Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
  • PTL Recordings

  • Antitrust Policy Notice

We start our meetings by mentioning the project's Antitrust Policy, which you can find linked from the LF and project websites. The policy is important where multiple companies, including potential industry competitors, are participating in meetings. Please review and if you have any questions, please contact your company legal counsel. Members of the LF may contact Andrew Updegrove at the firm Gesmer Updegrove LLP, which provides legal counsel to the LF.

Agenda

START RECORDING

SDC-4691

Update? They are still blocked.

  • https://jira.linuxfoundation.org/plugins/servlet/desk/portal/2/IT-27561 for vulnerability scan for Policy-OPA-PDP

  • Duration

    Agenda Item

    Requested by

    Notes / Links

    30 mins

    Cross-project discussion

    Sandra Jackson (Deactivated)

    louis li

    Paweł Pawlak

    Byung-Woo Jun

    Tony Hansen

    Security

    Amy Zwarico

    Byung-Woo Jun

    PTLs reported vulnerability reports are not accurate

    • NexusIQ reports and scripts have discrepancies - Fiete Ostkamp

    • May be a process issue - PTLs update based on the reports at the beginning of the release

    • Action items:

      • are PTLs willing to fix new vulnerabilities found up to code freeze? PTLs can fix new findings in NexusIQ

      • Bring up at At the next PTL meeting (9am ET) - December 2nd

      Now, we have automated
      • this Monday, Amy and PTLs discussed how to process vulnerability reports

      PTLs can pull up the latest and greatest reports from NexusIQ (
      • The current assumption is that PTLs access the Nexus for the vulnerability reports and decide when to apply the fixes

      • Amy Zwarico provided the initial Nexus access demo on December 2nd

      • CLM link, https://

      nexus-iq.wl.linuxfoundation/ ) anytime, not just at the beginning of the release
    • What would be the new process? We can discuss it further at SECCOM;

    • It seems that the periodic report is a good idea, and PTLs can access the report and make their decision on which release the issues are applied.
    • PTLs can add more people for the Nexus access (but maybe there are some license limitations; check with LF IT);

    • A Amy Zwarico , give a Nexus access demo can be provided by Amy Zwarico / Hannah ; December 9th PTL; can be changed.CLM link, https://jenkins.onap.org/view/CLM/ , can we give PTLs more current views?

    • Toine Siebelink , CPS has a fortnightly community meeting during which we already check some quality report. I think we will start including this Nexus IQ report in that cycle...

    • Will discuss this again at the SECCOM (initial discussion at SECCOM; and early next year with PTLs)

    Oslo Release update

    Byung-Woo Jun 

    RelEng/Infrastructure

    Jessica Gonzalez Paweł Pawlak 

    Byung-Woo Jun 

    RelEng/Infrastructure

    Ramesh Murugan Iyer

    Kevin Sandi

    • Jenkins issues to discuss

    • Deena Mukundan , cannot push images to nexus; gerrit command does not trigger jobs; … IT-27514 => Jenkins Jobs exhibits inconsistent behaviour when called from gerrit and sandbox

    • murali parthasarathy k , raised tickets; IT-27507: (IT-27519)

      docker push to nexus failing from jenkins job

      push jobs to jenkins sandbox via gerrit comment

    • Kevin Sandi , IT-27520, IT-27520

      Error in Creating Releng Go Jobs as per guide

    • @matt wakins, is working on it;

    • report new status at TSC or PTL

    Oslo Release update

    Byung-Woo Jun 

    Paweł Pawlak 

    Jira Legacy
    serverSystem Jira
    serverId4733707d-2057-3a0f-ae5e-4fd8aff50176
    key

    Paris Release update

    Byung-Woo Jun

    • The next Paris release schedule is proposed, Release Planning: Paris 

      • TSC plans to vote for the schedule in Novemberwill discuss the Paris schedule this Thursday at TSCapproved the current Paris release schedule on December 5th

      • An ArgoCD deployment to provide an alternative the helm deployment

      • Vishal Varvate , confirmed the RAN Simulator enhancement

      • Policy-OPA-PDP

    • Long Term Release Roadmap

    OOM 

    Andreas Geißler 

    • An ArgoCD deployment to provide an alternative the helm deployment. Marek Szwałkiewicz , Andreas Geißler , DT is working on it.; will decide which release that DT applies..

      • Andreas Geißler , will check with Marek and let us know... Postponed to Paris

      • Marek Szwałkiewicz , WIP; Matt needs a ticket for a check; update next week confirmed this feature is postponed to Paris

    RAN-SIM (Target Oslo)

    Vishal Varvate

    Andreas Geißler

    Update Jiras

    Oslo Package

    Amy Zwarico 

    Paweł Pawlak 

    Toine Siebelink

    Toine Siebelink updated the following: (Thanks!!!).

    • Assignee, please check the tickets

    • For the ticket without assignees, we need to find new assignees

    Epic: https://jira.onap.org/browse/REQ-439
    Oslo task:

    Jira Legacy
    serverSystem Jira
    serverId4733707d-2057-3a0f-ae5e-4fd8aff50176
    keyREQ-1592

    Jira Legacy
    serverSystem Jira
    columnIdscolumnsissuekeykey,summary,assignee,status,resolution
    columnscolumnIdskeyissuekey,summary,assignee,status,resolution
    maximumIssues20
    jqlQueryid IN linkedIssues("REQ-1592") AND type != Epic ORDER BY summary
    serverId4733707d-2057-3a0f-ae5e-4fd8aff50176


    Fiete Ostkamp , is there any automated tool for dependency checking from Gerrit? Matthew will provide its update. Matt/kevin will check; may use portal-ng as a test project/candidate; Fieta will a LF IT ticket toward Matt/Kevin. ; Matt put a couple of patches, still working on it. Matt gave us update…

    The Github2Gerrit is under IT-27340; about to merge; Matt, let us know; maybe this week;

    The Nexus IQ job is under IT-27251; It is done.

    The gerrit code merge issue opened by Tony is IT-26848; It is done

    Tony opened a new ticket; Kevin Sandi is working on it, IT-27455;

    Toine Siebelink , https://sonarcloud.io/summary/overall?id=onap_cps

    https://sonarcloud.io/organizations/onap/projects

    https://sonarcloud.io/summary/overall?id=onap_cps-ncmp-dmi-plugin

    LF IT Support

    Jessica Gonzalez 

    • *** note: please check if the following issues are still open ***

    • Pending ticket opened by Marek:

      https://jira.linuxfoundation.org/plugins/servlet/desk/portal/2/IT-25573

      • Kevin Sandi - a workaround solution will be tried;

      • Marek / Matthew - automatic building solution is needed; escalate this? Waiting for feedback from Marek 

      • Kevin/Matt/Kevin - create a ticket and try a solution (maybe Github action helps? PoC??)

      • Some action plans and updates next week

      • Kevin and Marek are working on it, testing and deployment. will report its status - 90% is working; WIP; scheduled for next week update

      • wait for argo-cd deployment update. will revisit...

      • wait for Marek's return

      • Marek is working on it. 

      • Kevin Sandi , waiting for Marek’s confirmation. Update next time; update it at the TSC meeting this Thursday.

      Kevin: Jenkins' sandbox; security patching is working fine; downtime would be 30 mins; will notify the downtime by email to ONAP community - WIP, still pending; let us know.

    • Thomas Kulik - issues with Portal-NG and other documentation - 

      Kevin / marek: WIP; update in two weeks.

      • Kevin / Marek are working on it. wait for Argo CD finish

      IT-26899 Project is not created in RTD - Kevin; found a root cause; almost done, pushed the fixes;

      Ticket opened by Tony: IT-26848 - Tony is checking on it, still has issues; Kevin will work on it; Let us know.

      • Kevin Sandi , working on it; removing gerrit plugins as a possible solution; update the ticket with findings and will check them with Tony; 

      • Byung-Woo Jun , will ask Tony for this at the SECCOM tomorrow.

      • Tony confirmed it still does not work; Kevin is working on this. 

      • IT-27455, Kevin Sandi is working on it.

    RelEng/Infrastructure

    Kevin Sandi

    • Kevin Sandi, Github action ticket (Kevin Sandi) - bypassing -1 for option jobs : any update? Jira ticket for tracking RELENG-5602

      • If patches are fixed today, Kevin can start testing.

    New bypassable workflow is in place and working. There are a couple of improvements I’m working on to avoid deprecation notices and use the correct voting github action.

    It is working, but Toine Siebelink , will create a new ticket for a new policy on checking the RTD links toward Kevin Sandi ; Thomas Kulik , reported there are many broken ONAP wikis; treat every warning as a warning??

    Toine Siebelink , created a new ticket, https://jira.linuxfoundation.org/plugins/servlet/desk/portal/2/IT-27475 .

    • Any update? Kevin Sandi will work on it later; backlog; most likely in Paris

    Testing Environment

    Testing Improvement

    CSIT Review

    ToolChain Improvement

    Documentation

    Other Improvement suggestion

    Andreas Geißler  Dan Timoney 

    In Oslo, Plan to migrate ONAP components to use RFC8040. and will Keep the New Delhi CCSDK/SDNC as LTS (long term support) for Biermann APIs. In Oslo, only RFC8040 will be supported.

    Dan Timoney, reviewed the above CCSDK/SDNC plan with ARCCOM and ARCCOM approved it.

    1. Recommended packages upgrades are available on the restricted Wiki. Jiras to be created per project. 

      Need to check NG Portal status CLM jobs. Any update? 

     - no solution for now:

    Fiete Ostkamp ,

    Jira Legacy
    serverSystem Jira
    serverId4733707d-2057-3a0f-ae5e-4fd8aff50176
    keySECCOM-276
    .
    Jira Legacy
    serverLinux Foundation Jira
    serverId786ecce4-c7f8-3725-b80d-ceab920b9b14
    keyIT-26882
    ; will check them

    Matt Watkins , will follow up. Please let us know the outcome. 

  • This is the Nexus IQ/Sonartype Lifecycle ticket Ref: https://jira.linuxfoundation.org/plugins/servlet/desk/portal/2/IT-27251

  • Here is the scan result: https://nexus-iq.wl.linuxfoundation.org/assets/index.html#/applicationReport/onap-portal-ng-ui/28f50ec63db94687a0556a343940e14f/policy

  • WIP; Fiete has scans, Matthew is working on; maybe in 2 weeks, the issue can be resolved.; WIP

  • Initial issues are done.

  • Matt to provide an update next week on merge

    Andreas Geißler , any update from Sanket?

    Subcommittee Updates for PTLs

    Paweł Pawlak 

    Amy Zwarico 

    working with Sanket and Dan. We need a new update by this Thursday.

    Byung-Woo Jun ,Sanket is checking in the SO code change for RFC8040. The SO team will decide if they finish this in the Oslo release.

    Sharing Best Practices

    IF TIME ALLOWS ....

    15 mins

    Release status

    5 mins

    Upcoming Events

    • Kubecon and CloudNativeCon North America 2024 (November 12-15), KubeCon+CloudNativeCon, and Open Networking & Edge Summit, next April 2025 in London

    • LFN DTF schedule will be announced when it is available

    • Open Networking & Edge Summit Registration: https://events.linuxfoundation.org/kubeconopen-networking-cloudnativeconedge-northsummit-america/?utm_source=google&utm_medium=paid-search&utm_campaign=kubecon-na-2024&utm_term=events-kubecon-na-2024-cncf&utm_content=kubecon-na_rsa&campaignid=21541954784&adgroupid=166431838780&creative=708046449585&matchtype=e&network=g&device=c&keyword=kubecon%202024&utm_term=kubecon%202024&utm_campaign=Events+-+KubeCon+NA+2024+-+CNCF&utm_source=google&utm_medium=ppc&hsa_acc=8666746580&hsa_cam=21541954784&hsa_grp=166431838780&hsa_ad=708046449585&hsa_src=g&hsa_tgt=aud-2235032889006:kwd-2276042045987&hsa_kw=kubecon%202024&hsa_mt=e&hsa_net=adwords&hsa_ver=3&gad_source=1&gclid=Cj0KCQjww5u2BhDeARIsALBuLnO86USewI8c0_a4uKus91l491oBwGC-cQoGruwKx3Sz5WUeGTuCFa0aAj_3EALw_wcB europe/register/

    • Byung-Woo Jun, will provide its summary sometime in Decemberis writing 2024 KubeCon+CloudNativeCon summary

    10 mins

    Remaining Action Items

    Zoom Recordings

    https://zoom.us/rec/share/HLPq9GyyULEoozJxbwnKRc3QsY4BZqTfMvdESox2MExSQXbwtDoBb0AGDAo2aTgkfdmUn3bPzyeXETTGjmA8fh4ee-0GRdv0Z8HBoTJKkO0mKTDhf8gsGi1btjN-2J5.tW2V9Cyz41ZgK_1ZVr5czUqnVQn0AMlO

    Zoom Chat Log