PTL 2020-03-09

PTL 2020-03-09

Agenda

START RECORDING

Duration

Agenda Item

Requested by

Notes / Links

Duration

Agenda Item

Requested by

Notes / Links

1 hour

Cross-project discussions

@Amy Zwarico

@David McBride

  • Compliance with Section 5 of the CIS Docker Benchmark

    • Amy to update description for REQ-215.  Will follow up with SECCOM then send email to discuss mailing list.

    • For Guilin, be more specific about how projects can meet compliance, especially wrt to automated verification

  • M4 Task - Address all security issues

    • SECCOM reads this as "resolve ALL open OJSI JIRA issues"

    • PTLs read this as "best effort"

    • @Krzysztof Opasiak - waiver for non-ONAP containers and for projects not active in Frankfurt and for projects impacted by AAF

      • If projects cannot meet the requirement, then SECCOM will review on a case-by-case issue

  • Exposed HTTP ports / filter 

LF IT Support

 

 

IT-19190 - Jenkins has been stuck in queue since Sunday am.

Testing Environment

 

 

Testing Improvement

 

 

CSIT Review

 

 

ToolChain Improvement

 

 

Documentation

 

Changes blocking migration away from submodules:

Bharath: https://gerrit.onap.org/r/#/c/music/distributed-kv-store/+/101342/
Mandar: https://gerrit.onap.org/r/#/c/dmaap/dbcapi/+/101338/
Huabing: https://gerrit.onap.org/r/#/c/msb/swagger-sdk/+/101307/
               https://gerrit.onap.org/r/#/c/msb/java-sdk/+/101306/
Guangrong: https://gerrit.onap.org/r/#/c/holmes/engine-management/+/101302/
Sylvain: https://gerrit.onap.org/r/#/c/oom/offline-installer/+/101352/
Yang: https://gerrit.onap.org/r/#/c/oparent/cia/+/101349/

Other Improvement suggestion

 

 

Subcommittee Updates for PTLs

@David McBride

  • AAF client certificate mechanism to update (@John Franey@Jonathan Gathman)

Sharing Best Practices

 

 

IF TIME ALLOWS ....

15 mins

Release status

@David McBride

5 mins

Upcoming Events

 

10 mins

Remaining Action Items

 

 

Zoom Chat Log 

07:04:28 From Morgan (Proxy Eric (Orange)) : Hi Seshu
07:29:26 From Sai Seshu : Go to go.. 
07:30:52 From Jimmy Forsyth (AT&T) : I'll update the jjb on that graphgraph one,
07:32:52 From Kenny Paul (LFN) : Link to Docathon zoom info https://lists.onap.org/g/onap-release/message/1544

Action Items 

@Amy Zwarico - update description for REQ-215 to clarify how projects can meet the requirement. Ensure that there is sufficient information about the function of the script that verifies compliance. 
@Krzysztof Opasiak - replace table in REQ-231 with list of issues