| name | nist-compliance-agent |
| description | Deploys OPA Gatekeeper policies for NIST SP 800-53 compliance following ch-stark/gatekeeper-examples patterns. Adds NIST control labels and annotations to all constraints for compliance tracking. |
| allowed-tools | ["mcp__kubernetes__configuration_view","mcp__kubernetes__namespaces_list","mcp__kubernetes__pods_list","mcp__kubernetes__resources_list","mcp__kubernetes__resources_get","WebSearch","WebFetch","Read","Write","Bash"] |
NIST Compliance Agent
Deploys OPA Gatekeeper with NIST SP 800-53 labeled constraints following ch-stark/gatekeeper-examples patterns.
Workflow Overview
This skill follows the ch-stark/gatekeeper-examples pattern with three levels:
LEVEL 1 - Infrastructure:
- policy-install-gatekeeper
- policy-check-gatekeeper
- policy-configure-gatekeeper
LEVEL 2 - Templates:
- policy-gatekeeperlibrary (deploys ConstraintTemplates)
LEVEL 3 - Constraints:
- policy-nist-sc-controls (with NIST labels)
- policy-nist-si-controls (with NIST labels)
- policy-nist-cm-controls (with NIST labels)
- policy-nist-ac-controls (with NIST labels)
Each level depends on the previous level being Compliant before proceeding.
Step 1: Cluster Discovery
1.1 Get Cluster Version
Use: mcp__kubernetes__resources_get
Parameters: apiVersion=config.openshift.io/v1, kind=ClusterVersion, name=version
1.2 Check Gatekeeper Status
Use: mcp__kubernetes__namespaces_list
Check: "gatekeeper-system" or "openshift-gatekeeper-system" exists
1.3 Load NIST Mappings
Use references/NIST_800_53_CATALOG.md for control-to-policy mappings and constraint examples.
Step 2: SCC Analysis (OpenShift Only)
2.1 Get SCCs and Pod Distribution
Use: mcp__kubernetes__resources_list
Parameters: apiVersion=security.openshift.io/v1, kind=SecurityContextConstraints
Use: mcp__kubernetes__pods_list
Extract: metadata.annotations["openshift.io/scc"]
2.2 Calculate Coverage
Use the mapping in references/NIST_800_53_CATALOG.md section "Complete Mapping Table":
- ≥95% SCC coverage → SKIP (redundant)
- <95% SCC coverage → INCLUDE (gap-filling)
- 0% SCC coverage → CRITICAL (must include)
Step 3: Create Output Directory
TRACE_ID=$(python3 skills/nist-compliance-agent/scripts/get_trace_id.py 2>/dev/null || echo "no-trace")
OUTPUT_DIR="skills/nist-compliance-agent/assets/${TRACE_ID}"
mkdir -p ${OUTPUT_DIR}/{gatekeeperinstall,gatekeeperchecks,gatekeeperconfig,gatekeeperlibrary,nist-constraints/{ac,cm,sc,si},placements}
cd ${OUTPUT_DIR}
Step 4: Download ch-stark Manifests
curl -sL https://raw.githubusercontent.com/ch-stark/gatekeeper-examples/main/gatekeeperinstall/gatekeepersubscription.yaml \
-o gatekeeperinstall/gatekeepersubscription.yaml
curl -sL https://raw.githubusercontent.com/ch-stark/gatekeeper-examples/main/gatekeeperchecks/gatekeeper-ready.yaml \
-o gatekeeperchecks/gatekeeper-ready.yaml
curl -sL https://raw.githubusercontent.com/ch-stark/gatekeeper-examples/main/gatekeeperconfig/config.yaml \
-o gatekeeperconfig/config.yaml
cat <<'EOF' > gatekeeperlibrary/kustomization.yaml
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- https://github.com/open-policy-agent/gatekeeper-library/library
EOF
Step 5: Generate NIST-Labeled Constraints
5.1 NIST Label Schema
All constraints MUST include:
Labels (for filtering):
labels:
nist-family: "SC"
nist-control: "SC-39"
nist-control-name: "process-isolation"
compliance-framework: "nist-800-53-r5"
severity: "critical"
Annotations (for reporting):
annotations:
nist.compliance/control: "SC-39"
nist.compliance/control-name: "Process Isolation"
nist.compliance/description: "Maintain separate execution domain for each process"
policy.open-cluster-management.io/standards: "NIST SP 800-53 Rev. 5"
policy.open-cluster-management.io/categories: "System and Communications Protection"
policy.open-cluster-management.io/controls: "SC-39"
5.2 Generate Constraints
Use references/NIST_800_53_CATALOG.md section "NIST-to-Gatekeeper Mapping Examples" for constraint templates.
Generate constraints organized by NIST family:
nist-constraints/ac/ - Access Control (AC-2, AC-3, AC-6)
nist-constraints/cm/ - Configuration Management (CM-2, CM-7)
nist-constraints/sc/ - System Protection (SC-7, SC-8, SC-39)
nist-constraints/si/ - System Integrity (SI-7)
Priority order (from references/NIST_800_53_CATALOG.md):
- CRITICAL (0% SCC):
read-only-root-filesystem, seccompv2, proc-mount
- ALWAYS INCLUDE:
requiredlabels, allowedrepos, imagedigests, httpsonly
- CONDITIONAL: Check SCC coverage before including
Step 6: Generate policyGenerator.yaml
Follow references/POLICYGENERATOR_FORMAT.md and ch-stark pattern:
apiVersion: policy.open-cluster-management.io/v1
kind: PolicyGenerator
metadata:
name: nist-gatekeeper-compliance
placementBindingDefaults:
name: nist-gatekeeper-binding
policyDefaults:
namespace: policies
placement:
placementName: gatekeeper-placement
remediationAction: inform
informGatekeeperPolicies: false
pruneObjectBehavior: DeleteIfCreated
ignorePending: true
policies:
- name: policy-install-gatekeeper
manifests:
- path: gatekeeperinstall
remediationAction: enforce
- name: policy-check-gatekeeper
manifests:
- path: gatekeeperchecks
remediationAction: enforce
dependencies:
- name: "policy-install-gatekeeper"
compliance: "Compliant"
- name: policy-configure-gatekeeper
manifests:
- path: gatekeeperconfig
remediationAction: enforce
dependencies:
- name: "policy-check-gatekeeper"
compliance: "Compliant"
- name: policy-gatekeeperlibrary
manifests:
- path: gatekeeperlibrary
remediationAction: enforce
dependencies:
- name: "policy-check-gatekeeper"
compliance: "Compliant"
ignorePending: true
- name: policy-nist-sc-controls
manifests:
- path: nist-constraints/sc
dependencies:
- name: "policy-gatekeeperlibrary"
compliance: "Compliant"
policyAnnotations:
policy.open-cluster-management.io/standards: "NIST SP 800-53 Rev. 5"
policy.open-cluster-management.io/controls: "SC-39,SC-8"
- name: policy-nist-si-controls
manifests:
- path: nist-constraints/si
dependencies:
- name: "policy-gatekeeperlibrary"
compliance: "Compliant"
policyAnnotations:
policy.open-cluster-management.io/standards: "NIST SP 800-53 Rev. 5"
policy.open-cluster-management.io/controls: "SI-7"
- name: policy-nist-cm-controls
manifests:
- path: nist-constraints/cm
dependencies:
- name: "policy-gatekeeperlibrary"
compliance: "Compliant"
policyAnnotations:
policy.open-cluster-management.io/standards: "NIST SP 800-53 Rev. 5"
policy.open-cluster-management.io/controls: "CM-2"
- name: policy-nist-ac-controls
manifests:
- path: nist-constraints/ac
dependencies:
- name: "policy-gatekeeperlibrary"
compliance: "Compliant"
policyAnnotations:
policy.open-cluster-management.io/standards: "NIST SP 800-53 Rev. 5"
policy.open-cluster-management.io/controls: "AC-6"
Step 7: Generate Supporting Files
kustomization.yaml
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
generators:
- policyGenerator.yaml
placements/placements.yaml
See references/POLICYGENERATOR_FORMAT.md for placement templates.
Step 8: Deploy
kubectl create namespace policies --dry-run=client -o yaml | kubectl apply -f -
kubectl apply -f placements/placements.yaml
kubectl label managedcluster <cluster-name> gatekeeper=true compliance=nist-moderate environment=staging
kustomize build --enable-alpha-plugins . | kubectl apply -n policies -f -
Step 9: Verify NIST Labels
kubectl get constraints -o custom-columns="NAME:.metadata.name,NIST-CONTROL:.metadata.labels.nist-control,SEVERITY:.metadata.labels.severity"
kubectl get constraints -l nist-control=SC-39
kubectl get constraints -l severity=critical
Output Structure
assets/${TRACE_ID}/
├── kustomization.yaml
├── policyGenerator.yaml
├── gatekeeperinstall/
├── gatekeeperchecks/
├── gatekeeperconfig/
├── gatekeeperlibrary/
├── nist-constraints/
│ ├── ac/
│ ├── cm/
│ ├── sc/
│ └── si/
├── placements/
└── NIST_COMPLIANCE_REPORT.md
Trigger Phrases
- "Set up NIST 800-53 compliance with Gatekeeper"
- "Deploy gatekeeper-library with NIST labels"
- "Follow ch-stark pattern with NIST compliance"
Reference Files
references/NIST_800_53_CATALOG.md
- NIST control mappings
- Constraint examples with NIST labels
- SCC coverage analysis
references/ACM_GATEKEEPER_EXAMPLES.md
- ch-stark integration patterns
references/POLICYGENERATOR_FORMAT.md
- PolicyGenerator structure
- Placement templates