PTL 2019-06-17

zoom bridge: https://zoom.us/j/283628617

Duration 60 minutes

DurationAgenda ItemRequested byNotes / Links
START RECORDING
30min

Dublin end game plans


Sign-off follow-up

Are we ready for sign off?

Report from integration & stability test runs - Yang Xu

Lab situation - We are having severe issue with lab (can hardly deploy ONAP). Lab admin suggested to cut CPU usage by half
- Call for PTLs to (gracefully) decommission their project VMs in the WR lab by noon PDT today.
AI: Set up meeting today w/Steve Gooch & Yang & Brian & Catherine Former user (Deleted)

Known issues:

  • Docs related
    • DOC-481 - Getting issue details... STATUS  - Eric Debeau to review
    • missing release notes
      • logging
  • Integration test status - incomplete
    • Consistent ID Bin Yang - Incomplete and unknown current status
    • 5G OOF/PCI
    • Change management
  • Security Feedback - Vulnerability Tables, CII Bagding, Release Note, OSJI, etc. - 26 CVE issued, pushing updates of release notes - please merge ASAP
  • Integration Tests Status: Dublin Release Integration Testing Status
    • 34 use cases/functional/non-functional requirements require E2E testing.

    • 31 out of 34 are completed (including N/A, Reduced scope for CCVPN/Consistent ID of a Cloud Region)

    • 2 out of 34 are at >=90% test completion

      • 5G - OOF/PCI - completion 6/21 too late - need to wrap-up on 6/17 EOD
      • Change Management - Flexible Designer & Orchestrator - no completion date - need to wrap-up on 6/17 EOD
    • 1 out of 34 de-scoped from release (vCPE with TOSCA)
  • Documentation Tickets: Documentation Status for Dublin
  • Projects: Project Status in Dublin Release
  • 29 projects (excluding Doc) - Sign-Off
    • 23 out of 29 are completed
    • 6 out of 29 are in progress - blockers and/or documentation - APPC, Policy, OOF, SDC, Logging & Integration
  • Dublin release branch NOT created – Long list to the right.... except Documentation since 5/15 (so cherry-pick)
  • Please update Readthedoc asap - Dublin Release Notes
  • Review Marketing Messages - https://lists.onap.org/g/onap-discuss/message/17065
  • Please update JIRA bugs, tasks, user stories, etc, but do not close tickets when the work is not done

      JIRA Query - Remaining 508 Items (was previously 491?)

status != Closed AND status != Done AND project != "Sandbox Project" AND project != CI-Management AND project != "ONAP TSC" and fixVersion = "Dublin Release" ORDER BY key ASC, priority DESC, updated DESC

5minEl Alto Release

Proposals for El Alto content to be the ONLY thing in the fixVersion == "El Alto Release" by EOD 

Review/update your JIRA El Alto Content to be aligned with the scope a.k.a.“Reduce Internal Debt” (Every 4 ONAP releases)

Original scope

  • Refactoring
  • JIRA Backlog Reduction (defects, etc.)
  • Vulnerability issues
  • Test Coverage including jS
  • Test Automation & CI/CD pipeline
  • Deployment procedure (including Upgrade Strategy)
  • Documentation
  • etc.

ONAP TSC priorities "MUST HAVE" (2019 DDF June Event) - TSC still working on the next level of details for

  • Security First - see Pawel's presentation i.e. CVEs/Penetration findings (Important/Critical)
  • Document as you Code - Look at your El Alto tickets (left over from Dublin release)
  • Do not break the build - Increase pair-wise testing/E2E test automation

There are currently

-144 items where affectedversion is “El Alto release”

JIRA Query

status != Closed AND status != Done AND project != "Sandbox Project" AND project != CI-Management AND project != "ONAP TSC" and affectedVersion = "El Alto Release" ORDER BY key ASC, priority DESC, updated DESC

-1878 items where fixversion is “El Alto release”

JIRA Query

status != Closed AND status != Done AND project != "Sandbox Project" AND project != CI-Management AND project != "ONAP TSC" and fixVersion = "El Alto Release" ORDER BY key ASC, priority DESC, updated DESC

15 min.Client Cert Generation

What was demonstrated today was the Target ElAlto using Dublin code set.  We did not document the Demo for Helm for Dublin because.  "Raw" Helm is not the official Kubernetes Platform for ONAP.  OOM is.  It does, however, demonstrate how we will run in OOM once El Alto kicks off (and WindRiver Resources are available for Testing are available to Developers again... currently AAF test OOM is off to provide maximum resources for Dublin Integration).

For Dublin, certificate mechanisms was documented for "Standalone" or "Docker Containers", to allow folks to generate their certificates for their current Mechanisms.

https://onap.readthedocs.io/en/latest/submodules/aaf/authz.git/docs/sections/configuration/AAF_4.1_config.html

This will, of course, be updated with "OOM First" for Wave 1.

 if PTLs want to preview the demo Helm Chart, which IS a functional Helm chart but is NOT in OOM format,

https://gerrit.onap.org/r/gitweb?p=aaf/authz.git;a=tree;f=auth/helm;h=c9c80097dea72548b6cb7e14e8ce05702a0206f0;hb=HEAD

The important part of the chart, "aaf-hello.yaml" can be found here

aaf-hello.yaml

5minSecurity in El Alto Proposal

Priorities for El Alto

  1. See the OJSI tickets for your project
  2. Shared components proposals (eg. update Java 8 to Java 11 - see chatlog for cheat sheet from Policy team, k8s versioning, Alpine versions)


Detailed discussion to be organized this week for a review of the proposal - PaweÅ‚ Pawlak

20 minNexus → Dockerhub MigrationBrian Hedstrom Paul-Ionut VaduvaJessica Gonzalez

Zoom Chat Log 

15:10:22 From Taka Cho : I will shutdown some VMs in APPC tenant
15:11:11 From Dan Timoney : I’ll shut down some in CCSDK tenant (not that we have many, but every little bit helps I guess)
15:12:00 From Jimmy Forsyth : I don’t have a full ONAP but will turn down what we have in AAI tenant space
15:23:18 From Ofir Sonsino (AT&T) : I'll type it sorry -
15:23:30 From Catherine Lefevre : @ofir - is it code issue or resource issue due to lab constraint?
15:23:50 From Catherine Lefevre : @bin - can you also confirm if the patch is working or not? can we close the SO issue? thanks
15:23:59 From Ofir Sonsino (AT&T) : So the fix might require a new docker release, just wondering is it too late to release another image?
15:24:32 From Catherine Lefevre : do it today and tell us why because if we can nto deploy SDC then we have a major pb with most of the use cases
15:24:52 From Catherine Lefevre : my feedback was for Ofir
15:24:58 From Ofir Sonsino (AT&T) : Anyway cleaning sdc cassandra keyspace should be a workaround
15:25:02 From Taka Cho : i have shutoff 5 VMs in APPC tenant. will shutoff some VMs later
15:25:02 From Bin Yang (Wind River) : @Catherine, I think the SO-1995 is fixed , I need figure out what the next issue belongs to, if it is related to SO, it will be another jira to SO
15:25:50 From Catherine Lefevre : @ofir, new image is risky - we like your workaround
15:25:58 From Catherine Lefevre : please document it now/today so we can try
15:26:08 From Ofir Sonsino (AT&T) : Ok will do
15:26:10 From Catherine Lefevre : thanks ofir in advance
15:26:21 From Yang Xu : @ofir, let’s talk offline
15:30:04 From Bin Yang (Wind River) : I just close SO-1995
15:31:36 From Catherine Lefevre : @bin - thank you !
15:51:28 From Catherine Lefevre : @Team - I have just updated the El Alto sections based on ONAP DDF TSC discussions. Currently a significant number of JIRA tickets for El Alto too ... 1878 items where fixversion is “El Alto release” and 144 items where affectedversion is “El Alto release” ... so please consider only 3 sprints of dev/tests - 9-10 full-time days of work per sprint in average - DO NOT OVERCOMMIT yourself
15:52:02 From Catherine Lefevre : and your team members
15:59:31 From Dan Timoney : Remember that for El Alto, we really only have 5 weeks development before early drop
15:59:51 From Keong : if any ONAP project can use aaf-hello to generate their own certificates, what additional security does this add to the system?
16:01:21 From Catherine Lefevre : @Dan - correct - that's the reason why commitments should be realistic prior we kick-off El Alto
16:02:23 From Catherine Lefevre : @Vijay - please check feeback from Eric about DOC-481
16:02:54 From Dan Timoney : my comment was that if we need to include this new way of generating certs in wave 1, then apps need the documentation in time to include it in their helm charts
16:04:50 From Jonathan Gathman : Dan, yes. Of course. I was expecting to document how to do it with OOM specifically, which, as we talked about, needs to happen when I have access to WindRiver Resources to test.
16:05:57 From Jonathan Gathman : Kenos. “AAF-Hello” is a sample app, whose purpose it to show the “initContainer”. You would not deploy “oaf-hello” ,but simply copy over the elements you need for your own Container.
16:06:29 From Jonathan Gathman : Sorry, Keong… Spell check messed up your name.
16:08:38 From Yang Xu : @ofir, sent you an invite to talk about SDC-2371 at 10:30am EST
16:09:38 From Liam Fallon : https://wiki.lfnetworking.org/display/LN/2019+June+Event+Topic+Proposals#id-2019JuneEventTopicProposals-ExperiencesinswitchingtoAlpineLinuxandupgradingtoJava11
16:09:54 From Ofir Sonsino (AT&T) : Thanks Yang


Action Items

  • 2/11: Migrate Docker image releases from Nexus3 into Docker Hub (Architecture Independence) by Dublin M4. 
    <2-15-2019> Preparing a preso for review of all known infrastructure change requests for review at PTL meeting 2-25-2019
    <2019-04-08: global-jjb progress report: start on DCAE soon - focus on El Alto delivery (precursor to Dockerhub)<2019-04-22 - Using mvn staging plugins to deploy - unfort many of the changes need to be in the source code to insure the job is running><2019-06-13>: Based on what has been discussed during the ONAP June DDF, migration will be performed outside any ONAP release; dependency is the global-jbb completion. Dockerhub migration to be tracked similarly to global-jbb migration from now
  • Tlab persistent storage IO architecture Rich Bennett 
    Request from Rich Bennett about Storage/Persistent Data Architecture Plan/PTLs - Single NFS server? 
    <2019-04-22: performance issues with old config - have bare metal cluster - - want to bring in more realistic operational aspects to the testing - network storage vs direct, would like to place modules in isolation into the environment. Evaluating the utility of testing this way. 
  • How to consume Alpine? Adolfo Perez-Duran (Deactivated)
    Meeting organized in May - https://lf-onap.atlassian.net/wiki/display/DW/TSC+2019-05-16