Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Jira No
SummaryDescriptionStatusSolutionService Mesh PoC status update

-Now work on migrating yaml files to proper helm templates (2.0 supported by ONAP, no resources so far for 3.0 – evident benefit: no limit for chart size), infra part to be added to OOM scripts, then first ONAP component to be migrated to service mesh.

ongoing

Support for projects with python upgrades - Michal

Michal is supporting SDC and DCAE projects.

For the DCAE support is tracked under

Jira
serverONAP JIRA
serverId425b2b0a-557c-3c0c-b515-579789cceedb
keyDCAEGEN2-2292
:

-An unofficial library usage is not a preferred solution as it later requires a maintenance. We recommend to wait until July, when open source Cloudify version is available - if only you would be enough time to perform all required activities within August time frame – to be confirmed with Michal.

-For the PyPy Python Interpreter in 3.6 SECCOM is fine with that in Guilin release - in H release upgrade to version 3.8 could be planned (we don't expect significant effort with that – to be confirmed with Michal.

ongoingTo provide SECCOM feedback under Jira item - done.

Jira
serverONAP JIRA
columnskey,summary,type,created,updated,due,assignee,reporter,priority,status,resolution
serverId425b2b0a-557c-3c0c-b515-579789cceedb
keyDCAEGEN2-2270

REQ-376

Flow matrix
  • Wiki created to collect data from PTLs.
  • 13 July PTL call: PTLs asked to complete their row of the flow matrix wiki.
ongoing
REQ-350

CII Badging Update

  • Priority 3 (PTL GO/NO GO) for Guilin.
  • Observation – bounds checking and injection prevention are part of S3P.
onging

Base Images

  • SECCOM recommends OS and language versions.
  • Ownership
DCAE components upgradeDCAE uses 1.3 branch of drop wizard. Maven recommendation of latest version is 2.0.11. Influence on jetty upgrade. SECCOM Recommendation: as Jetty vulnerability is priority 2 for SECCOM, it is acceptable that they can not do the upgrade. Our preference is to upgrade drop wizard to 2.0 version train. For Honolulu release DCAE must upgrade jetty.ONAP Images

Krzysztof has sent an e-mail to ONAP TSC and ONAP distribution list to ask TSC to vote on a list of approved licenses for our docker images.

GPLv3 = in the context of redistribution of modifications: apart from providing the source code, mechanizm and instruction on how to replace the package with a modified by end user version, must be provided.

In general companies are not very happy to provide such instructions.

Making available = redistributing.

waiting for a feedbackProblem stated clearly enough.Base imageQuestions are keep coming to SECCOM, but we can recommend versions but not base images. Ownership Morgan to be contacted to confirm his ownership to maintain
  • of base images is more on the Integration side.
ongoing
  • AP: Amy will provide Morgan the developer feedback about problems with the Frankfurt Integration base images.

 
onging
REQ-368Service Mesh PoC status update
  • KeyCloak patch integrated.
  • Working on OAuth proxy.
ongoing

ONAP Licensing

  • Waiting for TSC decision.



Harbor
  • AP: Fabian to present to TSC
  • AP: Eric to be consulted by Fabian.
  • AP: Amy will contact Fabian when he returns from PTO
Flow matrixCatherine asked to close this req-376  - Wiki created to collect data from PTLs. Catherine to be contacted and topic to be proposed at the next PTLs meetingongoingE-mail to be sent to Catherine to explain that this requirement does not put any additional effort on PTLs - just provide information.Harbor follow-up. No slot reserved so far for the TSC meeting to present.pendingTo consult Eric
  • .



OUR NEXT SECCOM MEETING CALL WILL BE HELD ON 21st OF JULY'20. 

Topics proposed:

  • Testing proposal – Sylvain
  • Security Documentation – Harald



Recording: none available because of problems with LastPass

View file
name2020-07-14 ONAP Security Meeting - AgendaAndMinutes.pptx
height150