Chef Ideas

We believe that the best way to build software is to do it in close collaboration with the people who use it. We invite you to submit your ideas using the form below. Please be sure to include the problem for which you are solving and the benefits of implementing the idea.

We do our best to implement as many Ideas as we can. Our Product team will evaluate all submitted ideas in a timely manner and will disposition each into one of the following categories: will integrate into the product roadmap, further research is needed, unlikely to implement.

Thanks for collaborating with us!

Waiver files included in an InSpec profile automatically picked up

I would like to build a overlay profile that leverages a predefined InSpec profile. This can be a generic profile that can be build on CIS benchmarks / STIGs or other security standards. As the base profile does not hold any state which is related to a specific custom environment, the reason for creating an overlay is to provide these as part of the configurable inputs. So far nothing new and this is currently supported by Chef.

In addition, I would also like to include a waiver file as a configurable input inside the profile and when I execute "inspec exec <profile_name>" I would like for this waiver file to be automatically be picked up. This can help maintain waiver files specific to a platform together with the profile. This functionality should apply to the chef-client as well which can report to automate with the waived controls.

  • Alex
  • Apr 28 2021
  • Currently Declined
  • Attach files
  • Smokey Piggs commented
    13 Jan 04:40am

    Hello Chef. Would you please elaborate on the "Declined" disposition of this idea? We're in the same situation for the same reasons as the OP. It's quite difficult for us to provide reasonable ideas and have them rejected without explanation. There's no opportunity for discussion, understanding of alternatives, or for us to refine the idea to account for the rejection criteria. As the OP says, "It would be nice to know."

  • Alex commented
    5 May, 2021 01:05pm

    Can you please specify a reason for declining this idea? It would be nice to know