Rip out compensating-controls framework #359

Merged
eblume merged 2 commits from rip-out-compensating-controls into main 2026-05-22 21:08:55 -07:00
Owner

Summary

Removes the compensating-controls (CC) framework. Prowler and Kingfisher continue to run weekly and produce reports; the Prowler mutelist YAML files stay in place but no longer carry `CC: ` prefixes — each entry now just keeps a free-form `Description` of why it's muted.

The CC review cadence proved to be more process overhead than this single-operator homelab needed.

What changed

Deleted

  • `compensating-controls.yaml` — the CC registry
  • `mise-tasks/review-compensating-controls` — the staleness-review task
  • `docs/how-to/operations/review-compensating-controls.md`
  • `docs/how-to/operations/record-review-evidence.md` (was aspirational)
  • `docs/explanation/compliance-mute-categories.md` (proposed-future CC/NA/RA work)
  • 5 orphan `+review-cc-*` / `+compliance-mute-categories` changelog fragments

Modified

  • 6 mutelist YAML files: stripped `CC: .` prefix from every `Description` / `statement` field, kept the free-form text
  • `mise-tasks/review-compliance-reports`: removed CC mentions from docstrings, panel text, and the node-verification table title. Node-verification logic itself is unchanged.
  • `docs/reference/operations/security.md`: removed the "Compensating controls" section
  • `docs/how-to/operations/read-compliance-reports.md`: rewrote step 3 of "Acting on findings" to point at the mutelist YAML directly
  • `docs/changelog.d/prowler-iac-mutelist.infra.md`: rewrote to drop the "two new compensating controls" framing

What did not change

  • All Prowler manifests (cronjobs, RBAC, PVs, kustomization) — scans still run on the same schedule
  • The Kingfisher deployment
  • The trivy-shim in the Prowler container — that's about Trivy ignorefile plumbing, independent of the CC concept
  • The mutelist entries themselves — each `Resources` list is unchanged; only the prose of `Description` was edited
  • `CHANGELOG.md` — historical releases are left as-is

Test plan

  • Wait for human review before deploying — once merged, re-point ArgoCD: `argocd app set prowler --revision main && argocd app sync prowler` (no manifest changes besides the ConfigMap, so impact is limited to muted-finding descriptions in next week's report)
  • Confirm next weekly Prowler K8s CIS run (Sunday 3am) still completes and produces a report on sifaka
  • Confirm next weekly Prowler IaC run still honors `trivyignore.yaml` (the trivy shim is untouched but the ignorefile content was rewritten)
  • `mise run review-compliance-reports` — verify node-verification block still runs and prints the renamed table title
## Summary Removes the compensating-controls (CC) framework. Prowler and Kingfisher continue to run weekly and produce reports; the Prowler mutelist YAML files stay in place but no longer carry \`CC: <id>\` prefixes — each entry now just keeps a free-form \`Description\` of why it's muted. The CC review cadence proved to be more process overhead than this single-operator homelab needed. ## What changed **Deleted** - \`compensating-controls.yaml\` — the CC registry - \`mise-tasks/review-compensating-controls\` — the staleness-review task - \`docs/how-to/operations/review-compensating-controls.md\` - \`docs/how-to/operations/record-review-evidence.md\` (was aspirational) - \`docs/explanation/compliance-mute-categories.md\` (proposed-future CC/NA/RA work) - 5 orphan \`+review-cc-*\` / \`+compliance-mute-categories\` changelog fragments **Modified** - 6 mutelist YAML files: stripped \`CC: <id>.\` prefix from every \`Description\` / \`statement\` field, kept the free-form text - \`mise-tasks/review-compliance-reports\`: removed CC mentions from docstrings, panel text, and the node-verification table title. Node-verification logic itself is unchanged. - \`docs/reference/operations/security.md\`: removed the "Compensating controls" section - \`docs/how-to/operations/read-compliance-reports.md\`: rewrote step 3 of "Acting on findings" to point at the mutelist YAML directly - \`docs/changelog.d/prowler-iac-mutelist.infra.md\`: rewrote to drop the "two new compensating controls" framing ## What did not change - All Prowler manifests (cronjobs, RBAC, PVs, kustomization) — scans still run on the same schedule - The Kingfisher deployment - The trivy-shim in the Prowler container — that's about Trivy ignorefile plumbing, independent of the CC concept - The mutelist entries themselves — each \`Resources\` list is unchanged; only the prose of \`Description\` was edited - \`CHANGELOG.md\` — historical releases are left as-is ## Test plan - [ ] Wait for human review before deploying — once merged, re-point ArgoCD: \`argocd app set prowler --revision main && argocd app sync prowler\` (no manifest changes besides the ConfigMap, so impact is limited to muted-finding descriptions in next week's report) - [ ] Confirm next weekly Prowler K8s CIS run (Sunday 3am) still completes and produces a report on sifaka - [ ] Confirm next weekly Prowler IaC run still honors \`trivyignore.yaml\` (the trivy shim is untouched but the ignorefile content was rewritten) - [ ] \`mise run review-compliance-reports\` — verify node-verification block still runs and prints the renamed table title
Deletes the CC how-to and explanation docs, and the orphan changelog
fragments describing CC reviews. Updates security.md and
read-compliance-reports.md to describe muting in terms of the mutelist
files only. Adds the branch changelog fragment.

Mutelist YAML files, the Prowler CronJobs, and the
review-compliance-reports task all stay — they're updated in the next
commit.
Strips the "CC: <id>." prefix from every Description field in the
Prowler mutelist YAML files (and the statement field in trivyignore).
Each entry's free-form description now stands on its own.

Deletes compensating-controls.yaml (the CC registry) and the
review-compensating-controls mise task. Updates
review-compliance-reports to drop CC references from docstrings,
panel text, and table titles. Node verification logic is unchanged.
eblume merged commit ee51bcafb4 into main 2026-05-22 21:08:55 -07:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
eblume/blumeops!359
No description provided.