You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 35 Next »

References

CPS-2249 - Getting issue details... STATUS  

Assumptions


AssumptionNotesSign-off
1

Scope:

  •  CPS-E-05
    • Update
    • Create
    • Delete
This does not affect (bulk/batch) Read

 

2Conflict Management Interface uses FDNConflict Management can support ANY format the Alternate ID can support (FDNs and/or URI-FDNs)

 

3Request per second is per the existing numbers on NCMP

 

Issues & Decisions


IssueNotes Decision
1

Uplift Ericsson source code (need permission)

CPS not allowed to lift // proprietary codes, we need to use pseudo code Gergely/team to support CPS with these codes
2

Implement in REST or Service Layer ?

This is currently implemented as an in the Service laye

r in // 


3

Publish public


Conflict Interface as part of NCMP (Concerns new generic interface)? 

NCMP shall own and document.
4

Could we make this more generic to suit non-conflict-management use i.e. tbac...

Agreed to make it more generic to suit ALL the use cases 
5Private properties are used to get FDN at the moment.

Will // provide us with registered Alternatid? Opensource does not support private property Peter Turcsanyi to revert TBC

// Confirmed they will implement all

https://eteamproject.internal.ericsson.com/browse/IDUN-105467

 

6CPS-1992 - NCMP to Support New 3GPP sync single FDN request to support Conflict mgt

CPS-1992  - When delivered, this should also support conflict management

7Legacy and ongoing bulk/batch interface (dataJobs CPS-1964) are not in scope

Bulk/batch operation

  • Datajobs bulk write op. ..... out-of-scope
  • single write operation -In-scope



8Name for more generic interface

Suggestion: External Validation AP Kolawole Adebisi-Adeolokun  to inform other stakeholders

New Interface name shall be PolicyExecution as agreed with stakeholders Kolawole Adebisi-Adeolokun kieran mccarthy Gergely Molnar 

9External Validation Request format

POST operation, all parameters in body, URL ? 

AP Toine Siebelink to create a page & collaborate with Gergely/Brian ( on initial proposal)

10Enable/service name discovery

config parameter with service name/address.
Blank to disable ?

AP Toine Siebelink to create a page & collaborate with Gergely/Brian ( on initial proposal)

11case sensitivity of parameters (payloadType, decision etc.)

e.g. accept 'allow', 'Allow', 'ALLOW' or only accept only on well defined case sensitive variation and anything else is a error scenario?!

To be discussed during proposal;

AP Toine Siebelink to create a page & collaborate with Gergely/Brian ( on initial proposal)

12Delivery Artefact

The new OpenAPI Interface definition wil be published on CPS Public Documentation Page. and through ONAP Gerrit.
Will it need to be delivered somewhere else (as snapshot for every build and/or release process)?
(I dont think this was done for DMI interface either)


13Specify cmChangeRequest in more detail
Sugegstion
{
  "moType": [
    {
      "id": "<mo Type Id>",
      "attributes": {
        "<key>": "<value>",
        "<key>": ["<value>", "<value>"]
        ...
      }
    }
  ]
}


Requirements

Functional: new generic 'PolicyExecution' REST interface 

This interface will NOT be implemented by CPS team except a stub for testing purposes


InterfaceRequirementAdditional InformationSignoff
1PolicyExecution

Documentation

NCMP own and clearly document interface using OpenAPI and RTD

2PolicyExecution

Input Parameters:

  • Bearer Token (header information?)
  • Payloadtype 
  • Decisiontype
  • Payload
    • resourceIdentifier
    • targetFdn
    • changeRequest

Payloadtype can only be 'CM_Write' for now

Payloadtype can only be 'Allow' for now

Exact Payload to be defined during study but should be well defined and cannot depend on Java interface (even if it is the same now)

3PolicyExecution

Output  Parameters;

  • Decision (enum: "allow", "deny")
  • Message - Should return a 409. Standard HTTP response
  • Decision id (String)

This is a New Generic interface that can support 'conflict handling'. 

Functional: CPS Impacts


InterfaceRequirementAdditional InformationSignoff
1CPS-E-05

Write operations are intercepted and validated using the new external service.
No effect on existing behavior if the result is 'Allow'



2CPS-E-05When the External validation is negative NCMP REST Response should be '409 Conflict'.  The HTTP status message should contain the message and decision id from the external validation service.NCMP interface validation shall be done before the external validation (Conflict management)
3

NCMP to provide metrics on external validation

AP on CPS to provide the metrics (Kolawole Adebisi-Adeolokun )

Error Handling


ScenarioExpected BehaviorNotesSignoff
1External validation service does not respond (in time) Or does not respond with 2xx (Http status code)

configurable default answer


This needs further investigation AP Gergely Molnar  

Possible proposal:

  • Implement watchdog similar to DMI health check

2Unrecognized response from External Validation

(Low prio)

No default behavior covered yet in //, 

If not reachable - default accept/reject with specific message



Characteristics


ParameterExpectationNotesSignoff
1Performance impact? 
  • External Validation Response time depends on various response time at the moment

Out of Scope

  1. Batch (bulk) interface methods and Execute a data operation for group of cm handle ids
  2. Data jobs (write) operations

Suggested User Stories

  1. Agree, Define (and Publish) Open Source Interface for Policy Execution
  2. Feature toggle and addressing configuration parameters
    1. use logging instead of actual call to new intreface
  3. Dummy Stub implementation (to allow for integration testing)
  4. Use new interface in NCMP
    1. use Stub to allow/disallow predefined names/patterns
  5. Publish artefact as part of snapshot and release builds (TBC)
  6. Update official documentation (when feature completed from OpenSource point-of-view)

Solution Proposal

Policy Executor REST Interface

Alternative a. No Parameters in URL (all data in body)

URI: <server-address>/policy-executor/api/v1

Alternative b-2. Payload and decision Type in URL 

remaining data in request body, no need for 'payload' object because the body = payload

URI: <server-address>/policy-executor/api/v1/<payload-type>/<decision-type>

e.g. myhost:1234//policy-executor/api/v1/CM_Write/Allow

Alternative b-2. Payload and decision Type in URL with variable names

remaining data in request body, no need for 'payload' object because the body = payload

URI: <server-address>/policy-executor/api/v1/payload/<payload-type>/<decision-type>

e.g. myhost:1234//policy-executor/api/v1/payload/CM_Write/decision/Allow


Input Parameters


NameParentTypeExampleOptional/CompulsoryNotes
1Authorization: BearerheaderString
Required

required for tracking/ (future) authentication and to identify the source of the request

2payloadTypebodyString CM_WriteRequired'CM_Write' currently, the only support value
3

decisionType

bodyStringAllowRequired'Allow' currently, the only supported value
4

payload

bodyObject Array
Required
5

cmHandleId

payloadStringF811AF64F5146DFC545EC60B73DE948EOptionalCan be sent while cmHandle is used instead of alternateId
6

resourceIdentifer

payloadStringericsson-enm-gnbdu:GNBDUFunction=1RequiredRemainder of FDN ?
7

targetFdn

payloadStringMEContext=RadioNode-0001,ManagedElement=RadioNode-0001RequiredFDN to 'CM-Handle' ?!
8

cmChangeRequest

payloadObject
RequiredCM Change Request
Sample Body
{
  "payloadType": "CM_Write",
  "decisionType": "Allow",
  "payload": [
    {
      "cmHandleId": "F811AF64F5146DFC545EC60B73DE948E",
      "resourceIdentifier": "some-resource-id",
      "targetFdn": "MEContext=RadioNode-K6_0001,ManagedElement=RadioNode-K6_0001",
      "cmChangeRequest": {
        "Cell": [
          {
            "id": "Cell-id",
            "attributes": {
              "administrativeState": "UNLOCKED"
            }
          }
        ]
      }
    }
  ]
}


Output Parameters


NameParentTypeExampleOptional/CompulsoryNotes
1decisionIdbodyString
RequiredUUID
2decisionbodyStringDenyRequiredcurrently only 'Allow' and 'Deny' are supported
(case sensitive ?!)
3messagebodyString 
Optional

How to use the Interface in NCMP

Pseudo Code
  IF property "CONFLICT_MANAGER_CLIENT_ENABLED" is set to "true" THEN
        DEFINE class NetworkCmProxyDataServiceInterceptor which EXTENDS NetworkCmProxyDataServiceImpl 
		
        INJECT ConflictManagerApiClient conflictManagerApiClient
		CREATE defaultPermitOnError AS boolean
		
		// Define a method named writeResourceDataPassThroughRunningForCmHandle that overrides the method from the parent class
		METHOD writeResourceDataPassThroughRunningForCmHandle(cmHandleId, resourceIdentifier, operationType, requestData, dataType, authorization)
			targetFdn = CALL createTargetFdn(cmHandleId)
			evaluationRequest = CALL createEvaluationRequest(cmHandleId, resourceIdentifier, targetFdn, requestData)
			TRY
				evaluatedResponse = CALL conflictManagerApiClient.evaluateRequest(evaluationRequest)
				RETURN CALL processResponseFromConflictManager(evaluatedResponse, evaluationRequest, operationType, requestData, dataType, authorization)
			CATCH ResourceAccessException WITH e
				CALL log.error(CONVERT e TO String)
				RETURN CALL checkDefaultDecision(evaluationRequest, operationType, requestData, dataType, authorization)
			END TRY
		END METHOD
        
		METHOD createTargetFdn(String cmHandleId)
			ncmpServiceCmHandle = CALL getNcmpServiceCmHandle(cmHandleId)
			dmiProperties = CALL getDmiProperties ON ncmpServiceCmHandle
			CREATE targetFdn AS new StringJoiner
			IF dmiProperties contains key "targetDnPrefix" AND dmiProperties contains key "targetNode" THEN
				CALL add(dmiProperties.get(targetDnPrefix)) ON targetFdn
				CALL add(dmiProperties.get(targetNode)) ON targetFdn
				RETURN targetFdn
			ELSE
				THROW InvalidPropertyException WITH (CmHandle.class, cmHandleId, "missing targetDnPrefix or targetNode from cmHandleProperties")
			END IF
		END METHOD
		
		METHOD createEvaluationRequest(cmHandleId, resourceIdentifier, targetFdn, requestData)
			CREATE evaluationRequest AS new EvaluationRequest
			CALL evaluationRequest.cmHandleId(cmHandleId)
			CALL evaluationRequest.resourceIdentifier(resourceIdentifier)
			CALL evaluationRequest.targetFdn(targetFdn)
			CALL evaluationRequest.requestData(requestData)
		END METHOD
		
		METHOD checkDefaultDecision(evaluationRequest, operationType, requestData, dataType, authorization)
			IF defaultPermitOnError IS true THEN
    			CALL log.info(""Failed to get response from Conflict Manager for fields:  cmHandleId: {}, resourceIdentifier: {}, targetFDN: {}, requestData: {}, default decision is permit",
           					   evaluationRequest.getCmHandleId(),
                               evaluationRequest.getResourceIdentifier(),
                               evaluationRequest.getTargetFdn(),
                               requestData)
			    RETURN super.writeResourceDataPassThroughRunningForCmHandle(evaluationRequest.getCmHandleId(),
																		    evaluationRequest.getResourceIdentifier(), operationType, requestData, dataType, authorization)
			ELSE
			     CALL log.info("Failed to get response from Conflict Manager for fields:  cmHandleId: {}, resourceIdentifier: {}, targetFDN: {}, requestData: {}, default decision is deny",
           					   evaluationRequest.getCmHandleId(),
                               evaluationRequest.getResourceIdentifier(),
                               evaluationRequest.getTargetFdn(),
                               requestData)
				THROW DataInUseException WITH ("Change request denied by Conflict Manager for reason: failed to get response from Conflict Manager, default decision is deny.",
          "Check logs for details.")
		END METHOD
		
		METHOD processResponseFromConflictManager(evaluatedResponse, evaluationRequest, operationType, requestData, dataType, authorization)
			IF evaluatedResponse.getDecision() NOT NULL AND evaluatedResponse.getDecision() EQUALS ResponseDecisionEnum.PERMIT THEN
				RETURN super.writeResourceDataPassThroughRunningForCmHandle(evaluationRequest.getCmHandleId(),
																			evaluationRequest.getResourceIdentifier(), operationType, requestData, dataType, authorization)
			ELSE IF evaluatedResponse.getDecision() NOT NULL AND evaluatedResponse.getDecision() EQUALS ResponseDecisionEnum.DENY THEN
				CALL log.info("Change request denied by Conflict Manager for fields cmHandleId: {}, resourceIdentifier: {}, targetFDN: {}, requestData: {}",
           					   evaluationRequest.getCmHandleId(),
                               evaluationRequest.getResourceIdentifier(),
                               evaluationRequest.getTargetFdn(),
                               requestData)
				THROW DataInUseException WITH ("Change request denied by Conflict Manager for reason: "  + evaluatedResponse.getReason(), "Check logs for details.")
			ELSE IF evaluatedResponse.getDecision() NOT NULL AND evaluatedResponse.getDecision() EQUALS ResponseDecisionEnum.PREEMPT THEN
				CALL log.info("Change request preempt by Conflict Manager for fields cmHandleId: {}, resourceIdentifier: {}, targetFDN: {}, requestData: {}", 
                               evaluationRequest.getCmHandleId(),
                               evaluationRequest.getResourceIdentifier(),
                               evaluationRequest.getTargetFdn(),
                               requestData)
				RETURN super.writeResourceDataPassThroughRunningForCmHandle(evaluationRequest.getCmHandleId(), evaluationRequest.getResourceIdentifier(), operationType, requestData, dataType, authorization)
			ELSE
				RETURN CALL checkDefaultDecision(evaluationRequest, operationType, requestData, dataType, authorization)
		END METHOD
  • No labels