Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Jira No
SummaryDescriptionStatusSolution

Service Mesh presentation by Andreas Geissler 

Andreas presented 4 networking options. Option 3 with ISTIO and Sidecar was recommended by SECCOM as default. 

ONAP "Networking" Options (>=Kohn)

ServiceMesh in Kohn...

startedDiscussion with Byung to be continued during OOM meeting.

David Wheeler presnetation presentation on SBOM and digital signatures

Operationalization of OpenSSF recommendations is not an easy topic...

Centos versionWas updated by Amy, thank you Maggie for sharing info and links.CentoS 9-stream is not yet released.

David's slides: https://docs.google.com/presentation/d/1BptlMG8kV14FutTMx3s9u4EnIL1Yzxt6-NID5H5XfAE/edit#slide=id.g13d496f372e_0_110

https://openssf.org/oss-security-mobilization-plan/

  • Identifies 3 goals, 10 streams to address those goals

SBOM recommended to be part of build process.

Package managers are good first step. SPDX in SECCOM uses package manager.

Dan Lorenc wrote an interesting paper on what is inside the container

Service MeshByung is working on it - it is a prioritized topic for him. Andrew is working on it. Once deplouyed, we will move avway from AAF. then Authentication and Authorization policy.OpenSSF recommedation

How to operationalize it? LF IT needs to make those capabilites available like in Marketplace.

It is important to allign OpenSSF recommendations with the budget, resources and deployment activities on LF IT side.




Next LFN events

ONE Summit NA Registration Open

  • CFP - Deadline: July 8th; 2022
  • Nov. 15 & 16 2022 Seattle, WA, USA
  • In Person

LFN Developer & Testing Forum NA Registration Open

  • Nov. 17 & 18 2022 Seattle, WA, USA
  • In Person
  • Securiung software supply chain by LFN - new topic to be proposed

Proposals to be submitted.

David was contacted and invited by Maggie to SECCOM meeting.

DevOPS Pipelines IRS presentation

Youtube link disappears ;-(

https://www.cloudbees.com/customers/IRS







SECCOM MEETING CALL WILL BE HELD ON 26th OF July'22. Session with David Wheeler on SBOM.

logging implementation discussion continuation.




...

View file
name2022-07-19_SECCOM_week.mp4
height150


SECCOM presentation:

View file
name2022-07-19 ONAP Security Meeting - AgendaAndMinutes.pptx
height150