Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

No.Project NameTSC Subgroup Release StatusIs this your first release Going for Maturity Review? 

CD Logs URL to be used for review

(Column filled in by PTLs)

How to: Push Logs to Nexus

Jenkins Master for Private Lab

Jenkins Peering Guide

Example: 

KubeEdge BP Test Documents

Link to executive one pager

(editable doc format)

(Column filled in by PTLs)

API Info Reporting Review

(Column filled in by API Subcommittee)

(note for PTLs – go here for steps to fill in project API info form)

BluVal

Certification

Bluval User Guide

Security

Certification

Provide link to Vuls, Lynis, and Kube-Hunter logs below.

Pass/Fail Criteria:  Steps To Implement Security Scan Requirements

Exception requests should be filed at:

https://wiki.akraino.org/display/AK/Akraino+CVE+Vulnerability+Exception+Request

Upstream Review (Column filled by Upstream Subcommittee and PTLs)


(note PTL can go to Release Upstream Compliance to find details)

Date ready for TSC review

(Column filled in by PTLs)

 TSC Review Date

(Column filled in by TSC)

1scheduled at 

TSC 2020-12-01 (Tues) 7 am Pacific

NY

https://nexus.akraino.org/content/sites/logs/parserlabs/r4/jobs/cvb/

Form uploaded

Scheduled for API subcommittee review

Waiting for re-uploaded API info form with PaaS API info

Reviewed by API subcommittee, PaaS APIs are subset of TARS APIs

Accepted

 

Vuls:  Accepted with exceptions shown at:

Release 4 Vuls Exception Reques

https://nexus.akraino.org/content/sites/logs/parserlabs/r4/jobs/cvb/


 

Lynis:  Accepted with exceptions shown at:

Release 4 Lynis Exceptions

https://nexus.akraino.org/content/sites/logs/parserlabs/r4/jobs/cvb/lynis_updated_26.log


Kube-Hunter:  Exception granted:  K8s not used by this BP.

Yes12/01
2scheduled at 

TSC 2020-12-01 (Tues) 7 am Pacific

NY

https://nexus.akraino.org/content/sites/logs/parserlabs/r4/jobs/iec-type4/

Form uploaded

Scheduled for API subcommittee review

Waiting for re-uploaded API info form with PaaS API info 

Reviewed by API subcommittee, PaaS APIs are subset of TARS APIs

Accepted

 

Vuls:  Accepted with exceptions shown at:

Release 4 Vuls Exception Request

https://nexus.akraino.org/content/sites/logs/parserlabs/r4/jobs/iec-type4/


 

Lynis:  Accepted with exceptions shown at:

Release 4 Lynis Exceptions

https://nexus.akraino.org/content/sites/logs/tencent/MR/iec-type4/


Kube-Hunter:  Exception granted:  K8s not used by this BP.

Yes12/01
3Scheduled at Release 4 Review 2020-12-01 (Tues) 7 am PacificNMature

https://nexus.akraino.org/content/sites/logs/att/job/Install_REC_on_OpenEdge1/

https://logs.akraino.org/production/vex-yul-akraino-jenkins-prod-1/rec-aarch64_baremetal-install-rec-weekly-master/

Form uploaded

Reviewed by API subcommittee

Accepted

https://nexus.akraino.org/content/sites/logs/att/job/Bluval_Logs/results-11-27-2020.tar

https://nexus.akraino.org/content/sites/logs/att/job/Bluval_Logs/results-2021-02-01/

 

VulsAccepted with exceptions shown at:

Release 4 Vuls Exception Request


 

Lynis:  Accepted with exceptions shown at:

Release 4 Lynis Exceptions


Kube-Hunter:  Accepted with exceptions shown at:

Release 4 Kube-Hunter Exceptions

Yes12/01
4Scheduled at 

Release 4 Review 2020-12-16 (Wed) 7 am Pacific

NN

ICN Master Baremetal Deployment Verifier

ICN Master Virtual Deployment Verifier

ICN SDEWAN Master End2End Testing

Form uploaded

Reviewed by API subcommittee

Accepted

https://nexus.akraino.org/content/sites/logs/intel/bluval_results/icn/master/20201210-010310/.

https://nexus.akraino.org/content/sites/logs/intel/bluval_results/icn/master/20201210-010310/

ICN R4 Test Document#BluValTesting

Vuls:  Accepted with exceptions shown at:

Release 4 Vuls Exception


Lynis:  Accepted with exceptions shown at:

Release 4 Lynis Exceptions


k8s/conformance:

Kube-Hunter:  Accepted

  • The logs show the run with the aquasec/kube-hunter:edge image to fix the CAP_NET_RAW inside a pod issue


Yes12/1012/16
5scheduled at 

TSC 2020-12-16 (Tues) 7 am Pacific

NN

https://nexus.akraino.org/content/sites/logs/huawei/blueprints/iotgateway/job/eliot-iotgateway-deploy-k8s-virtual-daily-master/684/

ELIOT R4 IOT-Gateway Datasheet

Form uploaded

Reviewed by API subcommittee  

Accepted

https://nexus.akraino.org/content/sites/logs/huawei/blueprints/iotgateway/job/eliot-iotgateway-bluval-virtual-daily-master/37/results/os/lynis/lynis.log

vuls exceptions Akraino CVE Vulnerability Exception Request

Akraino BluVal Exception Request

 

Vuls:  Accepted with exceptions shown at:

Release 4 Vuls Exception

Lynis: Accepted with exceptions shown at:

Release 4 Lynis Exceptions

Kube-Hunter:  Accepted with exceptions shown at:

Release 4 Kube-Hunter Exceptions

Yes12/08
6scheduled at 

TSC 2020-12-16 (Tues) 7 am Pacific

NNhttps://nexus.akraino.org/content/sites/logs/huawei/blueprints/uCPE/job/eliot-uCPE-deploy-k8s-centos-virtual-daily-master/545/ELIOT R4 - SD-WAN / WAN Edge / uCPE Data Sheet

Form uploaded

Reviewed by API subcommittee  

Accepted

https://nexus.akraino.org/content/sites/logs/huawei/blueprints/uCPE/job/eliot-uCPE-deploy-k8s-centos-virtual-daily-master/549/results/os/lynis/lynis.log

vuls exceptions Akraino CVE Vulnerability Exception Request

Akraino BluVal Exception Request

 

Vuls:  Accepted with exceptions shown at:

Release 4 Vuls Exception

Lynis: Accepted with exceptions shown at:

Release 4 Lynis Exceptions

Kube-Hunter:  Accepted with exceptions shown at:

Release 4 Kube-Hunter Exceptions

Yes12/08
7

Scheduled at

Release 4 Review 2020-12-09 (Wed) 7:30am


NNot Applicable

https://nexus.akraino.org/content/sites/logs/juniper/job/NC-Tungsten_Fabric/40/


https://nexus.akraino.org/content/sites/logs/juniper/validation-2021/



NetworkCloud-TF blueprint Datasheet.docx

Form uploaded

Scheduled for API subcommittee review

Reviewed by API subcommittee 

Accepted

Y

 

Vuls: Accepted with exceptions shown at:

Release 4 Vuls Exception


 

Lynis:  Accepted with exceptions shown at:

Release 4 Lynis Exceptions

Note there were exceptions granted for mandatory incubation items that must be fixed in the next incubation level release as well as other items that must be fixed for maturity.


 

Kube-Hunter:  Accepted with exceptions shown at:

Release 4 Kube-Hunter Exceptions

Yes12/0912/09
8Scheduled at 

TSC 2020-12-17 (Thurs) 7 am Pacific

NN

AWS footprint:
https://logs.akraino.org/production/vex-yul-akraino-jenkins-prod-1/kni-blueprint-pae-verify-deploy-aws/81/

GCP footprint:

https://logs.akraino.org/production/vex-yul-akraino-jenkins-prod-1/kni-blueprint-pae-verify-deploy-gcp/51/


Form uploaded

Reviewed by API subcommittee

Accepted

https://nexus.akraino.org/content/sites/logs/redhat-kni/bluval_results_pae/

 

Vuls:  Accepted with exception.  The KNI Provider Access Edge blueprint uses OpenShift as its k8s distribution, which is deployed on Red Hat CoreOS, an immutable OS that is not supported by Vuls.

https://nexus.akraino.org/content/sites/logs/redhat-kni/bluval_results_pae/os/vuls/log.html.gz


Lynis:

 

https://nexus.akraino.org/content/sites/logs/redhat-kni/bluval_results_pae/os/lynis/

Accepted with exceptions shown at:

Release 4 Lynis Exceptions


Kube-Hunter: 

https://nexus.akraino.org/content/sites/logs/redhat-kni/bluval_results_pae/k8s/kube-hunter/Kube-Hunter.Kube-Hunter/

Accepted with exceptions shown at:

Release 4 Kube-Hunter Exceptions

Yes12/0912/09
9


Slides for KNI blueprints review:

Akraino_KNI_Release4_Review.pdf

Scheduled at 

TSC 2020-12-17 (Thurs) 7 am Pacific

YN

Mgmt Hub logs:

https://logs.akraino.org/production/vex-yul-akraino-jenkins-prod-1/kni-blueprint-management-hub-verify-deploy-gcp/9/

IE logs:

https://logs.akraino.org/production/vex-yul-akraino-jenkins-prod-1/kni-blueprint-ie-verify-deploy-gcp/2/


Form uploaded

Reviewed by API subcommittee

Accepted

https://nexus.akraino.org/content/sites/logs/redhat-kni/bluval_results_ie/

 

Vuls:  Accepted with exception.  The KNI Industrial Edge blueprint uses OpenShift as its k8s distribution, which is deployed on Red Hat CoreOS, an immutable OS that is not supported by Vuls.

https://nexus.akraino.org/content/sites/logs/redhat-kni/bluval_results_ie/os/vuls/log.html.gz


Lynis:

https://nexus.akraino.org/content/sites/logs/redhat-kni/bluval_results_ie/os/lynis/

Accepted with exceptions shown at:

Release 4 Lynis Exceptions



Kube-Hunter: 

https://nexus.akraino.org/content/sites/logs/redhat-kni/bluval_results_ie/k8s/kube-hunter/Kube-Hunter.Kube-Hunter/

Accepted with exceptions shown at:

Release 4 Kube-Hunter Exceptions

Yes

10

Micro-MEC - moved to LTS


YNhttps://nexus.akraino.org/content/sites/logs/micromecAkraino R3 MicroMEC blueprint datasheet.docx

Form uploaded  

API committee review scheduled for

Reviewed by API subcommittee

Accepted

N/A





11

Scheduled at TSC 2020-11-24 (Tues) 7 am Pacific

NN

https://nexus.akraino.org/content/sites/logs/baidu/job/aiedge-otestack-master-deploy/

https://nexus.akraino.org/content/sites/logs/baidu/job/aiedge-otestack-master-validation/

Hechun replied by e-mail 12Jan, API info form is in progress

Form uploaded  

API committee review tentatively scheduled for

Reviewed by API subcommittee  

Accepted

https://nexus.akraino.org/content/sites/logs/baidu/job/bluval/aiedge/results/

24 Feb

Kube-Hunter: The following items must be fixed for maturity approval, these tests and results can be found in the cluster.log file:

  1. KHV005 - Unauthenticated access to API
  2. KHV002 - K8s Version Disclosure

The following items must be fixed for maturity approval, these tests and results can be found in the pod.log file:

  1.  Access to pod's secrets.  Accessing the pod's secrets within a compromised pod might disclose valuable data to a potential attacker.
  2. KHV050 - Read access to pod's service account token.  Accessing the pod service account token gives an attacker the option to use the server API.

Some Kubernetes remediation steps are shown on the following link in the kube-hunter section:

Steps To Implement Security Scan Requirements#KubeHunterIncubationandMaturityPASSFAILKube-HunterIncubationandMaturity:PASS/FAILCriteria,v1.0

Release 4 Kube-Hunter Exceptions

Exception granted for CAP_NET_RAW issue

  Accepted with exceptions shown at:

Release 4 Kube-Hunter Exceptions


Note:  There are 4 issues that must be fixed prior to the next Incubation OR Maturity release.
Yes (Please also update the upstream version besides the repo name)06/02
12
YNhttps://nexus.akraino.org/content/sites/logs/webank/job/xinhong/

Form uploaded 

API subcommittee review scheduled for 

Reviewed by API Subcommittee  

Accepted

N/A

https://nexus.akraino.org/content/sites/logs/webank/job/xinhong/

 

Vuls:  Accepted with exceptions shown at:

Release 4 Vuls Exception Request


Lynis: 

The following must be fixed for incubation:

  1. Test ID BOOT-5122 (Check for GRUB boot password) : Must Pass
  2. Test: Checking PASS_MAX_DAYS option in /etc/login.defs : Must Pass
  3. Test ID AUTH-9328 (Default umask values) : Must Pass
  4. Test ID SSH-7440 (Check OpenSSH option: AllowUsers and AllowGroups) : Must Pass
  5. sysctl key fs.suid_dumpable : Must Pass
  6. sysctl key kernel.dmesg_restrict : Must Pass
  7. sysctl key net.ipv4.conf.default.accept_source_route : Must Pass
  8. The following compilers must be removed:- /usr/bin/as- /usrbin/cc- /usr/bin/g++- /usr/bin/gcc

Kube-Hunter:  Exception granted:  K8s not used by this BP.

Yes (Please update the upstream versions besides the repo name)

13
YN

https://nexus.akraino.org/content/sites/logs/tencent/job/tencent_5g_mec/

Form uploaded  

Reviewed by API subcommittee

Accepted

N/A

Lynis: Accepted with exceptions shown at:

Release 4 Lynis Exceptions


Kube-Hunter: 

Accepted with exceptions shown at:

Release 4 Kube-Hunter Exceptions

Please update the release note with upstream information (R4 - Release Notes)06/03
14

Scheduled at

TSC 2021-02-04 (Thurs) 7 am PT

NNhttps://nexus.akraino.org/content/sites/logs/arm-china/jenkins092/iec-type3-android-cloud-ubuntu1804-daily-master/job/nvdroid/17/ IEC Release4-IEC Type3-datasheet.docx

Hanyu replied by e-mail  that they have no APIs offered or consumed. API subcommittee replied they still need to fill out the API info reporting form with BP name and Comments field explaining current and future API status, and upload the form

Form uploaded  

Reviewed by API Subcommittee  

Accepted

Bluval Exception has been accepted

Akraino BluVal Exception Request

https://nexus.akraino.org/content/sites/logs/arm-china/jenkins092/iec-type3-android-cloud-ubuntu1804-daily-master/job/nvdroid/34/ 

Lynis:  Accepted with exceptions shown at:

Release 4 Lynis Exceptions


Kube-Hunter:  Exception granted:  K8s not used by this BP.

Yes02/04
15Scheduled at 

TSC 2020-12-10 (Thurs) 7 am Pacific

NN

https://nexus.akraino.org/content/sites/logs/cmti/job/iec5_r4/15/

Form uploaded

Scheduled for API subcommittee review

Reviewed by API subcommittee

Accepted

Bluval Exception has been accepted for the project.

Akraino BluVal Exception Request

Kube-Hunter:  Exception granted:  K8s not used by this BP.

Yes

16scheduled at 

TSC 2020-12-10(Thurs) 7 am Pacific

NN

https://nexus.akraino.org/content/sites/logs/huawei/blueprints/ealt-edge/job/ealt-edge-deploy-virtual-daily-master/397

Form uploaded

Reviewed by API subcommittee

Accepted

https://nexus.akraino.org/content/sites/logs/huawei/blueprints/ealt-edge/job/ealt-edge-bluval-daily-master/251/results/

Vuls Exception Akraino CVE Vulnerability Exception Request

Akraino BluVal Exception Request

updated results link - 09-dec

Yes12/10
17

Scheduled at TSC 2021-1-14 (Thurs) 7 am Pacific

PCEI Time Slot 7:30-8:00 am Pacific

Y
https://nexus.akraino.org/content/sites/logs/cmti/job/pcei-daily/PCEI R4 Datasheet

Form uploaded 4Jan

Scheduled for API subcommittee review  

For R4, third-party location API provided as an example in PCEI architecture diagrams. For R5 they expect PCEI APIs to be exported

Reviewed by API subcommittee

Accepted

https://nexus.akraino.org/content/sites/logs/pcei/job/v1/

New BluVal logs 2021-01-08:

https://nexus.akraino.org/content/sites/logs/pcei/job/v2/results/

 

Updated BluVal logs with fixed sysctl key net.ipv4.conf.default.accept_source_route

https://nexus.akraino.org/content/sites/logs/pcei/job/v3/

 

Updated BluVal logs with fixed Kube-Hunter Vulnerability KHV050, KHV002, KHV005

https://nexus.akraino.org/content/sites/logs/pcei/job/v4/


 

Vuls:

Vuls:  Accepted with exceptions shown at:

Release 4 Vuls Exception Request

vuls.log included in the new logs (V2)

Lynis:  Accepted with exceptions shown at:

Release 4 Lynis Exceptions

Kube-Hunter:

Accepted with exceptions shown at:

Release 4 Kube-Hunter Exceptions


Yes01/14/21
18Scheduled at 

TSC 2020-12-08 (Tues) 7 am Pacific

YNhttps://nexus.akraino.org/content/sites/logs/webank/job/Federated ML application at edge R4 Datasheet

Form uploaded

Reviewed by API subcommittee

Accepted

N/AYes12/08
19Scheduled at Release 4 Review 2020-11-17 (Tue) 7 am PacificYNhttps://nexus.akraino.org/content/sites/logs/futurewei/kubeedgees/KubeEdge Edge Service Blueprint Release 4 datasheet

Form uploaded

Reviewed by API subcommittee

Accepted

Yes

https://nexus.akraino.org/content/sites/logs/futurewei/kubeedgees/58/results/

Akraino BluVal Exception Request

 

Vuls:  Accepted with exceptions shown at:

Release 4 Vuls Exception Request

 

Lynis:  Accepted

Kube-Hunter: Exception granted:  KubeEdge node is not on same subnet as the cloud node.  Communication occurs through the websocket endpoint, so kube-hunter can't be used.

Yes11/17
20

Scheduled at 

Release 4 Review 2021-02-25 



YNhttps://nexus.akraino.org/content/sites/logs/juniper/job/Private%205G%20BP/Akraino Private LTE/5G BP Datasheet

Prem replied by e-mail 17Jan, API info form is in progress

Form uploaded  

API committee review scheduled for

Reviewed by API subcommittee  

Accepted

N/A

Private 5G/LTE is using Tungsten Fabric hosts and Kubernetes orchestration.

Vuls:  Accepted using Network Cloud and TF approval

Lynis: Accepted using Network Cloud and TF approval

Kube-Hunter:  Accepted using Network Cloud and TF approval

See:  Network Cloud and TF (Tungsten Fabric) Integration Project

Yes 02/24
21Scheduled at Release 4 Review 2020-12-09 YNhttps://nexus.akraino.org/content/sites/logs/ai_solutions/job/Eden-flir/

Form uploaded

Reviewed by API subcommittee  , waiting for revised API info form to be uploaded

2nd revision of form uploaded   by V S

Final review by API subcommittee set for

Reviewed by API subcommittee

Accepted

Have an exceptionYes12/09


...