I'm unaware of any piece of software in RHEL that's GPL that you can't run in any other distro down to their specific version. It's true that it's hard to get the "complete and bug-for-bug-compatible operating system", but all the components are there, be it in CentOS Stream or fedora, and a lot of stuff is theirs, not just added changes, but a big part of the codebase.
A grsecurity enabled kernel is "just" their patchset and any version is only available to their customers, no developer program or anything, there's no open upstream they provide with their patches or anything.
If you have software that you want to work on RPM-based distributions, test against fedora, or CentOS Stream; or, if you have clients insisting on RHEL, use a developer account, the options are there. Or don't and refer bug reports from RHEL users to their distribution's support, they're paying for it and it should be their first PoC anyways.
My post wasn't only to go against yours, but against a general attitude; that Red Hat just takes upstream code, makes an enterprise distro out of it and then charges big bucks, terminating anyone's contract who wishes to exercise their rights under GPL. The question is rather what's the reason to actually redistribute recompiled code when most of it is available in their own funded upstream? People pretend Red Hat is squeezing a community that made them possible in the first place. But the truth is rather the reverse in my opinion. Without Red Hat, the community most likely wouldn't exist. Their first release of Red Hat Linux was in 1994, when the kernel was about three years old and I guess by most people considered a toy rather than an alternative to UNIX. I'd wager that without them, the Linux ecosystem today would look much different, if more than a niche at all.
I don't think the same can be said for grsecurity.