Thanks Daniel, so you can take that hardocoded „public network“ name ??
Not sure if I got that „i can do b in brians list“ … My latest question was more about what versions we should use for Dublin …. Is it really 1.4.0-SNAPSHOT ?? demoArtifactsVersion: "1.4.0-SNAPSHOT" scriptVersion: "1.4.0-SNAPSHOT" thanks, Michal From: [email protected] <[email protected]> On Behalf Of Daniel Rose Sent: Friday, June 21, 2019 1:05 PM To: [email protected]; [email protected] Cc: FREEMAN, BRIAN D <[email protected]>; PLATANIA, MARCO <[email protected]> Subject: Re: [onap-discuss] [Dublin-vFW] vFWCL in Dublin should work out of the box ? Michal, If you want to make me a ticket i can do b in brians list, i will be working in that area next week or so. Thanks, Daniel Rose ECOMP / ONAP com.att.ecomp 732-420-7308 On Jun 21, 2019, at 6:54 AM, Michal Ptacek via Lists.Onap.Org <http://Lists.Onap.Org> <[email protected] <mailto:[email protected]> > wrote: Hi Brian, what version of demo artifacts and scripts were used by integration team for Dublin ?? following are referenced in https://docs.onap.org/en/dublin/submodules/oom.git/docs/oom_quickstart_guide.html <https://urldefense.proofpoint.com/v2/url?u=https-3A__docs.onap.org_en_dublin_submodules_oom.git_docs_oom-5Fquickstart-5Fguide.html&d=DwMFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=2wwdGZ3YcpSivQ2Kio028A&m=RrWjQ-b_mW1T0rd4XbltPS9BRNOD5jUPJfEeUuFJzRs&s=FJR-Ez0zgB0uanCN9KIghOKuC02cQhaXZk_zXbmI0Os&e=> demoArtifactsVersion: "1.4.0-SNAPSHOT" scriptVersion: "1.4.0-SNAPSHOT" (we still use 1.3.0 in our VFWCL offline lab image) We need to prepare offline images with particular version so would like to avoid doing it more times 😊 (this instantiateVFWCL will pass even if VMs are not properly installed …. I guess it’s happy when it ssh is ready on IP, it’s not checking any honeycomb stuff) It looks also that this „vfwclosedloop“ tag expects some specific version which is having that „stream-count“ module ?? [root@tomas-infra ~]# curl -i -X GET -H "Authorization: Basic YWRtaW46YWRtaW4=" -H "Content-Type: application/json" -H "Cache-Control: no-cache" "http://10.8.8.34:8183/restconf/config/sample-plugin:sample-plugin/pg-streams <https://urldefense.proofpoint.com/v2/url?u=http-3A__10.8.8.34-3A8183_restconf_config_sample-2Dplugin-3Asample-2Dplugin_pg-2Dstreams-2522&d=DwQFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=2wwdGZ3YcpSivQ2Kio028A&m=RrWjQ-b_mW1T0rd4XbltPS9BRNOD5jUPJfEeUuFJzRs&s=l1tMGY6lPM9ExmUpnyvAVSitWxsNoPsBqJ8DZI51DRQ&e=> " HTTP/1.1 200 OK Date: Fri, 21 Jun 2019 10:48:55 GMT Content-Type: application/yang.data+json Transfer-Encoding: chunked Server: Jetty(9.3.11.v20160721) {"pg-streams":{"pg-stream":[{"id":"fw_udp1","is-enabled":true}]}}[root@tomas-infra ~]# [root@tomas-infra ~]# [root@tomas-infra ~]# curl -i -X GET -H "Authorization: Basic YWRtaW46YWRtaW4=" -H "Content-Type: application/json" -H "Cache-Control: no-cache" "http://10.8.8.34:8183/restconf/config/stream-count:stream-count/streams <https://urldefense.proofpoint.com/v2/url?u=http-3A__10.8.8.34-3A8183_restconf_config_stream-2Dcount-3Astream-2Dcount_streams-2522&d=DwQFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=2wwdGZ3YcpSivQ2Kio028A&m=RrWjQ-b_mW1T0rd4XbltPS9BRNOD5jUPJfEeUuFJzRs&s=fGTu91Z9EekAbpHRHxh8WyG_c5yST95IaeNbHiwBpTk&e=> " HTTP/1.1 400 Bad Request Date: Fri, 21 Jun 2019 10:49:27 GMT Content-Type: application/json Transfer-Encoding: chunked Server: Jetty(9.3.11.v20160721) {"errors":{"error":[{"error-type":"protocol","error-tag":"unknown-element","error-message":"The module named 'stream-count' does not exist."}]}}[root@tomas-infra ~]# Please advise, Thanks, Michal From: [email protected] <mailto:[email protected]> <[email protected] <mailto:[email protected]> > Sent: Friday, June 21, 2019 8:03 AM To: [email protected] <mailto:[email protected]> ; '[email protected] <mailto:[email protected]> ' <[email protected] <mailto:[email protected]> >; [email protected] <mailto:[email protected]> ; PLATANIA, MARCO <[email protected] <mailto:[email protected]> > Subject: RE: [onap-discuss] vFWCL in Dublin should work out of the box ? Thanks Brian, I think we are well aligned. Dublin) So once I wil get this running I will propose documentation update for https://docs.onap.org/en/dublin/submodules/integration.git/docs/docs_vfw.html# <https://urldefense.proofpoint.com/v2/url?u=https-3A__docs.onap.org_en_dublin_submodules_integration.git_docs_docs-5Fvfw.html&d=DwMFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=2wwdGZ3YcpSivQ2Kio028A&m=RrWjQ-b_mW1T0rd4XbltPS9BRNOD5jUPJfEeUuFJzRs&s=uatUTZd5jRQKV_BVmAGSrZLDCnDpyuKy9pnTnCTuAWM&e=> My understanding is that it should have all steps for vFWCL scenario, it looks that just „final“ step is described in there …. unless you know also about some better link where this „init“ and „instantiateVFWCL“ part is already described … El-ALto) we can support removing those hardcodings and keys distribution in El-Alto .. Michal From: [email protected] <mailto:[email protected]> <[email protected] <mailto:[email protected]> > On Behalf Of Brian Sent: Thursday, June 20, 2019 9:38 PM To: [email protected] <mailto:[email protected]> ; [email protected] <mailto:[email protected]> ; PLATANIA, MARCO <[email protected] <mailto:[email protected]> > Subject: Re: [onap-discuss] vFWCL in Dublin should work out of the box ? Submission to demo and testsuite repo are always welcome. a. Demo-k8s.sh onap init does populate AAI so not sure what you are seeing as missing. Can you say more ? b. That is a good catch on the public network name – a variable as part of the integration_robot_properties.py in OOM (and in testsuite) would be appropriate c. One is the public key that is put in the VM and one is the private key – agree that it would be nice to add to the helm chart the pointer to a volume mount of the private and public key for the VNFs as secrets that could be used by the provider d. Any all help on the documentation while its fresh appreciated Dublin is closed but it won’t be that long till El Alto early drop. Also – we can update robot container with release notes to either git clone inside the container or kubectl cp into it. Brian From: [email protected] <mailto:[email protected]> <[email protected] <mailto:[email protected]> > Sent: Thursday, June 20, 2019 3:27 PM To: FREEMAN, BRIAN D <[email protected] <mailto:[email protected]> >; [email protected] <mailto:[email protected]> ; PLATANIA, MARCO <[email protected] <mailto:[email protected]> > Subject: RE: [onap-discuss] vFWCL in Dublin should work out of the box ? Thanks Brian, I just managed to get instantiateVFWCL part passing … Subsequent step still failing on „404“ VFWCL Closed Loop Test | FAIL | 404 != 200 It looks that documentation is highly insufficient … I found several problems already: a. Need to run also demo-k8s.sh <namespace> init - Execute both init_customer + distribute (prior that) …. also init_customer + distribute is misleading, because it looks that „init“ = „init_customer“ + „distribute“ but in latter case openstack project specific entries are not loaded into AAI But they are needed by VID b. Network name is hardcoded for public network robot/resources/stack_validation/validate_vfw.robot: ${vfw_public_ip}= Get Server Ip ${server_list} ${stack_info} vfw_name_0 network_name=public robot/resources/demo_preload.robot: ${vpg_public_ip}= Get Server Ip ${server_list} ${stack_info} vpg_name_0 network_name=public … c. For connecting to node /var/opt/ONAP/robot/assets/keys/onap_dev.pvt is used from robot container, I would expect that it will take key from robot values.yaml instead robot: vnfPubKey d. I see a lot of new tricks added into https://docs.onap.org/en/latest/submodules/oom.git/docs/oom_quickstart_guide.html <https://urldefense.proofpoint.com/v2/url?u=https-3A__docs.onap.org_en_latest_submodules_oom.git_docs_oom-5Fquickstart-5Fguide.html&d=DwMFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=e3d1ehx3DI5AoMgDmi2Fzw&m=kg9hg5dGjHo2r-lqh8GFgpeJamF12Kgtzx-bd3CLjBs&s=ycy1UtLq8EAm84ETa8HYEgt0FTYK_-VKVl1xXtP2o5s&e=> which are very helpfull, e.g. now I know how to generate encrypted password for SO, APPC and Robot … but some fine tunings are still required in examples provided, need to check some combinations … but each attempt takes a lot of time for the correcting of those or the unsupported API, do you think we can propose some patches into demo repo ? (isn’t it too late for Dublin ? Especially I dont expect newer robot image to be released for Dublin and those scripts are part of the image, which is good 😊) thanks, Michal From: FREEMAN, BRIAN D <[email protected] <mailto:[email protected]> > Sent: Tuesday, June 18, 2019 8:22 PM To: [email protected] <mailto:[email protected]> ; [email protected] <mailto:[email protected]> ; PLATANIA, MARCO <[email protected] <mailto:[email protected]> > Subject: RE: [onap-discuss] vFWCL in Dublin should work out of the box ? Several things. 1. Vfwclosedloop takes the external IP of the packet generator that had been instantiated by a instantiateVFWCL. a. Its also the IP address that robot puts in the netconf mount to the packet generator b. What robot is going to do is use HTTP to update the number of streams to 10 then poll on device to see it reset to 5, then set it to 1 and look for the reset to 5 , then set it to 5 in case of failure. c. There is a step we added to match the control loop name in DCAE TCA to the policy name robot pushes to policy d. https://gerrit.onap.org/r/#/c/integration/+/90052/ <https://urldefense.proofpoint.com/v2/url?u=https-3A__gerrit.onap.org_r_-23_c_integration_-2B_90052_&d=DwMFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=e3d1ehx3DI5AoMgDmi2Fzw&m=kg9hg5dGjHo2r-lqh8GFgpeJamF12Kgtzx-bd3CLjBs&s=c4o2klURIVopgXa7hfb_i1o6W6MBvhmqnJbfNI58_GQ&e=> 2. 404 on calling openstack heat might be a lab setup incompatibility with robot. a. Is that stack created and just not in the return for the heat engine query that robot is doing ? b. If the stack is created but the heat bridge and activate stage is not functioning in robot then you only need to do those steps to set the VNF to Active in AAI and create the netconf mount c. Seems like robot isnt quite in synch with your openstack for some reason 3. We dont use that demo_preload.robot API in our standard testing so we missed updating the v8 to v14 a. Can you try v14 in your curl ? 4. From: [email protected] <mailto:[email protected]> <[email protected] <mailto:[email protected]> > Sent: Tuesday, June 18, 2019 2:01 PM To: [email protected] <mailto:[email protected]> ; FREEMAN, BRIAN D <[email protected] <mailto:[email protected]> >; PLATANIA, MARCO <[email protected] <mailto:[email protected]> > Subject: [onap-discuss] vFWCL in Dublin should work out of the box ? Hi Brian & Marco, thanks for great presentation on DDF in Kista regarding Robot improvements, I am wondering if you can help me with following issues. It seems I must be doing something completely wrong, as you mentioned that vFWCL is fully automated (since Beijing). And also it was already verified within integration team efforts https://wiki.onap.org/display/DW/Dublin+Release+Integration+Testing+Status <https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.onap.org_display_DW_Dublin-2BRelease-2BIntegration-2BTesting-2BStatus&d=DwMFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=e3d1ehx3DI5AoMgDmi2Fzw&m=Rc6hju_emTybKopcbMxa22DqvGvzGjOPJc-dbXhM4So&s=_pJ_J9wzzfGDcftzQPAS3-ZV_IszchncieX4TQzfuFA&e=> I started by checking how integration team documented our most beloved ONAP demo usecase in there: https://docs.onap.org/en/dublin/submodules/integration.git/docs/docs_vfw.html <https://urldefense.proofpoint.com/v2/url?u=https-3A__docs.onap.org_en_dublin_submodules_integration.git_docs_docs-5Fvfw.html&d=DwMFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=e3d1ehx3DI5AoMgDmi2Fzw&m=Rc6hju_emTybKopcbMxa22DqvGvzGjOPJc-dbXhM4So&s=JBVPpbkTU9q-U-2anNw3v1tEb3aDvp1PH4uyMfyvm90&e=> Description is pretty straightforward, just launch: bash oom/kubernetes/robot/demo-k8s.sh <namespace> vfwclosedloop <pgn-ip-address> it took just a moment to discover what pgn-ip-address might mean in this context (if run w/o this param it’s complaining about something what should be listening on 8183 port) InvalidURL: Invalid URL u'http://:8183/restconf/config/stream-count:stream-count/streams': No host supplied which is [root@tomas-infra robot]# kubectl get services -n onap | grep 8183 sdc-dcae-fe NodePort 10.43.231.35 <none> 8183:30263/TCP,9444:30264/TCP 6h20m so I launched full of expectations using ./demo-k8s.sh onap vfwclosedloop 10.43.231.35 It crashed almost instantly with VFWCL Closed Loop Test | FAIL | 404 != 200 according to logs it’s trying to connect to „ Connect To Packet Generator ${host}, alias=${alias}“ Q1) how this can work at this step ?? no VM’s are yet spawned in openstack !! so I reverted to what is documented for Casablanca, hoping for some more details over the scenario https://docs.onap.org/en/casablanca/submodules/integration.git/docs/docs_vfw.html <https://urldefense.proofpoint.com/v2/url?u=https-3A__docs.onap.org_en_casablanca_submodules_integration.git_docs_docs-5Fvfw.html&d=DwMFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=e3d1ehx3DI5AoMgDmi2Fzw&m=Rc6hju_emTybKopcbMxa22DqvGvzGjOPJc-dbXhM4So&s=5LrSnP09jRdF7QbsDPFyBoSb7yDmgdUYCLg9xSm9w8M&e=> the suggestion from there is to use following tag: bash oom/kubernetes/robot/ete-k8s.sh <namespace> instantiateVFWCL this failed after 10mins of timeout with following error 404 „The resource could not be found“ <image001.jpg> Q2) Do you know what is needed in there ? If it’s some misconfiguration I would expect rather some 401 unauthorized problems …. not that it failes to detect stack it is supposed to create ?? I have no other option for easy progress than to revert our instructions we collected when doing vFWCL on Casablanca with all workarounds and „hidden configuration“ settings and trying to see if it still works in Dublin Complete procedure was upstreamed as a part of our offline installer repo … https://gerrit.onap.org/r/gitweb?p=oom/offline-installer.git;a=blob;f=docs/vFWCL-notes.rst;h=690b6dc9ec3c19cc225f6f495c8711b098f91008;hb=refs/heads/casablanca <https://urldefense.proofpoint.com/v2/url?u=https-3A__gerrit.onap.org_r_gitweb-3Fp-3Doom_offline-2Dinstaller.git-3Ba-3Dblob-3Bf-3Ddocs_vFWCL-2Dnotes.rst-3Bh-3D690b6dc9ec3c19cc225f6f495c8711b098f91008-3Bhb-3Drefs_heads_casablanca&d=DwMFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=e3d1ehx3DI5AoMgDmi2Fzw&m=Rc6hju_emTybKopcbMxa22DqvGvzGjOPJc-dbXhM4So&s=RrOfQr98wlRNE8o4jl6hWl7BHxRfDX6nNzTSnTFemF0&e=> it looked promising at first but then it bumped in Step7) SDNC topology preload where robot script failed to insert topology preload for VNF’s created in VID GUI in previous step ./demo-k8s.sh onap preload vFWSNK-1 vFWSNK-Module-1 console output is not very helpful Preload VNF | FAIL | VNF Name: vFWSNK-1 is not found. ------------------------------------------------------------------------------ Testsuites.Demo :: Executes the VNF Orchestration Test cases inclu... | FAIL | 1 critical test, 0 passed, 1 failed 1 test total, 0 passed, 1 failed But in log it’s visible that it failed with 410 response because it’s using retired API ?? <image002.png> This step is easily reproducable curl -k -i -X GET --user [email protected]:demo123456 <mailto:[email protected]:demo123456> ! -H 'Accept: application/json' -H 'Content-Type: application/json' -H 'X-FromAppId: MSO' -H 'X-TransactionId: 89273498' -d '{"availability-zone-name": "AZ1", "hypervisor-type": "hypervisor"}' https://tomas-node0:30233/aai/v8/network/generic-vnfs <https://urldefense.proofpoint.com/v2/url?u=https-3A__tomas-2Dnode0-3A30233_aai_v8_network_generic-2Dvnfs&d=DwQFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=e3d1ehx3DI5AoMgDmi2Fzw&m=Rc6hju_emTybKopcbMxa22DqvGvzGjOPJc-dbXhM4So&s=AAxc_bhwC5FzSDjtkJ5Pr9cDsEQBWdo23ovhFxKAIZ8&e=> --insecure HTTP/1.1 410 Gone Date: Tue, 18 Jun 2019 17:53:46 GMT X-AAI-TXID: 1-aai-resources-190618-17:53:46:011-97349 Content-Type: application/json Content-Length: 285 Strict-Transport-Security: max-age=16000000; includeSubDomains; preload; {"requestError":{"serviceException":{"messageId":"SVC3007","text":"This version (%1) of the API is retired, please migrate to %2 (msg=%3) (ec=%4)","variables":["PUT","v8/network/generic-vnfs","This version (%1) of the API is retired, please migrate to %2","ERR.5.6.3007","v8","v16"]}}} Q3) What I am doing wrong ?? I did not spend much time in analyzing all those issues, it’s coming from my today’s attempt only, but I think replying on this might help also others unless it’s some silly problem I overlooked 😊 Please advise, Thanks in advance, Michal <http://ext.w1.samsung.net/mail/ext/v1/external/status/update?userid=m.ptacek&do=bWFpbElEPTIwMTkwNjE4MTgwMTA1ZXVjYXMxcDExZTIwZDVhNmJmZDg2NzRkNDlmZTMyOTZmMzIzODJjZSZyZWNpcGllbnRBZGRyZXNzPWJmMTkzNkBhdHQuY29t> <http://ext.w1.samsung.net/mail/ext/v1/external/status/update?userid=m.ptacek&do=bWFpbElEPTIwMTkwNjIwMTkyNjU1ZXVjYXMxcDI3ZDc4ZmJkOGQ1MjFjY2MzYzNlMTFjYmZiZTUxMjkwZiZyZWNpcGllbnRBZGRyZXNzPWJmMTkzNkBhdHQuY29t> <http://ext.w1.samsung.net/mail/ext/v1/external/status/update?userid=m.ptacek&do=bWFpbElEPTIwMTkwNjIxMTA1MzQ4ZXVjYXMxcDFlNzI5NjU5YzQ4MmJkMDlmMjQzNGQyZmRkODZhOGYzZiZyZWNpcGllbnRBZGRyZXNzPW9uYXAtZGlzY3Vzc0BsaXN0cy5vbmFwLm9yZw__> -=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#17683): https://lists.onap.org/g/onap-discuss/message/17683 Mute This Topic: https://lists.onap.org/mt/32157175/21656 Group Owner: [email protected] Unsubscribe: https://lists.onap.org/g/onap-discuss/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
