File: encryption_disabled.fail.sh

package info (click to toggle)
scap-security-guide 0.1.79-1
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid
  • size: 114,704 kB
  • sloc: xml: 244,677; sh: 84,647; python: 33,203; makefile: 27
file content (440 lines) | stat: -rwxr-xr-x 20,184 bytes parent folder | download | duplicates (3)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
#!/bin/bash
# remediation = none

yum install -y jq

kube_apipath="/kubernetes-api-resources"

# Create infra file for CPE to pass
mkdir -p "$kube_apipath/apis/config.openshift.io/v1/infrastructures/"
cat <<EOF > "$kube_apipath/apis/config.openshift.io/v1/infrastructures/cluster"
{
    "apiVersion": "config.openshift.io/v1",
    "kind": "Infrastructure",
    "metadata": {
        "name": "cluster",
    },
    "spec": {
        "platformSpec": {
            "type": "GCP"
        }
    },
    "status": {
        "platform": "GCP",
        "platformStatus": {
            "gcp": {
                "projectID": "openshift-gce-devel-ci",
                "region": "us-central1"
            },
            "type": "GCP"
        }
    }
}
EOF

machinev1beta1="/apis/machine.openshift.io/v1beta1"
machineset_apipath="$machinev1beta1/machinesets?limit=500"
# Create base file (not really needed for scanning but good for
# documentation and readability)
mkdir -p "$kube_apipath/$machinev1beta1"
cat <<EOF > "$kube_apipath/$machineset_apipath"
{
    "apiVersion": "v1",
    "items": [
        {
            "apiVersion": "machine.openshift.io/v1beta1",
            "kind": "MachineSet",
            "metadata": {
                "annotations": {
                    "machine.openshift.io/memoryMb": "15360",
                    "machine.openshift.io/vCPU": "4"
                },
                "creationTimestamp": "2021-11-02T15:04:09Z",
                "generation": 1,
                "labels": {
                    "machine.openshift.io/cluster-api-cluster": "ci-ln-jz1ylt2-72292-bqcd8"
                },
                "name": "ci-ln-jz1ylt2-72292-bqcd8-worker-a",
                "namespace": "openshift-machine-api",
                "resourceVersion": "17876",
                "uid": "6d06e16f-85a5-4a2c-b631-defb259a9558"
            },
            "spec": {
                "replicas": 1,
                "selector": {
                    "matchLabels": {
                        "machine.openshift.io/cluster-api-cluster": "ci-ln-jz1ylt2-72292-bqcd8",
                        "machine.openshift.io/cluster-api-machineset": "ci-ln-jz1ylt2-72292-bqcd8-worker-a"
                    }
                },
                "template": {
                    "metadata": {
                        "labels": {
                            "machine.openshift.io/cluster-api-cluster": "ci-ln-jz1ylt2-72292-bqcd8",
                            "machine.openshift.io/cluster-api-machine-role": "worker",
                            "machine.openshift.io/cluster-api-machine-type": "worker",
                            "machine.openshift.io/cluster-api-machineset": "ci-ln-jz1ylt2-72292-bqcd8-worker-a"
                        }
                    },
                    "spec": {
                        "metadata": {},
                        "providerSpec": {
                            "value": {
                                "apiVersion": "gcpprovider.openshift.io/v1beta1",
                                "canIPForward": false,
                                "credentialsSecret": {
                                    "name": "gcp-cloud-credentials"
                                },
                                "deletionProtection": false,
                                "disks": [
                                    {
                                        "autoDelete": true,
                                        "boot": true,
                                        "image": "projects/rhcos-cloud/global/images/rhcos-410-84-202110140201-0-gcp-x86-64",
                                        "labels": null,
                                        "sizeGb": 128,
                                        "type": "pd-ssd"
                                    }
                                ],
                                "kind": "GCPMachineProviderSpec",
                                "machineType": "n1-standard-4",
                                "metadata": {
                                    "creationTimestamp": null
                                },
                                "networkInterfaces": [
                                    {
                                        "network": "ci-ln-jz1ylt2-72292-bqcd8-network",
                                        "subnetwork": "ci-ln-jz1ylt2-72292-bqcd8-worker-subnet"
                                    }
                                ],
                                "projectID": "openshift-gce-devel-ci",
                                "region": "us-central1",
                                "serviceAccounts": [
                                    {
                                        "email": "ci-ln-jz1ylt2-72292-bqcd8-w@openshift-gce-devel-ci.iam.gserviceaccount.com",
                                        "scopes": [
                                            "https://www.googleapis.com/auth/cloud-platform"
                                        ]
                                    }
                                ],
                                "tags": [
                                    "ci-ln-jz1ylt2-72292-bqcd8-worker"
                                ],
                                "userDataSecret": {
                                    "name": "worker-user-data"
                                },
                                "zone": "us-central1-a"
                            }
                        }
                    }
                }
            },
            "status": {
                "availableReplicas": 1,
                "fullyLabeledReplicas": 1,
                "observedGeneration": 1,
                "readyReplicas": 1,
                "replicas": 1
            }
        },
        {
            "apiVersion": "machine.openshift.io/v1beta1",
            "kind": "MachineSet",
            "metadata": {
                "annotations": {
                    "machine.openshift.io/memoryMb": "15360",
                    "machine.openshift.io/vCPU": "4"
                },
                "creationTimestamp": "2021-11-02T15:04:10Z",
                "generation": 1,
                "labels": {
                    "machine.openshift.io/cluster-api-cluster": "ci-ln-jz1ylt2-72292-bqcd8"
                },
                "name": "ci-ln-jz1ylt2-72292-bqcd8-worker-b",
                "namespace": "openshift-machine-api",
                "resourceVersion": "19200",
                "uid": "2aa11a8f-a629-4b4f-beb9-dead2678d58c"
            },
            "spec": {
                "replicas": 1,
                "selector": {
                    "matchLabels": {
                        "machine.openshift.io/cluster-api-cluster": "ci-ln-jz1ylt2-72292-bqcd8",
                        "machine.openshift.io/cluster-api-machineset": "ci-ln-jz1ylt2-72292-bqcd8-worker-b"
                    }
                },
                "template": {
                    "metadata": {
                        "labels": {
                            "machine.openshift.io/cluster-api-cluster": "ci-ln-jz1ylt2-72292-bqcd8",
                            "machine.openshift.io/cluster-api-machine-role": "worker",
                            "machine.openshift.io/cluster-api-machine-type": "worker",
                            "machine.openshift.io/cluster-api-machineset": "ci-ln-jz1ylt2-72292-bqcd8-worker-b"
                        }
                    },
                    "spec": {
                        "metadata": {},
                        "providerSpec": {
                            "value": {
                                "apiVersion": "gcpprovider.openshift.io/v1beta1",
                                "canIPForward": false,
                                "credentialsSecret": {
                                    "name": "gcp-cloud-credentials"
                                },
                                "deletionProtection": false,
                                "disks": [
                                    {
                                        "autoDelete": true,
                                        "boot": true,
                                        "image": "projects/rhcos-cloud/global/images/rhcos-410-84-202110140201-0-gcp-x86-64",
                                        "labels": null,
                                        "sizeGb": 128,
                                        "type": "pd-ssd"
                                    }
                                ],
                                "kind": "GCPMachineProviderSpec",
                                "machineType": "n1-standard-4",
                                "metadata": {
                                    "creationTimestamp": null
                                },
                                "networkInterfaces": [
                                    {
                                        "network": "ci-ln-jz1ylt2-72292-bqcd8-network",
                                        "subnetwork": "ci-ln-jz1ylt2-72292-bqcd8-worker-subnet"
                                    }
                                ],
                                "projectID": "openshift-gce-devel-ci",
                                "region": "us-central1",
                                "serviceAccounts": [
                                    {
                                        "email": "ci-ln-jz1ylt2-72292-bqcd8-w@openshift-gce-devel-ci.iam.gserviceaccount.com",
                                        "scopes": [
                                            "https://www.googleapis.com/auth/cloud-platform"
                                        ]
                                    }
                                ],
                                "tags": [
                                    "ci-ln-jz1ylt2-72292-bqcd8-worker"
                                ],
                                "userDataSecret": {
                                    "name": "worker-user-data"
                                },
                                "zone": "us-central1-b"
                            }
                        }
                    }
                }
            },
            "status": {
                "availableReplicas": 1,
                "fullyLabeledReplicas": 1,
                "observedGeneration": 1,
                "readyReplicas": 1,
                "replicas": 1
            }
        },
        {
            "apiVersion": "machine.openshift.io/v1beta1",
            "kind": "MachineSet",
            "metadata": {
                "annotations": {
                    "machine.openshift.io/memoryMb": "15360",
                    "machine.openshift.io/vCPU": "4"
                },
                "creationTimestamp": "2021-11-02T15:04:10Z",
                "generation": 1,
                "labels": {
                    "machine.openshift.io/cluster-api-cluster": "ci-ln-jz1ylt2-72292-bqcd8"
                },
                "name": "ci-ln-jz1ylt2-72292-bqcd8-worker-c",
                "namespace": "openshift-machine-api",
                "resourceVersion": "19253",
                "uid": "eb57399e-8b21-46cb-abe3-9d148fc67e53"
            },
            "spec": {
                "replicas": 1,
                "selector": {
                    "matchLabels": {
                        "machine.openshift.io/cluster-api-cluster": "ci-ln-jz1ylt2-72292-bqcd8",
                        "machine.openshift.io/cluster-api-machineset": "ci-ln-jz1ylt2-72292-bqcd8-worker-c"
                    }
                },
                "template": {
                    "metadata": {
                        "labels": {
                            "machine.openshift.io/cluster-api-cluster": "ci-ln-jz1ylt2-72292-bqcd8",
                            "machine.openshift.io/cluster-api-machine-role": "worker",
                            "machine.openshift.io/cluster-api-machine-type": "worker",
                            "machine.openshift.io/cluster-api-machineset": "ci-ln-jz1ylt2-72292-bqcd8-worker-c"
                        }
                    },
                    "spec": {
                        "metadata": {},
                        "providerSpec": {
                            "value": {
                                "apiVersion": "gcpprovider.openshift.io/v1beta1",
                                "canIPForward": false,
                                "credentialsSecret": {
                                    "name": "gcp-cloud-credentials"
                                },
                                "deletionProtection": false,
                                "disks": [
                                    {
                                        "autoDelete": true,
                                        "boot": true,
                                        "image": "projects/rhcos-cloud/global/images/rhcos-410-84-202110140201-0-gcp-x86-64",
                                        "labels": null,
                                        "sizeGb": 128,
                                        "type": "pd-ssd"
                                    }
                                ],
                                "kind": "GCPMachineProviderSpec",
                                "machineType": "n1-standard-4",
                                "metadata": {
                                    "creationTimestamp": null
                                },
                                "networkInterfaces": [
                                    {
                                        "network": "ci-ln-jz1ylt2-72292-bqcd8-network",
                                        "subnetwork": "ci-ln-jz1ylt2-72292-bqcd8-worker-subnet"
                                    }
                                ],
                                "projectID": "openshift-gce-devel-ci",
                                "region": "us-central1",
                                "serviceAccounts": [
                                    {
                                        "email": "ci-ln-jz1ylt2-72292-bqcd8-w@openshift-gce-devel-ci.iam.gserviceaccount.com",
                                        "scopes": [
                                            "https://www.googleapis.com/auth/cloud-platform"
                                        ]
                                    }
                                ],
                                "tags": [
                                    "ci-ln-jz1ylt2-72292-bqcd8-worker"
                                ],
                                "userDataSecret": {
                                    "name": "worker-user-data"
                                },
                                "zone": "us-central1-c"
                            }
                        }
                    }
                }
            },
            "status": {
                "availableReplicas": 1,
                "fullyLabeledReplicas": 1,
                "observedGeneration": 1,
                "readyReplicas": 1,
                "replicas": 1
            }
        },
        {
            "apiVersion": "machine.openshift.io/v1beta1",
            "kind": "MachineSet",
            "metadata": {
                "annotations": {
                    "machine.openshift.io/memoryMb": "15360",
                    "machine.openshift.io/vCPU": "4"
                },
                "creationTimestamp": "2021-11-02T15:04:11Z",
                "generation": 1,
                "labels": {
                    "machine.openshift.io/cluster-api-cluster": "ci-ln-jz1ylt2-72292-bqcd8"
                },
                "name": "ci-ln-jz1ylt2-72292-bqcd8-worker-f",
                "namespace": "openshift-machine-api",
                "resourceVersion": "9412",
                "uid": "c5826d10-82a5-4db5-aa64-29c90a3e9349"
            },
            "spec": {
                "replicas": 0,
                "selector": {
                    "matchLabels": {
                        "machine.openshift.io/cluster-api-cluster": "ci-ln-jz1ylt2-72292-bqcd8",
                        "machine.openshift.io/cluster-api-machineset": "ci-ln-jz1ylt2-72292-bqcd8-worker-f"
                    }
                },
                "template": {
                    "metadata": {
                        "labels": {
                            "machine.openshift.io/cluster-api-cluster": "ci-ln-jz1ylt2-72292-bqcd8",
                            "machine.openshift.io/cluster-api-machine-role": "worker",
                            "machine.openshift.io/cluster-api-machine-type": "worker",
                            "machine.openshift.io/cluster-api-machineset": "ci-ln-jz1ylt2-72292-bqcd8-worker-f"
                        }
                    },
                    "spec": {
                        "metadata": {},
                        "providerSpec": {
                            "value": {
                                "apiVersion": "gcpprovider.openshift.io/v1beta1",
                                "canIPForward": false,
                                "credentialsSecret": {
                                    "name": "gcp-cloud-credentials"
                                },
                                "deletionProtection": false,
                                "disks": [
                                    {
                                        "autoDelete": true,
                                        "boot": true,
                                        "image": "projects/rhcos-cloud/global/images/rhcos-410-84-202110140201-0-gcp-x86-64",
                                        "labels": null,
                                        "sizeGb": 128,
                                        "type": "pd-ssd"
                                    }
                                ],
                                "kind": "GCPMachineProviderSpec",
                                "machineType": "n1-standard-4",
                                "metadata": {
                                    "creationTimestamp": null
                                },
                                "networkInterfaces": [
                                    {
                                        "network": "ci-ln-jz1ylt2-72292-bqcd8-network",
                                        "subnetwork": "ci-ln-jz1ylt2-72292-bqcd8-worker-subnet"
                                    }
                                ],
                                "projectID": "openshift-gce-devel-ci",
                                "region": "us-central1",
                                "serviceAccounts": [
                                    {
                                        "email": "ci-ln-jz1ylt2-72292-bqcd8-w@openshift-gce-devel-ci.iam.gserviceaccount.com",
                                        "scopes": [
                                            "https://www.googleapis.com/auth/cloud-platform"
                                        ]
                                    }
                                ],
                                "tags": [
                                    "ci-ln-jz1ylt2-72292-bqcd8-worker"
                                ],
                                "userDataSecret": {
                                    "name": "worker-user-data"
                                },
                                "zone": "us-central1-f"
                            }
                        }
                    }
                }
            },
            "status": {
                "observedGeneration": 1,
                "replicas": 0
            }
        }
    ],
    "kind": "List",
    "metadata": {
        "resourceVersion": "",
        "selfLink": ""
    }
}
EOF

jq_filter='[.items[] | select(.spec.template.spec.providerSpec.value.disks[0].encryptionKey.kmsKey.name != null) | .metadata.name]'

# Get filtered path. This will actually be read by the scan
filteredpath="$kube_apipath/$machineset_apipath#$(echo -n "$machineset_apipath$jq_filter" | sha256sum | awk '{print $1}')"

# populate filtered path with jq-filtered result
jq "$jq_filter" "$kube_apipath/$machineset_apipath" > "$filteredpath"