Skip to main content

Policies

policy-install-spo-operator​

File:

policies/base/policy-install-spo-operator.yaml

Purpose:

Install the Security Profiles Operator on selected managed clusters by using ACM OperatorPolicy.

Creates:

Namespace/openshift-security-profiles
OperatorPolicy/install-spo-operator

The OperatorPolicy requests:

package: security-profiles-operator
channel: release-alpha-rhel-8
source: redhat-operators
sourceNamespace: openshift-marketplace
upgradeApproval: Automatic

The policy leaves operatorGroup unset so ACM can accept an existing OperatorGroup in openshift-security-profiles or create the default group when none exists.

Remediation:

enforce

Prerequisites:

ACM OperatorPolicy support
OLM available on the managed cluster
Red Hat operator catalog available to the managed cluster
Cluster selected by Placement/placement-spo-test

Validate from the hub:

oc get policy -n <cluster-name> acm-spo-policies.policy-install-spo-operator

Validate from the managed cluster:

oc get operatorpolicy -A | grep install-spo-operator
oc get namespace openshift-security-profiles

Risk:

This policy installs a cluster operator and automatically approves SPO updates from the configured channel.

policy-spo-rawselinuxprofile-crd​

File:

policies/base/policy-spo-rawselinuxprofile-crd.yaml

Purpose:

Check that the Security Profiles Operator RawSelinuxProfile CRD is established before Blastwall profile resources are enforced.

Checks:

CustomResourceDefinition/rawselinuxprofiles.security-profiles-operator.x-k8s.io
status.conditions[type=Established].status=True

Remediation:

inform

Validate from the hub:

oc get policy -n <cluster-name> acm-spo-policies.policy-spo-rawselinuxprofile-crd

Risk:

This policy does not install SPO or create the CRD. It only reports whether the target cluster has the required SPO API available after the install policy runs.

policy-blastwall-v2-raw-profiles​

File:

policies/base/policy-blastwall-v2-raw-profiles.yaml

Purpose:

Deploy the Blastwall OpenShift/SPO base resources that do not depend on status-derived SCC typing.

Dependency:

policy-spo-rawselinuxprofile-crd must be Compliant

Creates:

Namespace/blastwall-spo
Namespace/blastwall-workloads
RawSelinuxProfile/blastwall
RawSelinuxProfile/blastwallnested
ConfigMap/blastwall-spo-probe

Remediation:

enforce

Prerequisites:

Security Profiles Operator installed by policy-install-spo-operator or already present
RawSelinuxProfile CRD established
Cluster selected by Placement/placement-spo-test

Validate from the managed cluster:

oc get rawselinuxprofile blastwall blastwallnested
oc get ns blastwall-spo blastwall-workloads

Risk:

This policy creates namespaces, SPO raw profiles, and the validation probe ConfigMap. It does not grant workload access to the Blastwall SCCs, and ConfigMap presence does not prove runtime confinement. Treat the probe as validation material until a pod or Job executes it and the output is collected.

policy-blastwall-v2-profile-usage​

File:

policies/base/policy-blastwall-v2-profile-usage.yaml

Purpose:

Gate SCC/RBAC rollout until both Blastwall RawSelinuxProfile resources publish status.usage.

Dependency:

policy-blastwall-v2-raw-profiles must be Compliant

Checks:

RawSelinuxProfile/blastwall status.usage
RawSelinuxProfile/blastwallnested status.usage

Remediation:

inform

Validate from the managed cluster:

oc get rawselinuxprofile blastwall blastwallnested \
-o custom-columns=NAME:.metadata.name,STATE:.status.state,USAGE:.status.usage

Risk:

This policy is a rollout gate. If SPO has not compiled and published usage strings, policy-blastwall-v2-runtime-bindings does not enforce SCC/RBAC bindings.

policy-blastwall-v2-runtime-bindings​

File:

policies/base/policy-blastwall-v2-runtime-bindings.yaml

Purpose:

Deploy Blastwall SCC and workload RBAC bindings after profile usage is available.

Dependency:

policy-blastwall-v2-profile-usage must be Compliant

Creates:

SecurityContextConstraints/blastwall-confined
SecurityContextConstraints/blastwall-nested
ServiceAccount, Role, and RoleBinding resources for Blastwall validation workloads

The SCC SELinux types are resolved from live RawSelinuxProfile.status.usage values. ACM Foil uses the upstream default calabi-ocp420-rawprofile-underscore mode for the supported blastwall and blastwallnested profiles.

Remediation:

enforce

Validate from the managed cluster:

oc get scc blastwall-confined blastwall-nested \
-o custom-columns=NAME:.metadata.name,TYPE:.seLinuxContext.seLinuxOptions.type
oc -n blastwall-workloads get serviceaccount,role,rolebinding

Risk:

This policy grants selected service accounts access to the Blastwall SCCs. Keep placement narrow until profile readiness, SCC admission, and probe results are validated.

policy-prevent-copy-fail-cve-ds​

File:

policies/base/policy-prevent-copy-fail-cve-ds.yaml

Purpose:

Deploy the Red Hat BPF LSM DaemonSet mitigation for CVE-2026-31431.

Creates:

Namespace/cve-2026-31431-mitigation-ebpf
RoleBinding/system:openshift:scc:privileged
DaemonSet/cve-2026-31431-mitigation-ebpf

Remediation:

enforce

Prerequisites:

OpenShift worker nodes that can run the Red Hat mitigation image
Cluster selected by Placement/placement-spo-test

Validate from the managed cluster:

oc get ds -n cve-2026-31431-mitigation-ebpf cve-2026-31431-mitigation-ebpf
oc get pods -n cve-2026-31431-mitigation-ebpf -o wide

Risk:

This policy deploys a privileged node-level DaemonSet. Use it only where the mitigation is approved.