|
Certs soon to expire
#aai
#policy
#policy dev-policy-xacml-pdp
#portal
#oom
Hello Bhavesh, In guilin, policy and I believe sdc uses the cert-initializer, so they are generated on the fly at container instantiation. I am not sure about aai. If you are in elalto, you may be abl
Hello Bhavesh, In guilin, policy and I believe sdc uses the cert-initializer, so they are generated on the fly at container instantiation. I am not sure about aai. If you are in elalto, you may be abl
|
By
Jorge Hernandez
· #22996
·
|
|
CLAMP org.onap.clamp.p12 certifcate expired
Sai, This error is more than likely being related to the expired dmaap certificates. Unfortunately, I don't have a good procedure to replace them. Being in Dublin, I think you're going to be running i
Sai, This error is more than likely being related to the expired dmaap certificates. Unfortunately, I don't have a good procedure to replace them. Being in Dublin, I think you're going to be running i
|
By
Jorge Hernandez
· #22978
·
|
|
CLAMP org.onap.clamp.p12 certifcate expired
That's good Sai, if you got to this point, the certificate problems between clamp and policy are solved, and now you are hitting something else. There's a known issue in Dublin where PAP loses synchro
That's good Sai, if you got to this point, the certificate problems between clamp and policy are solved, and now you are hitting something else. There's a known issue in Dublin where PAP loses synchro
|
By
Jorge Hernandez
· #22971
·
|
|
CLAMP org.onap.clamp.p12 certifcate expired
Hello Sai, I think that there must be something in the generated certificates and keystore/truststore that isn't quite right for these 2 components to talk. I think it may be worth to try out a plain
Hello Sai, I think that there must be something in the generated certificates and keystore/truststore that isn't quite right for these 2 components to talk. I think it may be worth to try out a plain
|
By
Jorge Hernandez
· #22937
·
|
|
CLAMP org.onap.clamp.p12 certifcate expired
Hello Vivek, Another possibility if you have access to a guilin lab is to get the generated keystore from the pap pod, and use it to replace the keystore in the "dublin" pap pod. In guilin, similar to
Hello Vivek, Another possibility if you have access to a guilin lab is to get the generated keystore from the pap pod, and use it to replace the keystore in the "dublin" pap pod. In guilin, similar to
|
By
Jorge Hernandez
· #22886
·
|
|
Invoking VNF REST API call as result of closed CL?
#controlloop
Hi Ken, The scenario that you described looks very similar to the vFirewall usecase. May be you know already, but take a look at the scripts that Brian F. put together for automating the scenario in t
Hi Ken, The scenario that you described looks very similar to the vFirewall usecase. May be you know already, but take a look at the scripts that Brian F. put together for automating the scenario in t
|
By
Jorge Hernandez
· #22760
·
|
|
[OOM][AAF] aaf helm release configMap too large
I've seen these, Jack. Check out this ticket for additional info: https://jira.onap.org/browse/OOM-2534 Jorge
I've seen these, Jack. Check out this ticket for additional info: https://jira.onap.org/browse/OOM-2534 Jorge
|
By
Jorge Hernandez
· #21954
·
|
|
[oom] deployment failures Frankfurt/latest
Hi Andrew, I see the same problem as I am incorporating the certInitializer into policy. The system installs fine but the individual components are unregistered (still see dmaap, portal, etc .. resour
Hi Andrew, I see the same problem as I am incorporating the certInitializer into policy. The system installs fine but the individual components are unregistered (still see dmaap, portal, etc .. resour
|
By
Jorge Hernandez
· #21867
·
|
|
ODP: [POLICY][CLAMP] Error when submitting to Policy Engine
#clamp
#policy
Hi Lukasz, The policy api component has a limitation in this release where requires you to start fresh with a database if you perform an upgrade, which seems may be the case in your situation as I'm g
Hi Lukasz, The policy api component has a limitation in this release where requires you to start fresh with a database if you perform an upgrade, which seems may be the case in your situation as I'm g
|
By
Jorge Hernandez
· #21267
·
|
|
[Frankfurt] vLB CDS bootstrap and Plicy naming modeling error
These are the latest Frankfurt images for policy, Yuriy: onap/policy-api:2.2.4 onap/policy-pap:2.2.3 onap/policy-pe:1.6.4 onap/policy-pdpd-cl:1.6.4 onap/policy-apex-pdp:2.3.2 onap/policy-xacml-pdp:2.2
These are the latest Frankfurt images for policy, Yuriy: onap/policy-api:2.2.4 onap/policy-pap:2.2.3 onap/policy-pe:1.6.4 onap/policy-pdpd-cl:1.6.4 onap/policy-apex-pdp:2.3.2 onap/policy-xacml-pdp:2.2
|
By
Jorge Hernandez
· #21234
·
|
|
[POLICY] Credentials to access policy
Hello Krzysztof, Some teams are migrating from legacy components (that will eventually will be deprecated) to non-legacy ones. Configuration is defined here ( see Values.restserver.user + .Values.rest
Hello Krzysztof, Some teams are migrating from legacy components (that will eventually will be deprecated) to non-legacy ones. Configuration is defined here ( see Values.restserver.user + .Values.rest
|
By
Jorge Hernandez
· #20997
·
|
|
[POLICY] DBDao username and password
I added a patch on top of your review, Kryzysztof, if you can take a look. It's passing healthchecks now in my side. I'll keep an eye on for the oom deploy job results, hopefully it will pass the heal
I added a patch on top of your review, Kryzysztof, if you can take a look. It's passing healthchecks now in my side. I'll keep an eye on for the oom deploy job results, hopefully it will pass the heal
|
By
Jorge Hernandez
· #20615
·
|
|
[POLICY] DBDao username and password
Hi Krysztof, Is this the patch that you are testing? https://gerrit.onap.org/r/c/oom/+/104915 If it is, I can install, give it a try and work with local folks as needed. Let me know. Jorge
Hi Krysztof, Is this the patch that you are testing? https://gerrit.onap.org/r/c/oom/+/104915 If it is, I can install, give it a try and work with local folks as needed. Let me know. Jorge
|
By
Jorge Hernandez
· #20612
·
|
|
Control loop policy error
Hello Sivakumar, The trigger_policy should point to an entry in the policies array: vIMSPolicy1 controlLoop: abatement: false controlLoopName: LOOP_Closed_Loop_vIMS_v3_0_VIMS_SPROUT0_analytics_ms time
Hello Sivakumar, The trigger_policy should point to an entry in the policies array: vIMSPolicy1 controlLoop: abatement: false controlLoopName: LOOP_Closed_Loop_vIMS_v3_0_VIMS_SPROUT0_analytics_ms time
|
By
Jorge Hernandez
· #20502
·
|
|
Control loop policy error
Hello Siva, It seems a malformed policy. I take it that this is El Alto or Dublin. From policy standpoint you could dump policies by doing a "kubectl exec -it " into drools container and dumping the p
Hello Siva, It seems a malformed policy. I take it that this is El Alto or Dublin. From policy standpoint you could dump policies by doing a "kubectl exec -it " into drools container and dumping the p
|
By
Jorge Hernandez
· #20447
·
|
|
Policy Offered Api Test:unable to get local issuer certificate,how to solve it?
#policy
#elalto
Hello, you'll need one of these 2 solutions: a) make newton client trust the aaf ca root certificate from which policy derives their certificates (same as other components), this would be configuratio
Hello, you'll need one of these 2 solutions: a) make newton client trust the aaf ca root certificate from which policy derives their certificates (same as other components), this would be configuratio
|
By
Jorge Hernandez
· #20287
·
|
|
[CLAMP] [onap-discuss] El Alto - CLAMP UI getting The policies defined have NOT yet been created on the policy engine
Hello Deepak, Based on your log message, it looks like you may be hitting the issue reported in the POLICY-1939 ticket in El Alto. The workaround would be to bounce the pod that the message is complai
Hello Deepak, Based on your log message, it looks like you may be hitting the issue reported in the POLICY-1939 ticket in El Alto. The workaround would be to bounce the pod that the message is complai
|
By
Jorge Hernandez
· #20093
·
|
|
#policy Policy created by CLAMP not found
#policy
Hello Aniello, The Policy GUI is part of the legacy architecture which will eventually be deprecated and it is not coupled with the CLAMP GUI (new architecture). You can look at policies through CLAMP
Hello Aniello, The Policy GUI is part of the legacy architecture which will eventually be deprecated and it is not coupled with the CLAMP GUI (new architecture). You can look at policies through CLAMP
|
By
Jorge Hernandez
· #19352
·
|
|
Policy push to default PDP groups
#policy
#drools
Hi Min, Yes, in the message, the "name":"default", should be "name":"amsterdam" to match the drools controller name. If you look in the actual "createPolicy" messages using the legacy APIs, https://gi
Hi Min, Yes, in the message, the "name":"default", should be "name":"amsterdam" to match the drools controller name. If you look in the actual "createPolicy" messages using the legacy APIs, https://gi
|
By
Jorge Hernandez
· #19139
·
|
|
Policy push to default PDP groups
#policy
#drools
Check out in the drools container the $POLICY_LOGS/network.log , look for configuration messages over the PDPD-CONFIGURATION channel, you should see an update configuration request commanding drools t
Check out in the drools container the $POLICY_LOGS/network.log , look for configuration messages over the PDPD-CONFIGURATION channel, you should see an update configuration request commanding drools t
|
By
Jorge Hernandez
· #19122
·
|