Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Jira No
SummaryDescriptionStatusSolution

LFN AI/ML use cases

Muddasar Ahmed presented the draft deck about LFN AI/ML use cases.

Maggie shared link:

https://www.nist.gov/itl/ai-risk-management-framework 

We need to have Ops feedback (NOC manager) on AI, what pain point could  be solved by AI.

Deck shared with Marian from Orange, feedback expected in 2 weeks.



Nephio security working group

Byung-Woo Jun informed SECCOM that the Nephio security WG is holding a joint meeting with the LF security SIG today at 11AM ET. Nephio plans to adopt 80% of OSSF passing badge.

Topic further discussed:

It was noted that the passing badge should be straight-forward to achieve.

The web page tlhansen.us/badging was discussed. Click on “Single Project…” then fill in a search string or badging ID (e.g. "nephio" or "7665").

For Nephio, Tony recommends to sort by “Type+Section”

Nephio SIG Security meeting:

By: Lucy Hyde When: Tuesday, October 31st, 2023 8:00am to 9:00am (UTC-07:00) Pacific Time - Los Angeles Repeats: Weekly on Tuesday Location: https://zoom.us/j/96025994457

We could support Nephio by sharing our best practices and processes in place. Lucy OOO for the next few weeks?

Byung introduced Tony's tool and was positively perceived by Nephio team. Nephio has GUI and talked about UI: AuthN and AuthZ to be shared by Byung.




Support for CPS to get gold badge

OJSI distribution list participants were updated with Amy's and Jess's support.

2FA ongoing by Jess and Eric for CPS and OJSI distribution list. 

Issue claimed to be finally solved. Amy and Pawel confirmed second authentication with QR code scaning for jira.

Per Jessica Wagantall:

LFIT will bring the request for 2FA for all users across all ONAP Jiras to the TSC (26th Oct) for approval. 

LFIT will implement 2FA for users across all ONAP Jiras.


Modeling component move to unmaintained

Modeling team did not follow the unmaintained project process. Build failing for components reliant on the "etsi" components.

modeling/etsicatalog repo deprecation

  • Email from Deng Hui
  • repo is already archived
  • Speak NZ making use of it - no contributions
  • SO is also a downstream user
    • can move the repo under SO

Actions:

  • AGREED: the TSC approved re-enabling the modeling/etsicatalog repo without anyone to currently maintain it
    • remove etsicatalog from archive status and restore Jenkins jobs
    • Tony Hansen  When a repo goes into unmaintained status, also need to change its badging status to indicate that it is unmaintained
  • Move etsicatalog under SO by New Delhi release
  • Jenkins jobs created

Kenny Paul following up to fix the build break.


AAF Certificate Expiration

Jira
serverONAP Jira
columnIdsissuekey,summary,issuetype,created,updated,duedate,assignee,reporter,priority,status,resolution
columnskey,summary,type,created,updated,due,assignee,reporter,priority,status,resolution
serverId425b2b0a-557c-3c0c-b515-579789cceedb
keyAAF-1217

Review work around proposed by Andreas Geissler - deferred until Andreas Geissler returns from holiday

Workaround

Some project containers still experiencing problems: clients using the cert-initializer (e.g. SO, SDC, CDS) still fail.

Need to document certificate management in user docs.

Louis Gamers' AAF cert wiki page: (1) Create AAF CA certificates - Developer Wiki - Confluence (onap.org)

  • Components such as dcaegen2 have their own cert init container with the aaf certificate embedded in the container image. This might be the reason why SO, SDC, and CDS broke if they have their own cert init containers.
  • Unclear why onap-aaf-sms-preload and onap-dmaap-bc-dmaap-provisioning jobs broke in Louis's environment.

Discussion with China Telecom done - they could check potentially next week and they worked independently on this issue, Aaarna Networks commited to check Andreas's patch.

Waiting for an update from Andreas as he is back from PTO.


Pawel Pawlak to send an e-mail notification to China Telecom about the script prepared by Andreas and associated Wiki documenting it.


Container Signing

Review next steps:

-select signing software (SECCOM + LFIT)

-perform POC with friendly projects (ONAP)

-integrate into build process (LFIT)

Looking for a volunteering project to work with us. raised at the 18th September PTL's call but no volunteer so far.

LF IT would have to prioritized topic. Prioritization is possible with LFN, Muddasar to update ticket. Item discussed with Matt at the lasy PTLs call.


Muddasar Ahmed to analyze which ONAP project has the most frequent changes in its containers.

Muddasar reached out to LF-IT, Jess and her team are analyzing what enhancement has to be made with CI jobs to allow for Container signing.  Further updates will be provided when scope and efforts have been assessed.

https://jira.linuxfoundation.org/plugins/servlet/desk/portal/2/IT-26130


No PTL for AAI, DCAE, OOF

-Andreas Geissler and Thomas Kulik made committers

-They will do the work necessary for the projects to participate in the release

-TSC approved streamlining process (7 September)

-SECCOM will create package upgrade recommendations

-TSC will recruit resources to perform upgrades for AAI, DCAE, OOF

  • need options to move forward

Kenny's reply is that we could benefit from Mentorship program. We have to define job description and skills needed.


-Byung will discuss with Andreas and Thomas to coordinate release tasks such as backlog prioritization

-Muddasar: someone needs to take backlog management role

-Muddasar: no mandated best practice to manage technical debt; call for a statement about code quality – all code will be secure

-Muddasar & Amy: bring mandate for code quality to LFN TAC 2023/8/16

  • Pawel to raise a request to TSC with getting resources for upgrades for AAI, DCAE, OOF - done.

SSO use case

Topic related to CI/CD, do we have 2FA for code submitter and committer.




TSC meeting (November 2nd)

Preso at the TAC yesterday  - Netmaker

  • uses wireguard - implacement for ipsec
  • simplifies implementation
  • Interested in becoming an LFN project

https://wiki.lfnetworking.org/display/LN/2023-11-1+TAC+Minutes?preview=/110264497/113213489/Netmaker%20Overview%20for%20LF%20Networking.pdf

LFN security web site.




PTL meeting (November 6th)

SonarCloud statement with Java 11:

"This project was scanned using Java 11 runtime. Starting from 15 Nov 2023, SonarCloud will stop accepting scans that are started with Java 11. We highly recommend moving your configuration to Java 17+."

Solved by LF IT one week ago by upgrading pipeline to Java 17.

2FA implementation.




LFN-TAC (October 11th)

See update from TSC summary.




NEXT SECCOM MEETING CALL WILL BE HELD ON 21st of November 2023. 

We cancel the meeting on 14th as there is DTF in Budapest.




...