Compliance Remediation Groupings

This page provides links to remediation groupings organized by OCP version. Each version has its own set of compliance remediations collected from the OpenShift Compliance Operator.


Available Versions

OCP Version Groups Remediations Status
OCP 5.0 40 groups 914 total Active
OCP 4.22 40 groups (33 tested) 910 total Active
OCP 4.21 17 groups 82 total Active

About Remediation Groupings

Remediation groupings consolidate individual compliance check failures into logical groups that can be addressed together. Each group typically results in a single MachineConfig or CRD that remediates multiple related checks.

Grouping Categories:

Status Legend:


Adding a New Version

To add remediation groupings for a new OCP version:

  1. Create directory: docs/versions/X.XX/
  2. Add remediations.md with version-specific content
  3. Update this index page with a link to the new version
Legend
Remediation Status
✅ PASS (vanilla) Passes on unhardened RHCOS; no remediation needed
🟢 Verified Remediation tested on live cluster, confirmed PASS
🔵 In Progress Remediation actively being developed or tested
🟡 Pending Not yet started; needs remediation work
🟠 Partial Some checks pass or remediation not fully validated
⚪ On Hold Work paused (blocked or deprioritized)
Upstream Verdict
🔼 Candidate Suitable for upstreaming to ComplianceAsCode
🟣 PR Open Upstream PR filed
🎯 RAN Only Only applies to RAN deployments
⚙️ Platform Requires OCP platform-level configuration
✅ Pass Already passing upstream
📍 Site Site/deployment-specific configuration
— N/A Not applicable for upstreaming
Platform
RHCOS Node-level checks (MachineConfig)
OCP Platform-level checks (API/CR)
Mixed Both RHCOS and OCP checks
Severity
HIGH
MEDIUM
LOW
MANUAL

Keyboard Shortcuts

Navigation
j / Next row
k / Previous row
Enter Open selected / Expand details
Esc Clear selection / Close modal
Actions
/ Focus search
d Toggle dark mode
? Show this help
g h Go to home
Filters
1 Show all
2 Pending only
3 In Progress only
4 Complete only