PTL 2019-05-13

zoom bridge: https://zoom.us/j/283628617

Duration 60 minutes

DurationAgenda ItemRequested byNotes / Links
START RECORDING
5minIncoming ONAP Events
  • Hackathon "Documentation" Virtual Day will be organized by the Documentation project on May 14th, 2019
  • The next DDF event will be organized in Stockholm from June 11th to June 14th 2019 jointly with other LFN Open source communities i.e. OPNFV, Tungsten Fabric, etc.

https://lists.onap.org/g/onap-tsc/topic/june_ddf_registration_is_now/31435252?p=,,,20,0,0,0::recentpostdate%2Fsticky,,,20,2,0,31435252


Congratulations to APPC, Holmes, Music, and Integration for completing the migration to global-jjb! 

global-jjb Migration Tracker

Reminder that the deadline for conversion is July 19 then tooling expires


30min

Dublin end game plans

RC1 - May 16th

RC2 - May 30th (Euro holiday)

Sign-off - June 6th

RC1 Preparation: Deliverables for RCx Milestone Checklist Template

Unreleased docker images in OOM
Yangs-MacBook-Air:oom yang$  find . -name 'values.yaml' -exec grep -H image {} \; | grep onap  | grep image | grep -E -i "staging|snapshot" | sort 
./kubernetes/aai/charts/aai-elasticsearch/values.yaml:image: onap/elasticsearch-sg:1.4-STAGING-latest
./kubernetes/aai/values.yaml:    image: onap/fproxy:2.1-STAGING-latest
./kubernetes/aai/values.yaml:    image: onap/rproxy:2.1-STAGING-latest
./kubernetes/aai/values.yaml:    image: onap/tproxy-config:2.1-STAGING-latest
./kubernetes/appc/charts/appc-cdt/values.yaml:image: onap/appc-cdt-image:1.5.0-SNAPSHOT-latest
./kubernetes/appc/values.yaml:image: onap/appc-image:1.5.0-SNAPSHOT-latest
./kubernetes/helm/starters/onap-app/values.yaml:image: <onap-app>:<1.2-STAGING-latest>
./kubernetes/msb/charts/msb-discovery/values.yaml:image: onap/msb/msb_discovery:1.2.3-STAGING-latest
./kubernetes/msb/charts/msb-eag/values.yaml:image: onap/msb/msb_apigateway:1.2.4-STAGING-latest
./kubernetes/msb/charts/msb-iag/values.yaml:image: onap/msb/msb_apigateway:1.2.4-STAGING-latest
./kubernetes/oof/values.yaml:image: onap/optf-osdf:1.3.0-SNAPSHOT-latest
./kubernetes/policy/charts/brmsgw/values.yaml:image: onap/policy-pe:1.4-SNAPSHOT-latest
./kubernetes/policy/charts/drools/values.yaml:image: onap/policy-pdpd-cl:1.4-SNAPSHOT-latest
./kubernetes/policy/charts/pdp/values.yaml:image: onap/policy-pe:1.4-SNAPSHOT-latest
./kubernetes/policy/charts/policy-apex-pdp/values.yaml:image: onap/policy-apex-pdp:2.1-SNAPSHOT-latest
./kubernetes/policy/charts/policy-api/values.yaml:image: onap/policy-api:2.0.0-SNAPSHOT-latest
./kubernetes/policy/charts/policy-distribution/values.yaml:image: onap/policy-distribution:2.1.0-SNAPSHOT-latest
./kubernetes/policy/charts/policy-pap/values.yaml:image: onap/policy-pap:2.0.0-SNAPSHOT-latest
./kubernetes/policy/charts/policy-xacml-pdp/values.yaml:image: onap/policy-xacml-pdp:2.0.0-SNAPSHOT-latest
./kubernetes/policy/values.yaml:image: onap/policy-pe:1.4-SNAPSHOT-latest
./kubernetes/pomba/charts/pomba-data-router/values.yaml:image: onap/data-router:1.4-STAGING-latest
./kubernetes/pomba/charts/pomba-networkdiscovery/values.yaml:image:  onap/network-discovery:1.5.0-SNAPSHOT-latest
./kubernetes/pomba/charts/pomba-search-data/values.yaml:image: onap/search-data-service:1.4-STAGING-latest
./kubernetes/pomba/charts/pomba-servicedecomposition/values.yaml:image:  onap/service-decomposition:1.5.0-SNAPSHOT-latest
./kubernetes/portal/charts/portal-app/values.yaml:image: onap/portal-app:2.5.0-STAGING-latest
./kubernetes/portal/charts/portal-mariadb/values.yaml:image: onap/portal-db:2.5.0-STAGING-latest
./kubernetes/portal/charts/portal-sdk/values.yaml:image: onap/portal-sdk:2.5.0-STAGING-latest
./kubernetes/portal/charts/portal-widget/values.yaml:image: onap/portal-wms:2.5.0-STAGING-latest
./kubernetes/robot/values.yaml:image: onap/testsuite:1.4.0-STAGING-latest
./kubernetes/vfc/charts/vfc-redis/values.yaml:image: onap/vfc/db:1.3.0-STAGING-latest

- Request from Integration: Test your Dublin release bug fix before delivery to Integration, and attach your test results in gerrit

10minUpdated theme of docs.onap.org 

https://gerrit.onap.org/r/#/c/85705/

Style will be adjusted to match OPNFV and ODL - see example: https://logs.onap.org/production/vex-yul-ecomp-jenkins-1/doc-master-verify-rtd/4531/html/

10minCII Badging corrections

Several questions on the CII Best Practices survey were incorrect. Let's gain a common understanding of the question and how to complete the survey if you need more security knowledge.

  • Identified 6 questions that have been answered incorrectly
  • Q on "Leaked credential" - almost all project leak credentials through the OOM helm charts
    • Storing the credentials to the DB or accounts in the repo
    • Needs addressed, should be planned for El-Alto
  • Krzysztof Opasiak to prepare a proposal for remedy that is ONAP wide 
  • ONAP delivered as "demo" - end users expected to change the credentials upon deployment
  • AAF to work with SECCOM to develop proposal
  • Passwd encryption standard for Dublin is lacking - need standard for encryption 
  • http exposed ports also is a common mis-answered question
  • Krzysztof Opasiak to send email on projects needing to update their CII best practices answers
5minVulnerability documentation plan

Plans for releasing the pen test results 

  • Plan on releasing results on 2019-05-28 to the network operators through a restricted wiki space (under construction)
  • OJSI jiras are open and viewable by the PTL and SECCOM


Zoom Chat Log 

06:03:49 From Kenny Paul (LFN) : #topic Doc Hackathon
06:04:55 From Kenny Paul (LFN) : May 14 - tomorrow- bridge info will be sent out by Sofia
06:05:17 From Kenny Paul (LFN) : #topic DDF
06:05:20 From Kenny Paul (LFN) : https://wiki.lfnetworking.org/display/LN/2019+June+Event+Topic+Proposals
06:06:46 From Kenny Paul (LFN) : https://lists.onap.org/g/onap-tsc/topic/june_ddf_registration_is_now/31435252?p=,,,20,0,0,0::recentpostdate%2Fsticky,,,20,2,0,31435252
06:07:41 From Kenny Paul (LFN) : #topic global-jjb migration
06:08:29 From Kenny Paul (LFN) : global-jjb Migration Tracker Reminder that the deadline for conversion is July 19
06:08:49 From Kenny Paul (LFN) : https://lf-onap.atlassian.net/wiki/display/DW/global-jjb+Migration+Tracker
06:09:23 From Kenny Paul (LFN) : #topic RC0
06:10:31 From Kenny Paul (LFN) : @Yang - still some projects that have not released yet. No real changes since TSC meeting
06:11:47 From Kenny Paul (LFN) : 4th release and we have never met RC0 always near RC1. Need to review our release process because ours is not working.
06:12:46 From Kenny Paul (LFN) : @Catherine - are we removing functionality at this point?
06:13:48 From Michael O'Brien(Amdocs, LOG) : for logging, went through half the images - didn't see the 3 pomba and 1 shared data-router
06:13:50 From Michael O'Brien(Amdocs, LOG) : https://git.onap.org/oom/tree/kubernetes/pomba/charts/pomba-networkdiscovery/values.yaml#n27
06:13:54 From Michael O'Brien(Amdocs, LOG) : will look into it
06:14:11 From Michael O'Brien(Amdocs, LOG) : shared
06:14:12 From Michael O'Brien(Amdocs, LOG) : https://git.onap.org/oom/tree/kubernetes/pomba/charts/pomba-data-router/values.yaml#n30
06:14:37 From Kenny Paul (LFN) : @Jimmy AAI - not AAI images. there is some AAF content in AAI repos.
06:15:59 From Kenny Paul (LFN) : @Michael O - team that was responsible for POMBA has been disbanded in AMDOCS - probably need to remove scope.
06:16:36 From Kenny Paul (LFN) : #ACTION @Michael to reach out and update everyone by tomorrow.
06:17:11 From Kenny Paul (LFN) : @Taka APPC - will provide update
06:17:28 From Kenny Paul (LFN) : OOM - doc , not an image
06:17:52 From Kenny Paul (LFN) : MSB - need an update from @huabing
06:21:47 From Kenny Paul (LFN) : @Shankar OOF - merge pending, waiting on review and merge - @Mike E - seeing the same jobs pass CI in one env and fail in another OOM does not know which one is correct.
06:22:04 From Yang Xu : @Shenkar please post the patchset
06:23:01 From Shankar Narayanan P N (AT&T) : https://gerrit.onap.org/r/#/c/86342/
06:23:08 From Taka Cho : @Yang, I updated APPC value yaml file: https://gerrit.onap.org/r/#/c/87555/
06:23:37 From Jonathan Gathman : This is one reason for OOM problem in Orange
06:23:42 From Jonathan Gathman : Note: ORANGE CI/CD may need to apply OOM-59 fix, emailed to Sylvain et al’
06:27:53 From Kenny Paul (LFN) : @Yand - should release the image first and then test with OOM
06:29:15 From Shankar Narayanan P N (AT&T) : Thanks for clarifying, Yang. I was waiting for the health check to pass since the rc0 requirement seemed to indicate the release candidate should pass health checks
06:30:00 From Kenny Paul (LFN) : @Jorge - Policy- fond bugs against important functionality for the release. Mad no sense to release knowing the bugs are there. Going through the 2nd round of testing and expect to release tomorrow.
06:30:09 From Yang Xu : @Taka once ONAP job finishes, I will merge it
06:30:46 From Taka Cho : @Yang, thanks, and check the rocket chat. I just posted there as well.
06:31:31 From Yang Xu : @Taka, I am taking care of that
06:32:00 From Michael O'Brien(Amdocs, LOG) : for pomba/data-router - this is a shared image with AAI - trying to find the submodule in aai hosting the image
06:35:34 From Kenny Paul (LFN) : #ACTION @Yang send daily updates of non-released images to the rerlease list
06:37:16 From Kenny Paul (LFN) : 18 high/highest bugs still open
06:38:22 From Kenny Paul (LFN) : @Yang, @Jim & @Kenny reviewed open last week.
06:39:18 From Kenny Paul (LFN) : Working very well if dev teams attach their test results to the jira
06:41:23 From Keong Lim k00759777 : it should be saved as a JIRA filter and shared to others
06:41:28 From Kenny Paul (LFN) : Large number of open DOc bugs - expecting a lot of these to be addressed during the hackathon tomorrow
06:41:38 From Jimmy Forsyth (AT&T) : Many of the AAI documentation tickets in the list are for El Alto
06:43:22 From Catherine Lefevre : #action Jim to update the JIRA documentation query adding fixversion = Dublin Release
06:43:24 From Kenny Paul (LFN) : need to add fixversion dublin to the query for the report
06:44:02 From Kenny Paul (LFN) : #reviewing propject release status
06:44:52 From Kenny Paul (LFN) : Portal still has a pending checklist item w/o an upbate
06:45:56 From Kenny Paul (LFN) : @catherign regarding discussions of what a waiver for sonar coverage means - discussion will be taken to email
06:46:46 From Kenny Paul (LFN) : #topic updated theme of docs.onap.org
06:47:08 From Kenny Paul (LFN) : https://gerrit.onap.org/r/#/c/85705/
06:48:13 From Kenny Paul (LFN) : https://logs.onap.org/production/vex-yul-ecomp-jenkins-1/doc-master-verify-rtd/4531/html/
06:49:05 From Kenny Paul (LFN) : aligns to ODL and OPNFV formats. May be some minor rendering issues
06:51:14 From Catherine Lefevre : +1
06:51:23 From Kenny Paul (LFN) : #AGREED ONAP will adopt the new format
06:51:45 From Kenny Paul (LFN) : #topic CII Badging
06:52:00 From Kenny Paul (LFN) : Not a lot of progress in this area
06:53:18 From Kenny Paul (LFN) : PTLs need to review the findings of the pen-test and compare that to the CII checklint as many of them are wrong
06:54:28 From Kenny Paul (LFN) : @Krzysztof reports that almost all project are storing credentials inside the repos
06:55:27 From Kenny Paul (LFN) : and currently projects list the fact they meet that CII badging criteria as met when it is not.
06:56:51 From Christophe Closset (AT&T) : "A project MAY leak "sample" credentials for testing and unimportant databases, as long as they are not intended to limit public access. " - Can we not consider ONAP OOM helm charts as a community sample ?
06:57:07 From Eric Debeau : +1 for this topic in June
06:58:27 From Catherine Lefevre : +1 on Christophe C proposal too
06:58:46 From Michael O'Brien(Amdocs, LOG) : need to drop for other meet, in production we would use some cloud native cred obfuscation via an s3 pull for example
06:58:58 From gervais-martial Ngueko : +1
06:59:26 From Shankar Narayanan P N (AT&T) : +1 most of the creds say demo, ONAP, etc.
06:59:42 From Kenny Paul (LFN) : @johnathan to meet w/ Seccom team
07:01:41 From Kenny Paul (LFN) : @Krzysztof ONAP needs a better strategy because too many projects have too many versions of this
07:02:29 From Catherine Lefevre : @Jim, I have a hard stop today. I will ping you to sync-up later in your tomezone
07:02:59 From Kenny Paul (LFN) : @Kenny what happens to CII entries that do not meet the criteria and currently have incorrect checklist answere
07:04:05 From Kenny Paul (LFN) : @Seshu strategy needed but may be able to encrypt but not be albe to eliminate it all
07:05:09 From Kenny Paul (LFN) : @Krzysztof still need a lot work on https vs. http approx 30% of projects still not meeting
07:07:09 From Kenny Paul (LFN) : #ACTION @Krzysztof to send email to release, cc tsc with recommendas
07:07:32 From Kenny Paul (LFN) : #topic Vulnerability documentation plan
07:08:02 From Kenny Paul (LFN) : #topic Vulnerability documentation plan
07:08:39 From Kenny Paul (LFN) : @Pawel shared a slide on early disclosure
07:11:40 From Keong Lim k00759777 : is the protected wiki space the same as the SV space or something new?
07:13:35 From Kenny Paul (LFN) : it will be a seperate protected tree within SV

Action Items

  • 2/11: Migrate Docker image releases from Nexus3 into Docker Hub (Architecture Independence) by Dublin M4. 
    <2-15-2019> Preparing a preso for review of all known infrastructure change requests for review at PTL meeting 2-25-2019
    <2019-04-08: global-jjb progress report: start on DCAE soon - focus on El Alto delivery (precursor to Dockerhub)<2019-04-22 - Using mvn staging plugins to deploy - unfort many of the changes need to be in the source code to insure the job is running>
  • Tlab persistent storage IO architecture Rich Bennett 
    Request from Rich Bennett about Storage/Persistent Data Architecture Plan/PTLs - Single NFS server? 
    <2019-04-22: performance issues with old config - have bare metal cluster - - want to bring in more realistic operational aspects to the testing - network storage vs direct, would like to place modules in isolation into the environment. Evaluating the utility of testing this way. 
  • How to consume Alpine? Adolfo Perez-Duran (Deactivated)
    Meeting organized in May - https://lf-onap.atlassian.net/wiki/display/DW/TSC+2019-05-16
  • Michael O'Brien   to reach out withing amdocs and and update everyone on the status of POMBA by tomorrow
  • Yang Xu    send daily updates of non-released images to the release list
  • Former user (Deleted)  to update the JIRA documentation query adding fixversion = Dublin Release
  • Krzysztof Kurczewski  send email to release, cc tsc with recommendations on CII