2020-10-20 Security Subcommittee Meeting Notes
Please find below the Minutes of Meetings and recording for the SECCOM meeting that was held on 20th of October 2020.
Jira No | Summary | Description | Status | Solution |
---|---|---|---|---|
| MVP definition for flow matrix | MVP definition – initial proposal for the run time shared with Architecture Subcommittee, and no specific comments received – only to take into account also new project: Configuration Persistence Service which was just approved by TSC.
Flow matrix is must have from SECCOM perspective. Maintenance of the YAMLs: Sylvain to be addressed. Common repoto host YAML files: Repo seems to be a better choice (as it has source control). Potential problem with synch between repo and Wiki. Creating sub-wiki Amy might help if Natacha has any problem. Impact of change of source YAML file and changes in documenattion - for a small change it is not the case. | ongoing | Pierre to check with Martial if we could work with CLAMP for flows documentation. Tool (Cidium?) to get flow matrix information to be elaborated by Fabian. To be checked with Eric and Catherine to get buyin from TSCs. Information to be provided by Fabian to Amy. |
| Harbor integration | Meeting with Jessica was organized to discuss next steps and explain activity goals. Key features of Harbor:
| ongoing | Action point for Fabian to provide requirements for Harbor to Jessica and use Jenkins sandbox. Fabian to run an internal meeting with his team and comeback to SECCOM with those 2 features utilization idea. |
| vF2F summary | Multiple presentations provided:
| done |
|
| Known vulnerabilities analysis for Honolulu | Our and effort projects bring value in decreasing the rsecurity isks
| ongoing |
|
| Honolulu non functional requirements |
| done | Test use cases and ac ceptance criteria shall be prepared for each requirement. |
| ONAP Release milestones | Non functional requirements to be provided by 16th of October RC0 - October 12th RC1 - October 22nd
| done |
|
| Java and Python upgrade | Final list of the projects that require upgrades to be created. |
| Amy to check with Morgan and Sylvain. |
| OUR NEXT SECCOM MEETING CALL WILL BE HELD ON 27th OF OCTOBER'20. | Secrets management if possible. |
|
|
Recording:
SECCOM presentation: