Hi Morgan and Team, I updated the pipelines in the DT Lab to include the additional security checks. - Daily Master - Daily ElAlto (new pipeline) I still need to check the results and most likely have to modify smaller parts, but tomorrow the tests should run.
Thanks for the work… Best regards Andreas Von: onap-tsc@lists.onap.org <onap-tsc@lists.onap.org> Im Auftrag von Morgan Richomme via Lists.Onap.Org Gesendet: Montag, 27. Januar 2020 11:44 An: onap-disc...@lists.onap.org; onap-tsc@lists.onap.org Cc: ROUZAUT Fabian TGI/OLN <fabian.rouz...@orange.com>; p.wieczor...@samsung.com; az9...@att.com Betreff: [onap-tsc] [ONAP] [CI][Integration] security tests integration in ONAP CI chains Hi I am happy to announce that a new xtesting security docker has been integrated end of last week. This new docker includes 3 new tests dealing with security: - root_pods: we check that the pods are not run as root - unlimitted_pods: we check that limits have been set for each pod - cis_kubernetes: we perform the CIS security suite implemented by aquasecurity based on CIS requirements and defined as a Security requirement by Seccom for Frankfurt (https://jira.onap.org/browse/REQ-243) root_pods and unlimitted_pods have been provided by F.Rouzaut involved in Seccom. Additional tests (port scan) are already available (https://git.onap.org/integration/tree/test/security) and will be added very soon in the docker to complete the test suite. All the security tests have been declared under the security project in the test DB: http://testresults.opnfv.org/onap/api/v1/projects/security/cases The good news is that the tests are now integrated and are run in the CI chains - Daily El Alto - Daily Master (future Frankfurt): e.g. https://gitlab.com/Orange-OpenSource/lfn/onap/xtesting-onap/-/jobs/415571519 - Gating: e.g. https://gitlab.com/Orange-OpenSource/lfn/onap/xtesting-onap/-/jobs/415455149 For the moment these chains are running on Orange labs (Daily + gating) + Azure (gating). But any lab can add this docker as part of its chains. The bad new is that there are all failing for the moment.. (https://gitlab.com/Orange-OpenSource/lfn/onap/xtesting-onap/-/jobs/415571519/artifacts/download) - regarding root_pods (135 on 240 pods launched as root) and unlimitted_pods, it is up to the project to fix the issues by modifying their docker build chain (not using root user) and/or fix limit in their helm charts. - regarding cis tests, 34 assertions are fail . It is not directly linked to ONAP but has to be fixed at k8s installation whatever the installer (rke, kubespray) Note port scannings to be added show also some open ports. We may add a topic for the PTL meeting on these new tests and also a topic to remind best practices on Gating /Morgan _________________________________________________________________________________________________________________________ Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration, Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci. This message and its attachments may contain confidential or privileged information that may be protected by law; they should not be distributed, used or copied without authorisation. If you have received this email in error, please notify the sender and delete this message and its attachments. As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified. Thank you. -=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#5879): https://lists.onap.org/g/onap-tsc/message/5879 Mute This Topic: https://lists.onap.org/mt/70151091/21656 Group Owner: onap-tsc+ow...@lists.onap.org Unsubscribe: https://lists.onap.org/g/onap-tsc/leave/2743226/1412191262/xyzzy [arch...@mail-archive.com] -=-=-=-=-=-=-=-=-=-=-=-