Skip to content

Commit 34fdc98

Browse files
authored
Update cnf-best-practices-image-standards.adoc
1 parent 0ba28a7 commit 34fdc98

File tree

1 file changed

+2
-5
lines changed

1 file changed

+2
-5
lines changed

modules/cnf-best-practices-image-standards.adoc

Lines changed: 2 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,25 +1,22 @@
1-
[id="cnf-best-practices-image-standards"]
1+
[id="k8s-best-practices-image-standards"]
22
= Image standards
33

44
It is recommended that container images be built utilizing Red Hat's Universal Base Image as they will have a solid security baseline as well as support from Red Hat.
55

6-
Vendors must satisfy 3 requirements related to maintaining proper workload isolation in a containerized environment:
6+
Must satisfy 3 requirements related to maintaining proper workload isolation in a containerized environment:
77

8-
.VCP CNF requirement
98
[IMPORTANT]
109
====
1110
Containerized workloads should work with a restricted SCC unless an exception is given
1211
====
1312

14-
.VCP CNF requirement
1513
[IMPORTANT]
1614
====
1715
Containerized workloads should work with Red Hat’s default SELinux context. This is meant to forbid all changes to both primary config files (SCC, SEL) and the many related files referenced by these primary files. All security configuration files must be unchanged from the vendor’s released version.
1816
1917
See test cases link:https://github.com/test-network-function/cnf-certification-test/blob/main/CATALOG.md#platform-alteration-base-image[platform-alteration-base-image], link:https://github.com/test-network-function/cnf-certification-test/blob/main/CATALOG.md#platform-alteration-is-selinux-enforcing[platform-alteration-is-selinux-enforcing]
2018
====
2119

22-
.VCP CNF requirement
2320
[IMPORTANT]
2421
====
2522
The container image must be secure.

0 commit comments

Comments
 (0)