2020-05-13 DCAE Meeting Notes
Bridge
Meeting pushed by 30 min for May 13, 2020 ; will start at 15.00 UTC
https://zoom.us/j/98967242523
Meeting ID: 989 6724 2523
One tap mobile
+16465588656,,98967242523# US (New York)
Dial by your location
+1 646 558 8656 US (New York)
+1 669 900 6833 US (San Jose)
877 369 0926 US Toll-free
855 880 1246 US Toll-free
Meeting ID: 989 6724 2523
Find your local number: https://zoom.us/u/ad1U59khic
Recording:
Attendees:
Host: @Vijay Kumar
Discussion Topics:
Time (est) | Topics | Requester/Assignee | Notes/Links | |
START RECORDING PARTICIPANT LIST | ||||
1 | Project Status | @Vijay Kumar | Release Status Frankfurt Milestone Status#RC1
| |
DCAE Blockers/High priority | DCAEGEN2-2218 - Deferred to Guilin; pending Security team confirmation DCAEGEN2-2217 - Fix done on OOM/DMAAP; CLOSED | |||
DCAE Outstanding Jira & MED priority bugs | DCAEGEN2-2219 - DFC's SFTP client doesn't protect from MITM attacks (Guilin) - Plan to disable SFTP; need help with Test Open items from last meeting
| |||
2 | DCAE bootstrap updates | @Vijay Kumar | Further blueprint updates will be assessed case by case if bootstrap version release is required 05/13/2020 - Bootstrap 1.12.6 (frankfurt) - Released and OOM updates completed
Reference : https://lists.onap.org/g/onap-discuss/message/20046 Blueprint management for Frankfurt - DCAEGEN2-2041 | |
3 | CBS TLS in SDK | @Piotr Wielebski | Review recent discussion on :https://gerrit.onap.org/r/#/c/dcaegen2/services/sdk/+/94266/ and identify next step Confluence:TLS support for CBS - Migration Plan link to the source- https://docs.onap.org/en/latest/submodules/dcaegen2.git/docs/sections/tls_enablement.html k8splugin version 2.0.0will automatically mount the CA certificate, in PEM and JKS formats, in the directory
k8splugin version 2.0.0 uses an init container to supply the CA certificates. 4/29, 4/1 -tested on HV-VES 1.4.0-not working- Exception in thread "main" org.onap.dcaegen2.services.sdk.security.ssl.exceptions.ReadingPasswordFromFileException:Could not read password from /etc/ves-hv/ssl/jks.pass - jks.pass is distributed only when use_tls is set to true; need to be checked if app expects cert as server? @Piotr Wielebski 5/13/ - after my investigation:
Conclusion:
| |
4 | Repo Branching | All repository branched including documentation (dcaegen2). Committer must ensure new submissions are cherrypicked into Frankfurt branch
| ||
6 | AAF change impact | @Fiachra Corcoran @Jack Lucas | aaf_agent (2.1.20) changed in Frankfurt generates cert as non-root; need to assess impact to dcae TLS init (currently uses 2.1.15)
DCAE change to be assessed based on CMPv2 proposal; generic onap/usergroup to be discsussed with AAF team - @Vijay Kumar | |
7 | Certificate for components/instance (wild card support) | >Frankfurt | PMSH may need to support multiple instance per different usecase. The certificate generation should be supported at instance level (possible AAF dependency 5/13 - John Franey/AAF confirmed wild card supported in AAF. Application can use AAF GUI to modify the SAN's (or bootstrap them via AAF/Windriver test). 4/29 - Policy may be using wildcard - *.pdp, *.pdp.onap.svc.cluster.local ; to be confirmed if supported from AAF currently - @Vijay Kumar 2/20 - DCAEGEN2-2084 - support certificate generation at instance level for DCAE services OPEN to track this request for DCAE; AAF dependency will be discussed post Frankfurt and corresponding AAF Jira to be created | |
8 | Guilin Items | @Vijay Kumar | Platform
Requirements from OOM team to be discussed with team
| |
VES topic/question | @Ravi Ravi | discussed VESCollector related question
| ||
@Vijay Kumar | Next meeting will be on 05/27 (05/20 meeting will be cancelled) |
Frankfurt Artifacts Release versions
Check "Artifacts released" section under RTD - https://docs.onap.org/en/latest/submodules/dcaegen2.git/docs/sections/release-notes.html
Open Action Items
New Action items
Seeking Community support
Topic/JIRA | Current Status | Planned Work |
---|---|---|
Docker build consistentency ( DCAEGEN2-1579) | JIRA cover broad aspect of standardizing DCAE component build process and docker tagging.
| Need volunteer from community to support
|