You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 3 Current »

Please find below the Minutes of Meetings and recording for the SECCOM meeting that was held on 30th of November 2021.

Jira No
SummaryDescriptionStatusSolution

Request from the Policy project group (Ramesh and Liam) 

‘cluster-admin’ permission on one of their helm charts in OOM for automate helm chart installation for microservice. 

Requested change in the OOM repository by defining a cluster role binding for the K8s participant (provided by CLAMP repository) in its HELM chart which allows the component to create/update/delete resources on the cluster scope.

K8s participant should have a mechanism that would validate HELM chart before deploying it. Those would be signatures, hashed or signed HELM chart. Service mesh in Jakarta could take part of securing access.

ongoingNeed to have a mechanism to validate the HELM chart and repository from which fetching the HELM chart from.

SECCOM presentations for incoming DDF (January).

Deadline for submission: December 3rd: 

  • SECCOM topics backlog for DDF (4 bullets we merge into one presentation):
    • Logging requirements clarification – Bob/Byung - https://wiki.lfnetworking.org/display/LN/2022-01-DD+-+ONAP%3A+Security+and+Logging
    • New requirements for Jakarta – Amy/Pawel – all in one – GR review with David
    • Recommended versions (SECCOM and OOM) – Amy/Pawel/Sylvain
    • Packages upgrades - Jakarta update - Amy/Pawel
    • Unmaintained code handling and its impact on documentation (SECCOM + Documentation) - main session stream Amy/Pawel/Thomas/Eric
    • Code quality demo - main session stream - Fabian
  • Interproject proposals:
    • SBOMs ONAP story – Muddasar/Pawel
ongoingProposals to be reviewed next SECCOM (last minute)

TSC voting process for submitted requirementsDeadline is on 2nd of December.ongoingNo action required on our side.


OUR NEXT SECCOM MEETING CALL WILL BE HELD ON 30th OF NOVEMBER'21. 

Part 1

SECCOM proposal for DDF:

  • Logging requiremets clarification
  • New requirements for Jakarta
  • Recommended versions (SECCOM and OOM)
  • Packages upgrades - Jakarta update
  • Umnaintained code handling and its impact on documentation (SECCOM + Documentation) - main session stream
  • Code quality demo - main session stream

Interproject proposals:

  • SBOMs ONAP story



SECCOM MEETING CALL WILL BE HELD ON 30th OF NOVEMBER'21. 

Part 2

Request from the Policy project group (Ramesh and Liam) for the ‘cluster-admin’ permission on one of their helm charts in OOM for automate helm chart installation for microservice. 


Recording: 


SECCOM presentation:







  • No labels