Hi

I am happy to announce that a new xtesting security docker has been integrated 
end of last week.

This new docker includes 3 new tests dealing with security:
- root_pods: we check that the pods are not run as root
- unlimitted_pods: we check that limits have been set for each pod
- cis_kubernetes: we perform the CIS security suite implemented by aquasecurity 
based on CIS requirements and defined as a Security requirement by Seccom for 
Frankfurt (https://jira.onap.org/browse/REQ-243)
root_pods and unlimitted_pods have been provided by F.Rouzaut involved in 
Seccom.
Additional tests (port scan) are already available 
(https://git.onap.org/integration/tree/test/security) and will be added very 
soon in the docker to complete the test suite.

All the security tests have been declared under the security project in the 
test DB: http://testresults.opnfv.org/onap/api/v1/projects/security/cases

The good news is that the tests are now integrated and are run in the CI chains
- Daily El Alto
- Daily Master (future Frankfurt): e.g. 
https://gitlab.com/Orange-OpenSource/lfn/onap/xtesting-onap/-/jobs/415571519
- Gating: e.g. 
https://gitlab.com/Orange-OpenSource/lfn/onap/xtesting-onap/-/jobs/415455149
For the moment these chains are running on Orange labs (Daily + gating) + Azure 
(gating). But any lab can add this docker as part of its chains.

The bad new is that there are all failing for the moment.. 
(https://gitlab.com/Orange-OpenSource/lfn/onap/xtesting-onap/-/jobs/415571519/artifacts/download)
- regarding root_pods (135 on 240 pods launched as root) and unlimitted_pods, 
it is up to the project to fix the issues by modifying their docker build chain 
(not using root user) and/or fix limit in their helm charts.
- regarding cis tests, 34 assertions are fail .
It is not directly linked to ONAP but has to be fixed at k8s installation 
whatever the installer (rke, kubespray)

Note port scannings to be added show also some open ports.

We may add a topic for the PTL meeting on these new tests and also a topic to 
remind best practices on Gating

/Morgan



_________________________________________________________________________________________________________________________

Ce message et ses pieces jointes peuvent contenir des informations 
confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce 
message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages 
electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou 
falsifie. Merci.

This message and its attachments may contain confidential or privileged 
information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete 
this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been 
modified, changed or falsified.
Thank you.


-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.

View/Reply Online (#5870): https://lists.onap.org/g/onap-tsc/message/5870
Mute This Topic: https://lists.onap.org/mt/70151091/21656
Group Owner: onap-tsc+ow...@lists.onap.org
Unsubscribe: https://lists.onap.org/g/onap-tsc/leave/2743226/1412191262/xyzzy  
[arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to