product-demos icon indicating copy to clipboard operation
product-demos copied to clipboard

Feature Request: Linux demo - Add ability to run compliance scan (once defined in Insights)

Open benblasco opened this issue 2 years ago • 3 comments

The LINUX / Compliance scan only offers the STIG profile. It would be great if we could provide this kind of workflow for a demo:

  1. Run LINUX / Register
  2. Log into console.redhat.com and associate systems to a compliance profile
  3. Run new LINUX / Compliance Scan job to call insights-client --compliance
  4. Ensure that the job above handles the case where the user hasn't associated the system to a compliance profile.

Happy to work on this and submit a PR when I can.

benblasco avatar Oct 25 '22 02:10 benblasco

This will also require the installation of the correct version of scap-security-guide on the host as per:

Insights Compliance - Supported Configurations

Here's an example of how I have dealt with it:

aap_rhelconfigure.yml

benblasco avatar Oct 25 '22 02:10 benblasco

there is a role for that here https://github.com/RedHatInsights/ansible-collections-insights/tree/master/roles/insights_client

would need to integrate into the lab

willtome avatar Oct 26 '22 13:10 willtome

I have revisited this particular demo and realise that it is not connected to Insights in any way. We are just running one of the compliance demos available from here: https://galaxy.ansible.com/RedHatOfficial

As a consequence maybe it is worthwhile developing a separate exercise to run an Insights-based compliance scan. Thoughts?

benblasco avatar Nov 20 '22 00:11 benblasco

I believe I have addressed this issue via PR #51 Do you think we can close this issue as a consequence?

benblasco avatar Dec 13 '22 20:12 benblasco

Closing as #51 has been merged

willtome avatar Jan 13 '23 17:01 willtome