Skip to content

[rc-4.8] Add new CIS hardening controls (#552)#571

Merged
abhinavnagaraj merged 1 commit intorc-4.8from
backport/rc-4.8/pr-552
Mar 19, 2026
Merged

[rc-4.8] Add new CIS hardening controls (#552)#571
abhinavnagaraj merged 1 commit intorc-4.8from
backport/rc-4.8/pr-552

Conversation

@github-actions
Copy link
Contributor

Backport

This will backport the following commits from main to rc-4.8:

Questions ?

Please refer to the Backport tool documentation

* Add new CIS hardening controls with idempotent implementations

New CIS controls added:
- CIS 5.2.2, 5.2.3, 5.2.4: Sudo hardening (pty, logging, password policies)
- CIS 5.4.3.3: Default umask 027 configuration
- Service hardening: Mask apport and rpcbind services
- CIS 1.5.x: Coredump restrictions via systemd
- CIS 2.1.x: NTP time synchronization

All new functions use idempotent patterns (file overwrites or grep guards).

Preserves all existing main branch hardening including AppArmor,
rsyslog, AIDE, kernel hardening, and SSH Level 2 controls.

Co-Authored-By: Oz <oz-agent@warp.dev>

* Add CUSTOM_KUBEADM_PROVIDER_IMAGE support for custom provider testing

Co-Authored-By: Oz <oz-agent@warp.dev>

* Remove NTP hardening from CIS controls

NTP configuration should be handled externally, not in image hardening.

Co-Authored-By: Oz <oz-agent@warp.dev>

* Remove CUSTOM_KUBEADM_PROVIDER_IMAGE override

No longer needed - using standard provider-kubeadm image.

Co-Authored-By: Oz <oz-agent@warp.dev>

---------

Co-authored-by: Sumit Mishra <sumitmishra@sumit.mishra's MacBook Pro>
Co-authored-by: Oz <oz-agent@warp.dev>
(cherry picked from commit 1c4682e)
@abhinavnagaraj abhinavnagaraj merged commit ac70327 into rc-4.8 Mar 19, 2026
2 checks passed
@abhinavnagaraj abhinavnagaraj deleted the backport/rc-4.8/pr-552 branch March 19, 2026 05:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants