14:31:58 #startmeeting Integration weekly sync meeting 05/02/2020 14:31:58 Meeting started Wed Feb 5 14:31:58 2020 UTC. The chair is morgan_orange. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:31:58 Useful Commands: #action #agreed #help #info #idea #link #topic. 14:31:58 The meeting name has been set to 'integration_weekly_sync_meeting_05_02_2020' 14:32:28 #topic action point follow-up 14:32:40 #info AP1: morgan asks for LF FQDN + certificates 14:32:50 #info discussion done, for the certificates => use let's encrypt and for the FQDN LF relunctant from a legal perspective to referent a web site it does not manage, possible workaround to use another domain 14:32:56 #info AP2: bartek add tox for vCPE and vagrant files 14:33:01 #info done WIP 14:33:06 #info AP3: morgan_orange add verification-python in ci-management for integration 14:33:18 #info done WIP: https://gerrit.onap.org/r/c/ci-management/+/100985 14:33:25 #info AP4: organize ad hoc meeting with lab owners to share tooling and best practices 14:33:30 #info not done yet 14:33:35 #action morgan_orange organize ad hoc meeting with lab owners to share tooling and best practices 14:33:40 #info AP5: morgan_orange contact Kzrysztof for several updates (dcae discussion/pnf_registrate/..) 14:33:46 #info done topic planned this week 15:01:38 #topic Syncho with Seccom / OOM 15:02:12 #info several security tests have been added in CI, the goal of the meeting was to agree on SECCOM/OOM/Integration position and prepare the PTL meeting 15:02:45 #agreed pod_root is priority one, we must not have pod run as root in Frankfurt. The build chain shall be reviewed and user must be used 15:02:56 #undo 15:02:56 Removing item from minutes: 15:03:04 #info pod_root is priority one, we must not have pod run as root in Frankfurt. The build chain shall be reviewed and user must be used 15:03:07 #agreed 15:03:44 #info java debug port must be closed - but be careful there are probably false positive (redis default port in dcae) 15:03:56 #action pawel complete the scripts to exclude false positive 15:04:38 #info cis: it will be hard to fix everything ... if we want to keep ONAP up&running, in other word it is possible to become cis compliant but ONAP will not run anymore 15:05:35 #info goal is to reduce the number of FAIL + keep ONAP runnable + evaluate modifications for next release to move to a CIS compliant k8S for ONAp (somehow problems ~ to those reported leading to non cloud native solution at the end) 15:06:38 #info http ports - not trivial. The solution consisting in stopping exposing some of them may lead to side effects (Serve mesh PoC could not work in some conditions) 15:08:57 #info we need to review the list of the current 20 http open ports (robot, portal-sdk, portal-app, message-router, dmaap-bc, log-kibana, log-es, dmaap-dr-prov, cli , consul-server-ui, sniro-emulator , refrepo , uui , config-binding-service , dashboard, netbox-nginx, music-tomcat , cds-blueprints-processor-http, aaf-fs 15:09:10 #info some exceptions are already known: aaf-fs 15:09:56 #info the goal for Frankfurt is to close what is really not needed 15:10:51 #topic Admin 15:11:07 #info Specific Integration milestones to be defined and reported to David McBride 15:11:14 #link https://wiki.onap.org/display/DW/Integration+M4+milestone+possible+evolution 15:11:37 #action all review the page and adjust the criteria / morgan to report to David before the end of the week 15:12:04 #info Update on Integration verification job: WIP, ci-management job has been merged, tox.ini to be introduced by Bartek 15:12:09 #topic lab status 15:12:56 #info gitlab runner installed on windriver lab, first tests showed that it was possible to trigger CI chains from gitlab.com on windriver through the runner without the VPN, so it should be possible to launch Daily CI chain in windriver lab 15:13:08 #topic Frankfurt status 15:13:53 #info CI status: Master relatively stable over the last days: only 3 pods failed today but APPC healthcheck is failing (as well as OOF and VFC), distribution and End to End tests are failing 15:14:03 #action morgan_orange create JIRA on OOF and VFC 15:14:48 #info Use case update (Selenium, DCAE update,..) => Krzstztof and Brian not present, lets sync by maul 15:14:58 #topic AoB 15:15:24 #info Bartek about to submit the tox.ini to introduce verification in integration repository 15:16:00 #info vCPE use case: SDNC DB bug fixed by SDNC team, but new issues probably due to ONAP instability 15:16:51 #info Pawel:update on the tests planned (especially to manage false positive). Pawel aso suggests to move ingress_nodeports to infrastructure healthcheck category (not really security) 15:17:09 #action morgan move ingress_nodeport to infrastructure-healthcheck 15:17:25 #info morgan integration of kube-hunter from aquasecurity in progress 15:17:58 #endmeeting