME:.metadata.name,TYPE:.seLinuxContext.seLinuxOptions.type
oc -n blastwall-workloads get serviceaccount,role,rolebinding
Risk:
This policy grants selected service accounts access to the Blastwall SCCs. Keep placement narrow until profile readiness, SCC admission, and probe results are validated.
policy-prevent-copy-fail-cve-ds
File:
policies/base/policy-prevent-copy-fail-cve-ds.yaml
Purpose:
Deploy the Red Hat BPF LSM DaemonSet mitigation for CVE-2026-31431.
Creates:
Namespace/cve-2026-31431-mitigation-ebpf
RoleBinding/system:openshift:scc:privileged
DaemonSet/cve-2026-31431-mitigation-ebpf
Remediation:
enforce
Prerequisites:
OpenShift worker nodes that can run the Red Hat mitigation image
Cluster selected by Placement/placement-spo-test
Validate from the managed cluster:
oc get ds -n cve-2026-31431-mitigation-ebpf cve-2026-31431-mitigation-ebpf
oc get pods -n cve-2026-31431-mitigation-ebpf -o wide
Risk:
This policy deploys a privileged node-level DaemonSet. Use it only where the mitigation is approved.