# Nist Compliance Agent

> Deploys OPA Gatekeeper policies for NIST SP 800-53 compliance following ch-stark/gatekeeper-examples patterns. Adds NIST control labels and annotations to all constraints for compliance tracking.

- Skill: `redhat-et/nist-compliance-agent` (Agent Skill, multi-file: 6 files)
- Install (CLI): `npx skillmds@latest add redhat-et/nist-compliance-agent`
- Raw SKILL.md: https://api.skillmd.com/api/skills/redhat-et/nist-compliance-agent/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: AI & ML
- Author: redhat-et (https://skillmd.com/u/redhat-et)
- Updated: 2026-09-22
- Page: https://skillmd.com/skills/redhat-et/nist-compliance-agent

---


# NIST Compliance Agent

Deploys OPA Gatekeeper with **NIST SP 800-53 labeled constraints** following [ch-stark/gatekeeper-examples](https://github.com/ch-stark/gatekeeper-examples) patterns.

## Workflow Overview

This skill follows the ch-stark/gatekeeper-examples pattern with three levels:

LEVEL 1 - Infrastructure:
  - policy-install-gatekeeper
  - policy-check-gatekeeper
  - policy-configure-gatekeeper

LEVEL 2 - Templates:
  - policy-gatekeeperlibrary (deploys ConstraintTemplates)

LEVEL 3 - Constraints:
  - policy-nist-sc-controls (with NIST labels)
  - policy-nist-si-controls (with NIST labels)
  - policy-nist-cm-controls (with NIST labels)
  - policy-nist-ac-controls (with NIST labels)

Each level depends on the previous level being Compliant before proceeding.

---

## Step 1: Cluster Discovery

### 1.1 Get Cluster Version
```
Use: mcp__kubernetes__resources_get
Parameters: apiVersion=config.openshift.io/v1, kind=ClusterVersion, name=version
```

### 1.2 Check Gatekeeper Status
```
Use: mcp__kubernetes__namespaces_list
Check: "gatekeeper-system" or "openshift-gatekeeper-system" exists
```

### 1.3 Load NIST Mappings
Use `references/NIST_800_53_CATALOG.md` for control-to-policy mappings and constraint examples.

---

## Step 2: SCC Analysis (OpenShift Only)

### 2.1 Get SCCs and Pod Distribution
```
Use: mcp__kubernetes__resources_list
Parameters: apiVersion=security.openshift.io/v1, kind=SecurityContextConstraints
```

```
Use: mcp__kubernetes__pods_list
Extract: metadata.annotations["openshift.io/scc"]
```

### 2.2 Calculate Coverage

Use the mapping in `references/NIST_800_53_CATALOG.md` section "Complete Mapping Table":
- **≥95% SCC coverage** → SKIP (redundant)
- **<95% SCC coverage** → INCLUDE (gap-filling)
- **0% SCC coverage** → CRITICAL (must include)

---

## Step 3: Create Output Directory

```bash
TRACE_ID=$(python3 skills/nist-compliance-agent/scripts/get_trace_id.py 2>/dev/null || echo "no-trace")
OUTPUT_DIR="skills/nist-compliance-agent/assets/${TRACE_ID}"
mkdir -p ${OUTPUT_DIR}/{gatekeeperinstall,gatekeeperchecks,gatekeeperconfig,gatekeeperlibrary,nist-constraints/{ac,cm,sc,si},placements}
cd ${OUTPUT_DIR}
```

---

## Step 4: Download ch-stark Manifests

```bash
# Level 1: Gatekeeper Installation
curl -sL https://raw.githubusercontent.com/ch-stark/gatekeeper-examples/main/gatekeeperinstall/gatekeepersubscription.yaml \
  -o gatekeeperinstall/gatekeepersubscription.yaml

# Level 1: Gatekeeper Health Checks
curl -sL https://raw.githubusercontent.com/ch-stark/gatekeeper-examples/main/gatekeeperchecks/gatekeeper-ready.yaml \
  -o gatekeeperchecks/gatekeeper-ready.yaml

# Level 1: Gatekeeper Configuration
curl -sL https://raw.githubusercontent.com/ch-stark/gatekeeper-examples/main/gatekeeperconfig/config.yaml \
  -o gatekeeperconfig/config.yaml

# Level 2: Gatekeeper Library
cat <<'EOF' > gatekeeperlibrary/kustomization.yaml
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
  - https://github.com/open-policy-agent/gatekeeper-library/library
EOF
```

---

## Step 5: Generate NIST-Labeled Constraints

### 5.1 NIST Label Schema

All constraints MUST include:

**Labels** (for filtering):
```yaml
labels:
  nist-family: "SC"                        # AC, AU, CM, SC, SI
  nist-control: "SC-39"                    # Primary control ID
  nist-control-name: "process-isolation"   # Kebab-case name
  compliance-framework: "nist-800-53-r5"
  severity: "critical"                     # critical, high, medium, low
```

**Annotations** (for reporting):
```yaml
annotations:
  nist.compliance/control: "SC-39"
  nist.compliance/control-name: "Process Isolation"
  nist.compliance/description: "Maintain separate execution domain for each process"
  policy.open-cluster-management.io/standards: "NIST SP 800-53 Rev. 5"
  policy.open-cluster-management.io/categories: "System and Communications Protection"
  policy.open-cluster-management.io/controls: "SC-39"
```

### 5.2 Generate Constraints

Use `references/NIST_800_53_CATALOG.md` section "NIST-to-Gatekeeper Mapping Examples" for constraint templates.

Generate constraints organized by NIST family:
- `nist-constraints/ac/` - Access Control (AC-2, AC-3, AC-6)
- `nist-constraints/cm/` - Configuration Management (CM-2, CM-7)
- `nist-constraints/sc/` - System Protection (SC-7, SC-8, SC-39)
- `nist-constraints/si/` - System Integrity (SI-7)

**Priority order** (from `references/NIST_800_53_CATALOG.md`):
1. **CRITICAL (0% SCC)**: `read-only-root-filesystem`, `seccompv2`, `proc-mount`
2. **ALWAYS INCLUDE**: `requiredlabels`, `allowedrepos`, `imagedigests`, `httpsonly`
3. **CONDITIONAL**: Check SCC coverage before including

---

## Step 6: Generate policyGenerator.yaml

Follow `references/POLICYGENERATOR_FORMAT.md` and ch-stark pattern:

```yaml
apiVersion: policy.open-cluster-management.io/v1
kind: PolicyGenerator
metadata:
  name: nist-gatekeeper-compliance
placementBindingDefaults:
  name: nist-gatekeeper-binding
policyDefaults:
  namespace: policies
  placement:
    placementName: gatekeeper-placement
  remediationAction: inform
  informGatekeeperPolicies: false
  pruneObjectBehavior: DeleteIfCreated
  ignorePending: true

policies:
  # LEVEL 1: Infrastructure (enforce)
  - name: policy-install-gatekeeper
    manifests:
      - path: gatekeeperinstall
    remediationAction: enforce

  - name: policy-check-gatekeeper
    manifests:
      - path: gatekeeperchecks
    remediationAction: enforce
    dependencies:
      - name: "policy-install-gatekeeper"
        compliance: "Compliant"

  - name: policy-configure-gatekeeper
    manifests:
      - path: gatekeeperconfig
    remediationAction: enforce
    dependencies:
      - name: "policy-check-gatekeeper"
        compliance: "Compliant"

  # LEVEL 2: ConstraintTemplates
  - name: policy-gatekeeperlibrary
    manifests:
      - path: gatekeeperlibrary
    remediationAction: enforce
    dependencies:
      - name: "policy-check-gatekeeper"
        compliance: "Compliant"
    ignorePending: true

  # LEVEL 3: NIST Constraints (by family)
  - name: policy-nist-sc-controls
    manifests:
      - path: nist-constraints/sc
    dependencies:
      - name: "policy-gatekeeperlibrary"
        compliance: "Compliant"
    policyAnnotations:
      policy.open-cluster-management.io/standards: "NIST SP 800-53 Rev. 5"
      policy.open-cluster-management.io/controls: "SC-39,SC-8"

  - name: policy-nist-si-controls
    manifests:
      - path: nist-constraints/si
    dependencies:
      - name: "policy-gatekeeperlibrary"
        compliance: "Compliant"
    policyAnnotations:
      policy.open-cluster-management.io/standards: "NIST SP 800-53 Rev. 5"
      policy.open-cluster-management.io/controls: "SI-7"

  - name: policy-nist-cm-controls
    manifests:
      - path: nist-constraints/cm
    dependencies:
      - name: "policy-gatekeeperlibrary"
        compliance: "Compliant"
    policyAnnotations:
      policy.open-cluster-management.io/standards: "NIST SP 800-53 Rev. 5"
      policy.open-cluster-management.io/controls: "CM-2"

  - name: policy-nist-ac-controls
    manifests:
      - path: nist-constraints/ac
    dependencies:
      - name: "policy-gatekeeperlibrary"
        compliance: "Compliant"
    policyAnnotations:
      policy.open-cluster-management.io/standards: "NIST SP 800-53 Rev. 5"
      policy.open-cluster-management.io/controls: "AC-6"
```

---

## Step 7: Generate Supporting Files

### kustomization.yaml
```yaml
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
generators:
  - policyGenerator.yaml
```

### placements/placements.yaml
See `references/POLICYGENERATOR_FORMAT.md` for placement templates.

---

## Step 8: Deploy

```bash
# Create namespace
kubectl create namespace policies --dry-run=client -o yaml | kubectl apply -f -

# Apply placements
kubectl apply -f placements/placements.yaml

# Label clusters
kubectl label managedcluster <cluster-name> gatekeeper=true compliance=nist-moderate environment=staging

# Build and apply
kustomize build --enable-alpha-plugins . | kubectl apply -n policies -f -
```

---

## Step 9: Verify NIST Labels

```bash
# List constraints with NIST labels
kubectl get constraints -o custom-columns="NAME:.metadata.name,NIST-CONTROL:.metadata.labels.nist-control,SEVERITY:.metadata.labels.severity"

# Query by NIST control
kubectl get constraints -l nist-control=SC-39

# Query by severity
kubectl get constraints -l severity=critical
```

---

## Output Structure

```
assets/${TRACE_ID}/
├── kustomization.yaml
├── policyGenerator.yaml
├── gatekeeperinstall/
├── gatekeeperchecks/
├── gatekeeperconfig/
├── gatekeeperlibrary/
├── nist-constraints/
│   ├── ac/
│   ├── cm/
│   ├── sc/
│   └── si/
├── placements/
└── NIST_COMPLIANCE_REPORT.md
```

---

## Trigger Phrases

- "Set up NIST 800-53 compliance with Gatekeeper"
- "Deploy gatekeeper-library with NIST labels"
- "Follow ch-stark pattern with NIST compliance"

---

## Reference Files

references/NIST_800_53_CATALOG.md
  - NIST control mappings
  - Constraint examples with NIST labels
  - SCC coverage analysis

references/ACM_GATEKEEPER_EXAMPLES.md
  - ch-stark integration patterns

references/POLICYGENERATOR_FORMAT.md
  - PolicyGenerator structure
  - Placement templates

