...
Jira No | Summary | Description | Status | Solution |
---|---|---|---|---|
Logging update based on Tata Communication | How ONAP is used in their production environment. They use logging aggregation (Logstash). There is collaboration oportunity for PoC. Byung presented differences between generic ONAP and Tata Communication. They use syslog for metrics and Logstash for logs aggregation. We are not using sidecar while Tata is using it. In our reference architecture we separate generation from aggregation. Removing Filebit implementation is for London release. Folo logging architecture there is no Best Practice yet. PoC shall be satisfying first. | ongoing | Bob to send information on Byung who are the key players. Details to be discussed next week. | |
SBOM status update | Ongoing escalation with Ranny, Jess close to complete SBOM with CPS | |||
5G security | Security was not explicitly stated in ONAP but some features are part of the implementation. | |||
Waiver Analysis | Waiver analysis was reviewed.
| Pawel to check formatting for versions_xfail.txt and Jakarta - checked it is ok. Specific tickets to be opened for projects. | ||
Next LFN events | ONE Summit NARegistration Open
LFN Developer & Testing Forum NARegistration Open
| Proposals to be submitted. David to be contacted and invited by Maggie to SECCOM meeting. | ||
Update on Jakarta release | TSC approved the sign off of the Jakarta release on June 30th Security tests results at 60%: https://logs.onap.org/onap-integration/daily/onap-daily-dt-oom-jakarta/2022-06/30_04-01/ https://wiki.onap.org/display/DW/Jakarta%3A++Lessons+Learned | |||
SBOM status update | Muddasar contacted with several PTLs and waiting for their feedback. | We need LF IT support, GB was informed by Amy. We ned to run SBOM in the pipeline. Amy to talk to Kenny, Muddasar and Ranny. | ||
Technical debt | Muddasar reviewed Jira tickets recently. Some PTLs are using TechnicalDebt tagging and some not at all. Grooming the tickets would be helpful. Updating packages is technical debt for us. | |||
OSA branch | WE have not had any vulnerability raised within the process, so nothing to be added in OSA for Jakarta release. | Thomas to be contacted during unmaintained meeting on Monday. | ||
Last SECCOM meeting link | 2022-06-28 Security Subcommittee Meeting Notes | |||
DevOPS Pipelines IRS presentation | Youtube link disappears ;-( | |||
SECCOM MEETING CALL WILL BE HELD ON 19th OF July'22. | Potentially session with David Wheeler on SBOM. Overview of Tata Communications DTF presentation on their production logging implementation, https://wiki.lfnetworking.org/display/LN/2022-06-DD+-+ONAP%3A+The+Path+to+a+Production-Grade+ONAP - see the "Logs and Metrics: Architecture" and "Monitoring and Troubleshooting" sectionslogging implementation discussion continuation. |
Recording:
View file | ||||
---|---|---|---|---|
|
...