| name | bsi-compliance-agent |
| description | Deploys OPA Gatekeeper policies for BSI IT-Grundschutz compliance (SYS.1.6 Containerisation, APP.4.4 Kubernetes) following ch-stark patterns with BSI requirement labels. |
| allowed-tools | ["mcp__kubernetes__configuration_view","mcp__kubernetes__namespaces_list","mcp__kubernetes__pods_list","mcp__kubernetes__resources_list","mcp__kubernetes__resources_get","WebFetch","Read","Write","Bash"] |
BSI Compliance Agent
Deploys OPA Gatekeeper policies for BSI IT-Grundschutz compliance on OpenShift clusters. Covers SYS.1.6 (Containerisation) and APP.4.4 (Kubernetes) modules with BSI requirement labels.
Reference: https://access.redhat.com/articles/7045834
Step 1: Cluster Discovery
1.1 Get Cluster Version
Use: mcp__kubernetes__resources_get
Parameters: apiVersion=config.openshift.io/v1, kind=ClusterVersion, name=version
1.2 Check Gatekeeper Status
Use: mcp__kubernetes__namespaces_list
Check: "gatekeeper-system" or "openshift-gatekeeper-system" exists
1.3 Load BSI Mappings
Use references/BSI_IT_GRUNDSCHUTZ.md for requirement-to-policy mappings.
Step 2: SCC Analysis
2.1 Get SCCs
Use: mcp__kubernetes__resources_list
Parameters: apiVersion=security.openshift.io/v1, kind=SecurityContextConstraints
2.2 Get Pod SCC Distribution
Use: mcp__kubernetes__pods_list
Extract: metadata.annotations["openshift.io/scc"]
Calculate: percentage of pods using each SCC
2.3 Calculate Coverage
Use mapping from references/BSI_IT_GRUNDSCHUTZ.md:
- 95%+ restricted-v2: SKIP privileged, capabilities, host-namespace policies
- <95%: INCLUDE these policies
- 0% coverage: CRITICAL GAP (always include)
Step 3: Create Output Directory
TRACE_ID=$(python3 skills/bsi-compliance-agent/scripts/get_trace_id.py 2>/dev/null || echo "no-trace")
OUTPUT_DIR="skills/bsi-compliance-agent/assets/${TRACE_ID}"
mkdir -p ${OUTPUT_DIR}/{gatekeeperinstall,gatekeeperchecks,gatekeeperconfig,gatekeeperlibrary,bsi-constraints/{sys16,app44},placements}
cd ${OUTPUT_DIR}
Step 4: Download ch-stark Manifests
curl -sL https://raw.githubusercontent.com/ch-stark/gatekeeper-examples/main/gatekeeperinstall/gatekeepersubscription.yaml \
-o gatekeeperinstall/gatekeepersubscription.yaml
curl -sL https://raw.githubusercontent.com/ch-stark/gatekeeper-examples/main/gatekeeperchecks/gatekeeper-ready.yaml \
-o gatekeeperchecks/gatekeeper-ready.yaml
curl -sL https://raw.githubusercontent.com/ch-stark/gatekeeper-examples/main/gatekeeperconfig/config.yaml \
-o gatekeeperconfig/config.yaml
cat <<'EOF' > gatekeeperlibrary/kustomization.yaml
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- https://github.com/open-policy-agent/gatekeeper-library/library
EOF
Step 5: Generate BSI-Labeled Constraints
5.1 BSI Label Schema
All constraints must include:
Labels:
bsi-module: "SYS.1.6" or "APP.4.4"
bsi-requirement: "A11"
bsi-requirement-name: "resource-limits"
compliance-framework: "bsi-it-grundschutz"
severity: "critical" or "high" or "medium"
Annotations:
bsi.compliance/module: "SYS.1.6"
bsi.compliance/requirement: "A11"
bsi.compliance/requirement-name: "Configuring Container Resources"
bsi.compliance/level: "basic" or "elevated"
policy.open-cluster-management.io/standards: "BSI IT-Grundschutz"
policy.open-cluster-management.io/controls: "SYS.1.6.A11"
5.2 Generate Constraints by BSI Module
Use references/BSI_IT_GRUNDSCHUTZ.md for constraint examples.
SYS.1.6 Containerisation (bsi-constraints/sys16/):
- bsi-sys16-a11-resource-limits.yaml (ALWAYS INCLUDE)
- bsi-sys16-a15-readonly-rootfs.yaml (CRITICAL - ALWAYS INCLUDE)
APP.4.4 Kubernetes (bsi-constraints/app44/):
- bsi-app44-a9-allowed-registries.yaml (ALWAYS INCLUDE)
- bsi-app44-a9-image-digests.yaml (ALWAYS INCLUDE)
- bsi-app44-a10-required-labels.yaml (ALWAYS INCLUDE)
5.3 Priority Order
- CRITICAL (0% SCC): k8spspreadonlyrootfilesystem (SYS.1.6.A15)
- ALWAYS INCLUDE: resource limits, allowed repos, image digests, required labels
- CONDITIONAL: Check SCC coverage before including
Step 6: Generate policyGenerator.yaml
apiVersion: policy.open-cluster-management.io/v1
kind: PolicyGenerator
metadata:
name: bsi-it-grundschutz-compliance
placementBindingDefaults:
name: bsi-compliance-binding
policyDefaults:
namespace: policies
placement:
placementName: bsi-placement
remediationAction: inform
informGatekeeperPolicies: false
pruneObjectBehavior: DeleteIfCreated
ignorePending: true
policies:
- name: policy-install-gatekeeper
manifests:
- path: gatekeeperinstall
remediationAction: enforce
- name: policy-check-gatekeeper
manifests:
- path: gatekeeperchecks
remediationAction: enforce
dependencies:
- name: "policy-install-gatekeeper"
compliance: "Compliant"
- name: policy-configure-gatekeeper
manifests:
- path: gatekeeperconfig
remediationAction: enforce
dependencies:
- name: "policy-check-gatekeeper"
compliance: "Compliant"
- name: policy-gatekeeperlibrary
manifests:
- path: gatekeeperlibrary
remediationAction: enforce
dependencies:
- name: "policy-check-gatekeeper"
compliance: "Compliant"
ignorePending: true
- name: policy-bsi-sys16-containerisation
manifests:
- path: bsi-constraints/sys16
dependencies:
- name: "policy-gatekeeperlibrary"
compliance: "Compliant"
policyAnnotations:
policy.open-cluster-management.io/standards: "BSI IT-Grundschutz"
policy.open-cluster-management.io/categories: "Containerisation"
policy.open-cluster-management.io/controls: "SYS.1.6.A11,SYS.1.6.A15"
- name: policy-bsi-app44-kubernetes
manifests:
- path: bsi-constraints/app44
dependencies:
- name: "policy-gatekeeperlibrary"
compliance: "Compliant"
policyAnnotations:
policy.open-cluster-management.io/standards: "BSI IT-Grundschutz"
policy.open-cluster-management.io/categories: "Kubernetes"
policy.open-cluster-management.io/controls: "APP.4.4.A9,APP.4.4.A10"
Step 7: Generate kustomization.yaml
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
generators:
- policyGenerator.yaml
Step 8: Generate Placements
apiVersion: cluster.open-cluster-management.io/v1beta1
kind: Placement
metadata:
name: bsi-placement
namespace: policies
spec:
predicates:
- requiredClusterSelector:
labelSelector:
matchExpressions:
- key: vendor
operator: In
values:
- OpenShift
- key: compliance
operator: In
values:
- bsi-it-grundschutz
Step 9: Deploy
kubectl create namespace policies --dry-run=client -o yaml | kubectl apply -f -
kubectl apply -f placements/
kubectl label managedcluster <cluster-name> compliance=bsi-it-grundschutz
kustomize build --enable-alpha-plugins . | kubectl apply -n policies -f -
Step 10: Verify BSI Labels
kubectl get constraints -l compliance-framework=bsi-it-grundschutz
kubectl get constraints -l bsi-module=SYS.1.6
kubectl get constraints -l bsi-module=APP.4.4
kubectl get constraints -l bsi-requirement=A15
kubectl get constraints -l severity=critical
Step 11: User Feedback
Ask user: "Any changes needed to the generated files?"
If user provides feedback:
- Identify which file needs changes
- Make the requested changes
- Show updated file
- Ask again until user confirms
Output Structure
assets/${TRACE_ID}/
├── kustomization.yaml
├── policyGenerator.yaml
├── gatekeeperinstall/
├── gatekeeperchecks/
├── gatekeeperconfig/
├── gatekeeperlibrary/
├── bsi-constraints/
│ ├── sys16/
│ │ ├── bsi-sys16-a11-resource-limits.yaml
│ │ └── bsi-sys16-a15-readonly-rootfs.yaml
│ └── app44/
│ ├── bsi-app44-a9-allowed-registries.yaml
│ ├── bsi-app44-a9-image-digests.yaml
│ └── bsi-app44-a10-required-labels.yaml
├── placements/
└── BSI_COMPLIANCE_REPORT.md
BSI Requirement to Constraint Mapping
SYS.1.6 Containerisation:
A11 (Resource limits): k8scontainerlimits - ALWAYS INCLUDE
A12 (No privileged): k8spspprivileged - SKIP (SCC 95%)
A13 (Drop capabilities): k8spspcapabilities - SKIP (SCC 95%)
A14 (Network isolation): k8srequiredlabels - ALWAYS INCLUDE
A15 (Read-only FS): k8spspreadonlyrootfilesystem - CRITICAL GAP
A16 (No host resources): k8spsphostnamespace - SKIP (SCC 95%)
APP.4.4 Kubernetes:
A9 (Secure images): k8sallowedrepos, k8simageDigests - ALWAYS INCLUDE
A10 (Secure config): k8srequiredlabels, k8srequiredannotations - ALWAYS INCLUDE
A11 (Protect nodes): k8spsphostnamespace - SKIP (SCC 95%)
Reference Files
references/BSI_IT_GRUNDSCHUTZ.md
- BSI module mappings (SYS.1.6, APP.4.4)
- Requirement-to-policy mappings
- SCC coverage analysis
- BSI-labeled constraint examples
Trigger Phrases
- "Make my cluster BSI compliant"
- "Deploy BSI IT-Grundschutz policies"
- "Set up BSI compliance for OpenShift"
- "Apply German security standards to my cluster"
When to Use This Skill
Use for:
- BSI IT-Grundschutz compliance
- German federal security requirements
- SYS.1.6 and APP.4.4 module implementation
Do NOT use for:
- NIST 800-53 compliance -> use rhacm-unified-policy-agent
- Custom policy requirements -> use custom-rego-policy-generator