Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

No.Project NameTSC Subgroup Release StatusIs this your first release Going for Maturity Review? 

CD Logs URL to be used for review

(Column filled in by PTLs)

Link to executive one pager

(editable doc format)

(Column filled in by PTLs)

API Info Reporting Review

(Column filled in by API Subcommittee)

(note for PTLs – go here for steps to fill in project API info form)

BluVal

Certification

Security

Certification

Provide link to Vuls, Lynis, and Kube-Hunter logs below.

Pass/Fail Criteria:  Steps To Implement Security Scan Requirements

Exception requests should be filed at:

https://wiki.akraino.org/display/AK/Akraino+CVE+Vulnerability+Exception+Request

Upstream Review (Column filled by Upstream Subcommittee and PTLs)


(note PTL can go to Release Upstream Compliance to find details)

Date ready for TSC review

(Column filled in by PTLs)

 TSC Review Date

(Column filled in by TSC)

1scheduled at 

TSC 2020-12-01 (Tues) 7 am Pacific

NY

https://nexus.akraino.org/content/sites/logs/parserlabs/r4/jobs/cvb/

Form uploaded

Scheduled for API subcommittee review

Waiting for re-uploaded API info form with PaaS API info

Reviewed by API subcommittee, PaaS APIs are subset of TARS APIs

Accepted

 

Vuls:  Accepted with exceptions shown at:

Release 4 Vuls Exception Reques

https://nexus.akraino.org/content/sites/logs/parserlabs/r4/jobs/cvb/


 

Lynis:  Accepted with exceptions shown at:

Release 4 Lynis Exceptions

https://nexus.akraino.org/content/sites/logs/parserlabs/r4/jobs/cvb/lynis_updated_26.log


Kube-Hunter:  Exception granted:  K8s not used by this BP.

Yes12/01
2scheduled at 

TSC 2020-12-01 (Tues) 7 am Pacific

NY

https://nexus.akraino.org/content/sites/logs/parserlabs/r4/jobs/iec-type4/

Form uploaded

Scheduled for API subcommittee review

Waiting for re-uploaded API info form with PaaS API info 

Reviewed by API subcommittee, PaaS APIs are subset of TARS APIs

Accepted

 

Vuls:  Accepted with exceptions shown at:

Release 4 Vuls Exception Request

https://nexus.akraino.org/content/sites/logs/parserlabs/r4/jobs/iec-type4/


 

Lynis:  Accepted with exceptions shown at:

Release 4 Lynis Exceptions

https://nexus.akraino.org/content/sites/logs/parserlabs/r4/jobs/iec-type4/lynis_updated_26.log


Kube-Hunter:  Exception granted:  K8s not used by this BP.

Yes12/01
3Scheduled at Release 4 Review 2020-12-01 (Tues) 7 am PacificNMature

https://nexus.akraino.org/content/sites/logs/att/job/Install_REC_on_OpenEdge1/

https://logs.akraino.org/production/vex-yul-akraino-jenkins-prod-1/rec-aarch64_baremetal-install-rec-weekly-master/

Form uploaded

Reviewed by API subcommittee

Accepted

https://nexus.akraino.org/content/sites/logs/att/job/Bluval_Logs/results-11-27-2020.tar

https://nexus.akraino.org/content/sites/logs/att/job/Bluval_Logs/results-112021-27-2020.tar02-01/

 

VulsAccepted with exceptions shown at:

Release 4 Vuls Exception Request


27 Jan  

Performing test ID HRDN-7220 (Check if one or more compilers are installed)

Lynis:    -ISSUES that MUST be fixed for Maturity or a more specific exception reason needs to be provided:

  • sysctl key net.ipv6.conf.all.accept_redirects has a different value than expected in scan profile. Expected=0, Real=1
  • sysctl key net.ipv6.conf.default.accept_redirects has a different value than expected in scan profile. Expected=0, Real=1
  •  Accepted with exceptions shown at:


    Release 4 Lynis Exceptions


    Kube-Hunter:  Accepted with exceptions shown at:

    Release 4 Kube-Hunter Exceptions

    Yes12/01
    4Scheduled at 

    Release 4 Review 2020-12-16 (Wed) 7 am Pacific

    NN

    ICN Master Baremetal Deployment Verifier

    ICN Master Virtual Deployment Verifier

    ICN SDEWAN Master End2End Testing

    Form uploaded

    Reviewed by API subcommittee

    Accepted

    https://nexus.akraino.org/content/sites/logs/intel/bluval_results/icn/master/20201210-010310/.

    https://nexus.akraino.org/content/sites/logs/intel/bluval_results/icn/master/20201210-010310/

    ICN R4 Test Document#BluValTesting

    Vuls:  Accepted with exceptions shown at:

    Release 4 Vuls Exception


    Lynis:  Accepted with exceptions shown at:

    Release 4 Lynis Exceptions


    k8s/conformance:

    Kube-Hunter:  Accepted

    • The logs show the run with the aquasec/kube-hunter:edge image to fix the CAP_NET_RAW inside a pod issue


    Yes12/1012/16
    5scheduled at 

    TSC 2020-12-16 (Tues) 7 am Pacific

    NN

    https://nexus.akraino.org/content/sites/logs/huawei/blueprints/iotgateway/job/eliot-iotgateway-deploy-k8s-virtual-daily-master/684/

    ELIOT R4 IOT-Gateway Datasheet

    Form uploaded

    Reviewed by API subcommittee  

    Accepted

    https://nexus.akraino.org/content/sites/logs/huawei/blueprints/iotgateway/job/eliot-iotgateway-bluval-virtual-daily-master/37/results/os/lynis/lynis.log

    vuls exceptions Akraino CVE Vulnerability Exception Request

    Akraino BluVal Exception Request

     

    Vuls:  Accepted with exceptions shown at:

    Release 4 Vuls Exception

    Lynis: Accepted with exceptions shown at:

    Release 4 Lynis Exceptions

    Kube-Hunter:  Accepted with exceptions shown at:

    Release 4 Kube-Hunter Exceptions

    Yes12/08
    6scheduled at 

    TSC 2020-12-16 (Tues) 7 am Pacific

    NNhttps://nexus.akraino.org/content/sites/logs/huawei/blueprints/uCPE/job/eliot-uCPE-deploy-k8s-centos-virtual-daily-master/545/ELIOT R4 - SD-WAN / WAN Edge / uCPE Data Sheet

    Form uploaded

    Reviewed by API subcommittee  

    Accepted

    https://nexus.akraino.org/content/sites/logs/huawei/blueprints/uCPE/job/eliot-uCPE-deploy-k8s-centos-virtual-daily-master/549/results/os/lynis/lynis.log

    vuls exceptions Akraino CVE Vulnerability Exception Request

    Akraino BluVal Exception Request

     

    Vuls:  Accepted with exceptions shown at:

    Release 4 Vuls Exception

    Lynis: Accepted with exceptions shown at:

    Release 4 Lynis Exceptions

    Kube-Hunter:  Accepted with exceptions shown at:

    Release 4 Kube-Hunter Exceptions

    Yes12/08
    7

    Scheduled at

    Release 4 Review 2020-12-09 (Wed) 7:30am


    NNot Applicable

    https://nexus.akraino.org/content/sites/logs/juniper/job/NC-Tungsten_Fabric/40/


    https://nexus.akraino.org/content/sites/logs/juniper/validation-2021/



    NetworkCloud-TF blueprint Datasheet.docx

    Form uploaded

    Scheduled for API subcommittee review  

    Accepted

    Y

     

    Vuls: Accepted with exceptions shown at:

    Release 4 Vuls Exception


     

    Lynis:  ISSUES that MUST be fixed or a more specific exception reason needs to be provided:

    1. Performing test ID AUTH-9328 (Default umask values)
    2. Test: Check if one or more compilers can be found on the system

    Following compilers found:

    • Found known binary: as (compiler) - /usr/bin/as
    • Found known binary: cc (compiler) - /usr/bin/cc
    • Found known binary: gcc (compiler) - /usr/bin/gcc

     

    Kube-Hunter:  In review

    Sukhdev Kapur has requested that the Release 3 exceptions be provided for Release 4

    Yes12/0912/09
    8Scheduled at 

    TSC 2020-12-17 (Thurs) 7 am Pacific

    NN

    AWS footprint:
    https://logs.akraino.org/production/vex-yul-akraino-jenkins-prod-1/kni-blueprint-pae-verify-deploy-aws/81/

    GCP footprint:

    https://logs.akraino.org/production/vex-yul-akraino-jenkins-prod-1/kni-blueprint-pae-verify-deploy-gcp/51/


    Form uploaded

    Reviewed by API subcommittee

    Accepted

    https://nexus.akraino.org/content/sites/logs/redhat-kni/bluval_results_pae/

     

    Vuls:  Accepted with exception.  The KNI Provider Access Edge blueprint uses OpenShift as its k8s distribution, which is deployed on Red Hat CoreOS, an immutable OS that is not supported by Vuls.

    https://nexus.akraino.org/content/sites/logs/redhat-kni/bluval_results_pae/os/vuls/log.html.gz


    Lynis:

     

    https://nexus.akraino.org/content/sites/logs/redhat-kni/bluval_results_pae/os/lynis/

    Accepted with exceptions shown at:

    Release 4 Lynis Exceptions


    Kube-Hunter: 

    https://nexus.akraino.org/content/sites/logs/redhat-kni/bluval_results_pae/k8s/kube-hunter/Kube-Hunter.Kube-Hunter/

    Accepted with exceptions shown at:

    Release 4 Kube-Hunter Exceptions

    Yes12/0912/09
    9


    Slides for KNI blueprints review:

    Akraino_KNI_Release4_Review.pdf

    Scheduled at 

    TSC 2020-12-17 (Thurs) 7 am Pacific

    YN

    Mgmt Hub logs:

    https://logs.akraino.org/production/vex-yul-akraino-jenkins-prod-1/kni-blueprint-management-hub-verify-deploy-gcp/9/

    IE logs:

    https://logs.akraino.org/production/vex-yul-akraino-jenkins-prod-1/kni-blueprint-ie-verify-deploy-gcp/2/


    Form uploaded

    Reviewed by API subcommittee

    Accepted

    https://nexus.akraino.org/content/sites/logs/redhat-kni/bluval_results_ie/

     

    Vuls:  Accepted with exception.  The KNI Industrial Edge blueprint uses OpenShift as its k8s distribution, which is deployed on Red Hat CoreOS, an immutable OS that is not supported by Vuls.

    https://nexus.akraino.org/content/sites/logs/redhat-kni/bluval_results_ie/os/vuls/log.html.gz


    Lynis:

    https://nexus.akraino.org/content/sites/logs/redhat-kni/bluval_results_ie/os/lynis/

    Accepted with exceptions shown at:

    Release 4 Lynis Exceptions



    Kube-Hunter: 

    https://nexus.akraino.org/content/sites/logs/redhat-kni/bluval_results_ie/k8s/kube-hunter/Kube-Hunter.Kube-Hunter/

    Accepted with exceptions shown at:

    Release 4 Kube-Hunter Exceptions

    Yes

    10

    Micro-MEC


    YNhttps://nexus.akraino.org/content/sites/logs/micromecAkraino R3 MicroMEC blueprint datasheet.docx

    Form uploaded  

    API committee review scheduled for

    Accepted

    N/A





    11

    Scheduled at TSC 2020-11-24 (Tues) 7 am Pacific

    NY

    https://nexus.akraino.org/content/sites/logs/baidu/job/aiedge-otestack-master-deploy/

    https://nexus.akraino.org/content/sites/logs/baidu/job/aiedge-otestack-master-validation/

    Hechun replied by e-mail 12Jan, API info form is in progress

    Form uploaded  

    API committee review tentatively scheduled for

    N/A


    Yes (Please also update the upstream version besides the repo name)06/02
    12
    YN
    Need one-pager


    Yes (Please update the upstream versions besides the repo name)

    13
    YN

    https://nexus.akraino.org/content/sites/logs/tencent/job/tencent_5g_mec/

    Form uploaded  

    Accepted

    N/A

    Lynis: Accepted with exceptions shown at:

    Release 4 Lynis Exceptions


    Kube-Hunter: 

    Accepted with exceptions shown at:

    Release 4 Kube-Hunter Exceptions

    Please update the release note with upstream information (R4 - Release Notes)06/03
    14

    Scheduled at

    TSC 2021-1-28 (Thurs) 7 am Pacific

    NNhttps://nexus.akraino.org/content/sites/logs/arm-china/jenkins092/iec-type3-android-cloud-ubuntu1804-daily-master/job/nvdroid/17/ IEC Release4-IEC Type3-datasheet.docx

    PTL replied by e-mail  that they have no APIs offered or consumed. API subcommittee replied they still need to fill out the API info reporting form with BP name and Comments field explaining current and future API status, and upload the form

    Form uploaded  

    Reviewed by API Subcommittee  

    Accepted

    Bluval Exception has been accepted

    Akraino BluVal Exception Request

    Vuls:vuls docker images has no arm version.


    Lynis:

    https://nexus.akraino.org/content/sites/logs/arm-china/jenkins092/iec-type3-android-cloud-ubuntu1804-daily-master/job/nvdroid/


    Kube-Hunter: do not use K8S.

    Yes02/04
    15Scheduled at 

    TSC 2020-12-10 (Thurs) 7 am Pacific

    NN

    https://nexus.akraino.org/content/sites/logs/bytedance/job/run-install-bluefield-fs/

    https://nexus.akraino.org/content/sites/logs/bytedance/job/run-install-ovs-dpdk/

    Form uploaded

    Scheduled for API subcommittee review

    Accepted



    Yes

    16scheduled at 

    TSC 2020-12-10(Thurs) 7 am Pacific

    NN

    https://nexus.akraino.org/content/sites/logs/huawei/blueprints/ealt-edge/job/ealt-edge-deploy-virtual-daily-master/397

    Form uploaded

    Reviewed by API subcommittee

    Accepted

    https://nexus.akraino.org/content/sites/logs/huawei/blueprints/ealt-edge/job/ealt-edge-bluval-daily-master/251/results/

    Vuls Exception Akraino CVE Vulnerability Exception Request

    Akraino BluVal Exception Request

    updated results link - 09-dec

    Yes12/10
    17

    Scheduled at TSC 2021-1-14 (Thurs) 7 am Pacific

    PCEI Time Slot 7:30-8:00 am Pacific

    Y
    https://nexus.akraino.org/content/sites/logs/cmti/job/pcei-daily/PCEI R4 Datasheet

    Form uploaded 4Jan

    Scheduled for API subcommittee review  

    For R4, third-party location API provided as an example in PCEI architecture diagrams. For R5 they expect PCEI APIs to be exported

    Accepted

    https://nexus.akraino.org/content/sites/logs/pcei/job/v1/

    New BluVal logs 2021-01-08:

    https://nexus.akraino.org/content/sites/logs/pcei/job/v2/results/

     

    Updated BluVal logs with fixed sysctl key net.ipv4.conf.default.accept_source_route

    https://nexus.akraino.org/content/sites/logs/pcei/job/v3/

     

    Updated BluVal logs with fixed Kube-Hunter Vulnerability KHV050, KHV002, KHV005

    https://nexus.akraino.org/content/sites/logs/pcei/job/v4/


     

    Vuls:

    Vuls:  Accepted with exceptions shown at:

    Release 4 Vuls Exception Request

    vuls.log included in the new logs (V2)

    Lynis:  Accepted with exceptions shown at:

    Release 4 Lynis Exceptions

    Kube-Hunter:

    Accepted with exceptions shown at:

    Release 4 Kube-Hunter Exceptions


    Yes01/14/21
    18Scheduled at 

    TSC 2020-12-08 (Tues) 7 am Pacific

    YNhttps://nexus.akraino.org/content/sites/logs/webank/job/Federated ML application at edge R4 Datasheet

    Form uploaded

    Reviewed by API subcommittee

    Accepted

    N/AYes12/08
    19Scheduled at Release 4 Review 2020-11-17 (Tue) 7 am PacificYNhttps://nexus.akraino.org/content/sites/logs/futurewei/kubeedgees/KubeEdge Edge Service Blueprint Release 4 datasheet

    Form uploaded

    Reviewed by API subcommittee

    Accepted

    Yes

    https://nexus.akraino.org/content/sites/logs/futurewei/kubeedgees/58/results/

    Akraino BluVal Exception Request

     

    Vuls:  Accepted with exceptions shown at:

    Release 4 Vuls Exception Request

     

    Lynis:  Accepted

    Kube-Hunter: Exception granted:  KubeEdge node is not on same subnet as the cloud node.  Communication occurs through the websocket endpoint, so kube-hunter can't be used.

    Yes11/17
    20
    Y

    need one pager

    Prem replied by e-mail 17Jan, API info form is in progress

    API committee review tentatively scheduled for



    Yes (Please update the upstream versions)

    21Scheduled at Release 4 Review 2020-12-09 YNhttps://nexus.akraino.org/content/sites/logs/ai_solutions/job/Eden-flir/

    Form uploaded

    Reviewed by API subcommittee  , waiting for revised API info form to be uploaded

    2nd revision of form uploaded   by V S

    Final review by API subcommittee set for

    Accepted

    Have an exception
    Yes12/09


    ...