Skip to content

DOCS-2992: Remove remaining compliance feature prose from Calico Enterprise 3.24 and next - #2896

Merged
ctauchen merged 3 commits into
tigera:mainfrom
ctauchen:remove-compliance-prose-ce-3.24-next
Jul 31, 2026
Merged

DOCS-2992: Remove remaining compliance feature prose from Calico Enterprise 3.24 and next#2896
ctauchen merged 3 commits into
tigera:mainfrom
ctauchen:remove-compliance-prose-ce-3.24-next

Conversation

@ctauchen

Copy link
Copy Markdown
Collaborator

Second pass of the compliance removal (DOCS-2992). The first pass, which removed the compliance pages, navigation, cross-links, install references, and API reference, is already merged. This pass removes the remaining prose that describes the compliance feature, in Calico Enterprise next and version-3.24-1.

Removed or reworded:

  • Component architecture reference: removed the Compliance component section, its table-of-contents entry, and the compliance mentions in the intro and Manager descriptions.
  • Observability overview: removed the "Logs for compliance reporting" subsection.
  • Audit-log docs (audit overview, Kubernetes audit logs): reworded so audit logs are no longer described as feeding compliance reports.
  • Install and upgrade flows: reworded the steps that told users to enable a Compliance resource, and removed the compliance install-option rows.
  • Windows limitations table, license read-only console list, and log-storage prerequisite: dropped compliance.

Deliberately left in place:

  • Generic regulatory "compliance" wording unrelated to the feature (for example, WAF compliance guardrails, "compliance requirements").
  • References to components and fields that still ship: the LogStorage complianceReports retention field, and the Compliance CR resource-configuration reference.

Jira: https://tigera.atlassian.net/browse/DOCS-2992

For reviewers, representative changed pages are the component architecture reference and the observability overview.

… next

Second pass of the compliance removal, covering the prose the first pass left.
In Calico Enterprise next and version-3.24-1:

- Remove the Compliance component section, TOC entry, and intro/Manager
  mentions from the component architecture reference.
- Remove the "Logs for compliance reporting" subsection from the observability
  overview.
- Reword the audit-log docs (audit overview, Kubernetes audit logs) so they no
  longer describe compliance reports as a consumer.
- Reword install and upgrade steps that told users to enable a Compliance
  resource, and drop the compliance install-option rows (options-install,
  default-install feature list).
- Drop compliance from the Windows limitations table, the license read-only
  console list, and the log-storage prerequisite.

Left in place: generic regulatory "compliance" wording unrelated to the
feature, and references to components/fields that still ship (the LogStorage
complianceReports retention field, the Compliance CR resource-configuration
reference).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings July 31, 2026 16:35
@ctauchen
ctauchen requested a review from a team as a code owner July 31, 2026 16:35
@netlify

netlify Bot commented Jul 31, 2026

Copy link
Copy Markdown

Deploy Preview for calico-docs-preview-next ready!

Name Link
🔨 Latest commit 8b3c182
🔍 Latest deploy log https://app.netlify.com/projects/calico-docs-preview-next/deploys/6a6cdc4bd8ee140008bce759
😎 Deploy Preview https://deploy-preview-2896--calico-docs-preview-next.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@netlify

netlify Bot commented Jul 31, 2026

Copy link
Copy Markdown

Deploy Preview succeeded!

Built without sensitive environment variables

Name Link
🔨 Latest commit 8b3c182
🔍 Latest deploy log https://app.netlify.com/projects/tigera/deploys/6a6cdc4bd8ee140008bce754
😎 Deploy Preview https://deploy-preview-2896--tigera.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
Lighthouse
Lighthouse
1 paths audited
Performance: 74 (no change from production)
Accessibility: 98 (no change from production)
Best Practices: 92 (no change from production)
SEO: 100 (no change from production)
PWA: -
View the detailed breakdown and full score reports
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Removes remaining documentation prose for the Calico Enterprise “Compliance” feature across both Enterprise next (calico-enterprise/) and the 3.24-1 versioned docs (calico-enterprise_versioned_docs/version-3.24-1/), aligning the docs with the earlier pass that removed compliance pages/navigation and related references.

Changes:

  • Removes the Compliance component section (and related TOC entry) from the component architecture reference.
  • Removes/rewords compliance-related language from observability/audit-log docs (including Elasticsearch overview and Kubernetes audit log docs).
  • Updates install/upgrade flows, options tables, and limitations/licensing docs to remove compliance as an installable/visible feature.

Reviewed changes

Copilot reviewed 26 out of 26 changed files in this pull request and generated 7 comments.

Show a summary per file
File Description
calico-enterprise/reference/architecture/overview.mdx Removes Compliance component prose and related mentions from the architecture overview.
calico-enterprise/operations/logstorage/create-storage.mdx Removes compliance reports from storage prerequisites language.
calico-enterprise/operations/license-options.mdx Removes Compliance from read-only console visibility list.
calico-enterprise/observability/kube-audit.mdx Rewords Kubernetes audit logs content to remove compliance-report dependencies.
calico-enterprise/observability/elastic/overview.mdx Removes the “Logs for compliance reporting” subsection.
calico-enterprise/observability/elastic/audit-overview.mdx Removes compliance-report framing/screenshots and rewords required next steps.
calico-enterprise/installation/install-calico-enterprise-mke-4k.mdx Removes compliance from optional enablement guidance during install.
calico-enterprise/getting-started/upgrading/upgrading-enterprise/kubernetes-upgrade-tsee/helm.mdx Removes compliance from optional Helm upgrade enablement instructions.
calico-enterprise/getting-started/install-on-clusters/windows-calico/limitations.mdx Removes compliance-related limitations entry from Windows limitations table.
calico-enterprise/getting-started/install-on-clusters/kubernetes/quickstart.mdx Removes compliance from optional custom-resources enablement step in quickstart.
calico-enterprise/getting-started/install-on-clusters/kubernetes/options-install.mdx Removes Compliance from the operator API options table.
calico-enterprise/getting-started/install-on-clusters/kubernetes/helm.mdx Removes compliance from optional Helm install enablement instructions.
calico-enterprise/_includes/content/_default-install.mdx Removes compliance reporting from default install “You get…” table.
calico-enterprise_versioned_docs/version-3.24-1/reference/architecture/overview.mdx Mirrors Compliance component removal in 3.24-1 architecture reference.
calico-enterprise_versioned_docs/version-3.24-1/operations/logstorage/create-storage.mdx Mirrors storage prerequisite rewording for 3.24-1.
calico-enterprise_versioned_docs/version-3.24-1/operations/license-options.mdx Mirrors license read-only console list update for 3.24-1.
calico-enterprise_versioned_docs/version-3.24-1/observability/kube-audit.mdx Mirrors Kubernetes audit log rewording for 3.24-1.
calico-enterprise_versioned_docs/version-3.24-1/observability/elastic/overview.mdx Mirrors removal of compliance-report logging subsection for 3.24-1.
calico-enterprise_versioned_docs/version-3.24-1/observability/elastic/audit-overview.mdx Mirrors removal of compliance-report framing/screenshots for 3.24-1.
calico-enterprise_versioned_docs/version-3.24-1/installation/install-calico-enterprise-mke-4k.mdx Mirrors removal of compliance from optional enablement guidance for 3.24-1.
calico-enterprise_versioned_docs/version-3.24-1/getting-started/upgrading/upgrading-enterprise/kubernetes-upgrade-tsee/helm.mdx Mirrors removal of compliance from optional Helm upgrade guidance for 3.24-1.
calico-enterprise_versioned_docs/version-3.24-1/getting-started/install-on-clusters/windows-calico/limitations.mdx Mirrors Windows limitations table update for 3.24-1.
calico-enterprise_versioned_docs/version-3.24-1/getting-started/install-on-clusters/kubernetes/quickstart.mdx Mirrors quickstart optional enablement wording update for 3.24-1.
calico-enterprise_versioned_docs/version-3.24-1/getting-started/install-on-clusters/kubernetes/options-install.mdx Mirrors removal of Compliance from operator API options table for 3.24-1.
calico-enterprise_versioned_docs/version-3.24-1/getting-started/install-on-clusters/kubernetes/helm.mdx Mirrors Helm install optional enablement wording update for 3.24-1.
calico-enterprise_versioned_docs/version-3.24-1/_includes/content/_default-install.mdx Mirrors removal of compliance reporting from default install table for 3.24-1.

Comment on lines +129 to +131
1. Optional: Packet capture is an optional feature. To enable or maintain the enabled status, review the `values.yaml` file and set the flag to `enabled: true`.

If your `values.yaml` configuration does not include `compliance` or `packetCaptureAPI`, add them to the configuration and set to `enabled: true`
If your `values.yaml` configuration does not include `packetCaptureAPI`, add it to the configuration and set to `enabled: true`
1. [Configure a storage class for Calico Enterprise](../../../operations/logstorage/create-storage).

1. Optional: Compliance and packetcapture features are optional. To enable these features, review the `values.yaml` file and set the flag to `enabled: true`. In the next step, use this modified `values.yaml` for the Helm install.
1. Optional: Packet capture is an optional feature. To enable it, review the `values.yaml` file and set the flag to `enabled: true`. In the next step, use this modified `values.yaml` for the Helm install.
```

1. Optional: Compliance and packet capture features are optional. To enable these features during installation, download and review the custom-resources.yaml file. Uncomment the necessary CRs and use this custom-resources.yaml for installation.
1. Optional: Packet capture is an optional feature. To enable it during installation, download and review the custom-resources.yaml file. Uncomment the necessary CRs and use this custom-resources.yaml for installation.
## Big picture

Before installing $[prodname], you must configure persistent storage for flow logs, DNS logs, audit logs, and compliance reports.
Before installing $[prodname], you must configure persistent storage for flow logs, DNS logs, and audit logs.
| Networking | Default networking implementation based on your provider and platform. <br />Default IP pool/CIDR range. |
| Tiered network policy | Tiered network policy components. <br />Existing Kubernetes clusters are put in default tier.<br />$[prodname] components are secured with network policy. |
| User interface | the $[prodname] web console user interface (with a default of “no access outside the cluster”). |
| Logs and data | All nodes configured for log data collection using fluentdLog storage for a single node.<br />One instance of Elasticsearch and Kibana. |
| Networking | Default networking implementation based on your provider and platform. <br />Default IP pool/CIDR range. |
| Tiered network policy | Tiered network policy components. <br />Existing Kubernetes clusters are put in default tier.<br />$[prodname] components are secured with network policy. |
| User interface | the $[prodname] web console user interface (with a default of “no access outside the cluster”). |
| Logs and data | All nodes configured for log data collection using fluentdLog storage for a single node.<br />One instance of Elasticsearch and Kibana. |
## Big picture

Before installing $[prodname], you must configure persistent storage for flow logs, DNS logs, audit logs, and compliance reports.
Before installing $[prodname], you must configure persistent storage for flow logs, DNS logs, and audit logs.
ctauchen and others added 2 commits July 31, 2026 18:25
…r removed pages

The compliance component-resource reference (kept, since the components still
ship) linked to Compliance API anchors that the first pass removed from the
generated operator API reference. Unlink those anchors, keeping the
configuration content as plain text.

Add redirects for the compliance pages removed from Calico Enterprise 3.24:
the compliance guide pages redirect to the release notes, and the
compliance-reports reference pages and GlobalReport redirect to the resources
reference index.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The TKG install page links to two VMware Tanzu Kubernetes Grid docs pages that
now 502 the crawler after the Broadcom docs migration, failing the build's link
check. Add docs.vmware.com to the link-check skip list, matching how the other
vendor documentation sites (Mirantis, OpenShift, Red Hat) are handled.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ctauchen
ctauchen merged commit e1fc24d into tigera:main Jul 31, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants