u/Holly_Enrique-623

Still on bitnamilegacy for Postgres and Redis almost a year later, need to just get off it

Same boat as half of this sub I think. When the cutover hit last August we repointed Postgres, Redis, Mongo and Rabbit at bitnamilegacy as a stopgap and told ourselves we'd sort it properly later. It's July and later never came.

The legacy images don't get patched though and Bitnami's own line is that repo isn't meant to stick around, meaning we're sitting on unpatched infra that could also just vanish on us. Redis is a whole separate headache now with Valkey being the fork.

Small team, I really don't want to end up owning ten hand-rolled operator setups by myself. is it just service by service or how did y'all get all the way through this and land somewhere decent.

reddit.com
u/Holly_Enrique-623 — 4 days ago
▲ 6 r/grc

How do you handle no-fix vulnerabilities on a FedRAMP POA&M?

Sanity checking our approach on the compliance side before an assessment. We're going for FedRAMP and a chunk of our vulnerability findings have no vendor fix available, the patch simply doesn't exist yet. A lot of them come from third-party components we don't build because remediation isn't in our hands. We can't close them and we can't ignore them, they go on the POA&M.

We prioritise with exploitability signals, CISA KEV and EPSS such that we know which no-fix items are worth escalating versus just monitoring. The part I'm unsure about is the long-term optics. That POA&M line just grows, criticals sitting as monitored with no close date because the fix is outside our control.

What I'm really after is whether this holds up at assessment. If you've taken a growing no-fix POA&M through a 3PAO, do they let it ride as monitored or force close dates and deviation requests on you.

reddit.com
u/Holly_Enrique-623 — 8 days ago