Compliance Remediation Groupings

This page provides links to remediation groupings organized by OCP version. Each version has its own set of compliance remediations collected from the OpenShift Compliance Operator.


Available Versions

OCP Version Groups Remediations Status
OCP 5.0 40 groups 914 total Active
OCP 4.22 40 groups (33 tested) 910 total Active
OCP 4.21 17 groups 82 total Active

About Remediation Groupings

Remediation groupings consolidate individual compliance check failures into logical groups that can be addressed together. Each group typically results in a single MachineConfig or CRD that remediates multiple related checks.

Grouping Categories:

Status Legend:


Adding a New Version

To add remediation groupings for a new OCP version:

make add-version OCP_VERSION=5.1 SOURCE_VERSION=5.0

That scaffolds version pages, group pages, and docs/_data/tracking-X_Y.json. Then:

  1. Export scan data: make export-compliance OCP_VERSION=5.1
  2. Update this index page with a link to the new version
  3. Refresh docs/_data/group-matrix.json with make generate-group-matrix
  4. Fill missing scan-history profile counts with make backfill-scan-profiles
Legend
Remediation Status
✅ PASS (vanilla) Passes on unhardened RHCOS; no remediation needed
🟢 Verified Remediation tested on live cluster, confirmed PASS
🔵 In Progress Remediation actively being developed or tested
🟡 Pending Not yet started; needs remediation work
🟠 Partial Some checks pass or remediation not fully validated
⚪ On Hold Work paused (blocked or deprioritized)
Upstream Verdict
🔼 Candidate Suitable for upstreaming to ComplianceAsCode
🟣 PR Open Upstream PR filed
🎯 RAN Only Only applies to RAN deployments
⚙️ Platform Requires OCP platform-level configuration
✅ Pass Already passing upstream
📍 Site Site/deployment-specific configuration
— N/A Not applicable for upstreaming
Platform
RHCOS Node-level checks (MachineConfig)
OCP Platform-level checks (API/CR)
Mixed Both RHCOS and OCP checks
Severity
HIGH
MEDIUM
LOW
MANUAL