Function | ONAP Today | Service Mesh | Risk |
Authentication (Enforcement) | |||
Password Authn |
|
| ONAP Today:
|
PKI-based Authn |
|
| |
Authorization (Enforcement) |
|
| |
RBAC (Enforcement) |
|
| |
Confidentiality (Encrypted transport) |
|
| |
User Management (Information Store) |
| ONAP Today:
| |
Certificate Management | |||
TCP and UDP support |
|
|
DCAE (SNMP trap collector) uses UDP for data collection (SNMP) Service Mesh would not change the security posture of ONAP use of UDP Authentication could be implemented as a sidecar plugin, but would require custom work | |||
Logging |
|
| ONAP Today:
Service Mesh: |
API Tracing | |||
Monitoring | |||
Performance | |||
Integration |
| ONAP Today:
| |
Layer 7 load balancing | |||
Integration with Ingress |