Agenda:

  • Bugs in H release:  Marat Salakhutdinov
    • most of them because AAF is disabled
    • maybe work on a specific gate system for that with people who wants it
    • two bugs are merged:
    • a bug on DMAAP MR:
    • SDC doesn't start as dedicated DB (with subcharts part) → need to validate the exact situation (at least 'if local part' is missing but other stuff may be also missing)
    • some "gating" environment may be proposed by Bell in order to validate all patch against this configuration
  • Kubernetes version and dual stack status update: Magdalena Biernacka Daniel Milaszkiewicz
  • ONAP vF2F: Damian Nowak
  • service mesh initiative rererebooted: Sylvain Desbureaux Byung-Woo Jun Gareth Roper
    • 3 topics:
      • make (subset of) ONAP to run on a "simple" service mesh (mTLS, no AAA)
      • AAA
        • onboard roles and realm on Keycloak for tests / reference implementation (use of OIDC / JWT)
        • add oauth2 proxy in the solution to redirect unauthenticated traffic to SSO Portal (keycloak as example)
          • prototype was OK but then istio has changed the conf part
        • add some rules to enforce (AuthorizationPolicy)
          • work by fabian rouzaut in order to automatically create a bunch of them
        • add some service accounts (work ongoing)
      • add reference implementation for "PaaS" part installation (keycloak, prometheus, istio, cert-manager, ...) and use it during gating/daily installations
  • prometheus monitoring and internal ports: Lukasz Grech Sylvain Desbureaux
  • idea: move to operator?
    • what would be the work to do?
    • how to transform common part in to "common for operator" (services, secrets, aaf, repositories, ...)?

Next meeting:

  • chartmuseum integration


  • No labels