Put the foil on managed clusters with ACM-delivered security policies.
ACM Foil • Deploy • Validate • Concepts • Policy Reference
ACM Foil is inspired by, and built in collaboration with, Greg Procunier (gprocunier) and his Blastwall project. Blastwall demonstrates hardened fleet management for RHEL with IdM, with a path for bringing that same hardened disposition to OpenShift workloads. ACM Foil extends that model into ACM-driven OpenShift fleet management.
Use ACM Foil when you want GitOps and ACM to deliver stricter workload confinement, controlled cluster placement, and compliance evidence across selected OpenShift clusters. See Blastwall Workload Confinement for the benefits and adoption boundary.
Requirements:
- Red Hat Advanced Cluster Management
- ACM
OperatorPolicysupport on the hub and managed clusters - OpenShift GitOps / Argo CD on the ACM hub
- Managed OpenShift clusters with OLM and access to the Red Hat operator catalog
- Managed cluster label
spo=true
ACM Foil installs the Security Profiles Operator on selected managed clusters by using ACM OperatorPolicy. See Red Hat's Understanding the Security Profiles Operator docs for what SPO provides.
Deploy the Argo CD Application on the ACM hub:
oc apply -f apps/hub/argocd-application.yamlOpt in a managed cluster:
oc label managedcluster <cluster-name> spo=true --overwriteCheck Argo CD and ACM placement:
oc get applications.argoproj.io -n openshift-gitops spo-acm-policies-test
oc get policy,policyset,placement,placementbinding -n acm-spo-policies
oc get placementdecision -n acm-spo-policies -o yamlThe managed policies should report Compliant.
| PolicySet | Policies |
|---|---|
policyset-blastwall-test |
policy-spo-rawselinuxprofile-crd, policy-blastwall-v2-raw-profiles, policy-blastwall-v2-profile-usage, policy-blastwall-v2-runtime-bindings |
policyset-spo-test |
policy-install-spo-operator, policy-prevent-copy-fail-cve-ds |
The SPO policy set installs the Security Profiles Operator into openshift-security-profiles through the Red Hat operator catalog. The active placement still controls where this happens.
The Blastwall policy set includes an inform-only precondition policy that checks for the established RawSelinuxProfile CRD provided by SPO. The Blastwall rollout then applies raw profile resources, waits for status.usage, and applies SCC/RBAC bindings with status-derived SELinux types.
The Argo CD application keeps automated sync, pruning, and self-healing enabled so the hub state returns to the Git-defined policy set after manual drift.
The CVE mitigation policy deploys the Red Hat BPF LSM DaemonSet mitigation for CVE-2026-31431.
- Project Site - documentation home with deployment, validation, concepts, examples, and reference pages
- Policy Reference - active policies, resources created, remediation behavior, validation commands, and risks
- Troubleshooting - checks for Argo CD health, ACM placement, policy compliance, and missing SPO resources
| Path | Purpose |
|---|---|
apps/hub/argocd-application.yaml |
Argo CD Application applied to the ACM hub |
policies/base/ |
Active ACM Policies and PolicySets |
policies/overlays/test-spo-cluster-scoped/ |
Active overlay with namespace, placement, and binding resources |
examples/ |
Optional policies that are not deployed by default |
validation/ |
Local render and ACM placement checks |
docs/ |
Docusaurus documentation site |
