Thanks Daniel, so you can take that hardocoded „public network“ name ??

Not sure if I got that „i can do b in brians list“ … 

 

My latest question was more about what versions we should use for Dublin …. Is 
it really 1.4.0-SNAPSHOT ??

  demoArtifactsVersion: "1.4.0-SNAPSHOT"

  scriptVersion: "1.4.0-SNAPSHOT"

 

thanks,

Michal

 

From: [email protected] <[email protected]> On Behalf Of 
Daniel Rose
Sent: Friday, June 21, 2019 1:05 PM
To: [email protected]; [email protected]
Cc: FREEMAN, BRIAN D <[email protected]>; PLATANIA, MARCO 
<[email protected]>
Subject: Re: [onap-discuss] [Dublin-vFW] vFWCL in Dublin should work out of the 
box ?

 

Michal, 

If you want to make me a ticket i can do b in brians list, i will be working in 
that area next week or so.

Thanks,

Daniel Rose 

ECOMP / ONAP

com.att.ecomp

732-420-7308


On Jun 21, 2019, at 6:54 AM, Michal Ptacek via Lists.Onap.Org 
<http://Lists.Onap.Org>  <[email protected] 
<mailto:[email protected]> > wrote:

Hi Brian,

 

what version of demo artifacts and scripts were used by integration team for 
Dublin  ??

 

following are referenced in 
https://docs.onap.org/en/dublin/submodules/oom.git/docs/oom_quickstart_guide.html
 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__docs.onap.org_en_dublin_submodules_oom.git_docs_oom-5Fquickstart-5Fguide.html&d=DwMFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=2wwdGZ3YcpSivQ2Kio028A&m=RrWjQ-b_mW1T0rd4XbltPS9BRNOD5jUPJfEeUuFJzRs&s=FJR-Ez0zgB0uanCN9KIghOKuC02cQhaXZk_zXbmI0Os&e=>
 

 

  demoArtifactsVersion: "1.4.0-SNAPSHOT"

  scriptVersion: "1.4.0-SNAPSHOT"

(we still use 1.3.0 in our VFWCL offline lab image)

 

We need to prepare offline images with particular version so would like to 
avoid doing it more times 😊

 

(this instantiateVFWCL will pass even if VMs are not properly installed ….  I 
guess it’s happy when it ssh is ready on IP, it’s not checking any honeycomb 
stuff)

 

It looks also that this „vfwclosedloop“ tag expects some specific version which 
is having that „stream-count“ module ??

 

[root@tomas-infra ~]#  curl -i -X GET -H "Authorization: Basic 
YWRtaW46YWRtaW4=" -H "Content-Type: application/json" -H "Cache-Control: 
no-cache" 
"http://10.8.8.34:8183/restconf/config/sample-plugin:sample-plugin/pg-streams 
<https://urldefense.proofpoint.com/v2/url?u=http-3A__10.8.8.34-3A8183_restconf_config_sample-2Dplugin-3Asample-2Dplugin_pg-2Dstreams-2522&d=DwQFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=2wwdGZ3YcpSivQ2Kio028A&m=RrWjQ-b_mW1T0rd4XbltPS9BRNOD5jUPJfEeUuFJzRs&s=l1tMGY6lPM9ExmUpnyvAVSitWxsNoPsBqJ8DZI51DRQ&e=>
 "

HTTP/1.1 200 OK

Date: Fri, 21 Jun 2019 10:48:55 GMT

Content-Type: application/yang.data+json

Transfer-Encoding: chunked

Server: Jetty(9.3.11.v20160721)

 

{"pg-streams":{"pg-stream":[{"id":"fw_udp1","is-enabled":true}]}}[root@tomas-infra
 ~]#

[root@tomas-infra ~]#

[root@tomas-infra ~]#  curl -i -X GET -H "Authorization: Basic 
YWRtaW46YWRtaW4=" -H "Content-Type: application/json" -H "Cache-Control: 
no-cache" 
"http://10.8.8.34:8183/restconf/config/stream-count:stream-count/streams 
<https://urldefense.proofpoint.com/v2/url?u=http-3A__10.8.8.34-3A8183_restconf_config_stream-2Dcount-3Astream-2Dcount_streams-2522&d=DwQFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=2wwdGZ3YcpSivQ2Kio028A&m=RrWjQ-b_mW1T0rd4XbltPS9BRNOD5jUPJfEeUuFJzRs&s=fGTu91Z9EekAbpHRHxh8WyG_c5yST95IaeNbHiwBpTk&e=>
 "

HTTP/1.1 400 Bad Request

Date: Fri, 21 Jun 2019 10:49:27 GMT

Content-Type: application/json

Transfer-Encoding: chunked

Server: Jetty(9.3.11.v20160721)

 

{"errors":{"error":[{"error-type":"protocol","error-tag":"unknown-element","error-message":"The
 module named 'stream-count' does not exist."}]}}[root@tomas-infra ~]#

 

Please advise,

Thanks,

Michal

 

From: [email protected] <mailto:[email protected]>  
<[email protected] <mailto:[email protected]> > 
Sent: Friday, June 21, 2019 8:03 AM
To: [email protected] <mailto:[email protected]> ; 
'[email protected] <mailto:[email protected]> ' <[email protected] 
<mailto:[email protected]> >; [email protected] 
<mailto:[email protected]> ; PLATANIA, MARCO 
<[email protected] <mailto:[email protected]> >
Subject: RE: [onap-discuss] vFWCL in Dublin should work out of the box ?

 

Thanks Brian, I think we are well aligned.

 

Dublin)

So once I wil get this running I will propose documentation update for 
https://docs.onap.org/en/dublin/submodules/integration.git/docs/docs_vfw.html# 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__docs.onap.org_en_dublin_submodules_integration.git_docs_docs-5Fvfw.html&d=DwMFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=2wwdGZ3YcpSivQ2Kio028A&m=RrWjQ-b_mW1T0rd4XbltPS9BRNOD5jUPJfEeUuFJzRs&s=uatUTZd5jRQKV_BVmAGSrZLDCnDpyuKy9pnTnCTuAWM&e=>
 

My understanding is that it should have all steps for vFWCL scenario, it looks 
that just „final“ step is described in there …. unless you know also about some 
better link where this „init“ and „instantiateVFWCL“ part is already described …

 

El-ALto)

we can support removing those hardcodings and keys distribution in El-Alto ..

 

 

Michal

From: [email protected] <mailto:[email protected]>  
<[email protected] <mailto:[email protected]> > On Behalf 
Of Brian
Sent: Thursday, June 20, 2019 9:38 PM
To: [email protected] <mailto:[email protected]> ; 
[email protected] <mailto:[email protected]> ; PLATANIA, 
MARCO <[email protected] <mailto:[email protected]> >
Subject: Re: [onap-discuss] vFWCL in Dublin should work out of the box ?

 

Submission to demo and testsuite repo are always welcome.

 

a.      Demo-k8s.sh onap init does populate AAI so not sure what you are seeing 
as missing. Can you say more ?
b.      That is a good catch on the public network name – a variable as part of 
the integration_robot_properties.py in OOM (and in testsuite) would be 
appropriate
c.      One is the public key that is put in the VM and one is the private key 
– agree that it would be nice to add to the helm chart  the pointer to a volume 
mount of the private and public key for the VNFs as secrets that could be used 
by the provider 
d.      Any all help on the documentation while its fresh appreciated

 

Dublin is closed but it won’t be that long till El Alto early drop.

 

Also – we can update robot container with release notes to either git clone 
inside the container or kubectl cp into it.

 

Brian

 

 

From: [email protected] <mailto:[email protected]>  
<[email protected] <mailto:[email protected]> > 
Sent: Thursday, June 20, 2019 3:27 PM
To: FREEMAN, BRIAN D <[email protected] <mailto:[email protected]> >; 
[email protected] <mailto:[email protected]> ; PLATANIA, 
MARCO <[email protected] <mailto:[email protected]> >
Subject: RE: [onap-discuss] vFWCL in Dublin should work out of the box ?

 

Thanks Brian,

 

I just managed to get  instantiateVFWCL part passing  …

Subsequent step still failing on „404“

VFWCL Closed Loop Test

| FAIL |

404 != 200

 

It looks that documentation is highly insufficient … I found several problems 
already:

 

a.      Need to run also 

demo-k8s.sh <namespace> init

               - Execute both init_customer + distribute

               (prior that)  …. also init_customer + distribute is misleading, 
because it looks that „init“ = „init_customer“ + „distribute“ but in latter 
case openstack project specific entries are not loaded into AAI

               But they are needed by VID

 

b.      Network name is hardcoded for public network

robot/resources/stack_validation/validate_vfw.robot:    ${vfw_public_ip}=    
Get Server Ip    ${server_list}    ${stack_info}   vfw_name_0    
network_name=public

robot/resources/demo_preload.robot:    ${vpg_public_ip}=    Get Server Ip    
${server_list}    ${stack_info}   vpg_name_0    network_name=public

              …

 

c.      For connecting to node /var/opt/ONAP/robot/assets/keys/onap_dev.pvt is 
used from robot container, I would expect that it will take key from robot 
values.yaml instead

robot:   

                 vnfPubKey

 

d.      I see a lot of new tricks added into 
https://docs.onap.org/en/latest/submodules/oom.git/docs/oom_quickstart_guide.html
 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__docs.onap.org_en_latest_submodules_oom.git_docs_oom-5Fquickstart-5Fguide.html&d=DwMFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=e3d1ehx3DI5AoMgDmi2Fzw&m=kg9hg5dGjHo2r-lqh8GFgpeJamF12Kgtzx-bd3CLjBs&s=ycy1UtLq8EAm84ETa8HYEgt0FTYK_-VKVl1xXtP2o5s&e=>
 

which are very helpfull, e.g. now I know how to generate encrypted password for 
SO, APPC and Robot …

but some fine tunings are still required in examples provided, need to check 
some combinations … but each attempt takes a lot of time

 

 

for the correcting of those or the unsupported API, do you think we can propose 
some patches into demo repo ? 

(isn’t it too late for Dublin ? Especially I dont expect newer robot image to 
be released for Dublin and those scripts are part of the image, which is good 😊)

 

thanks,

Michal

 

From: FREEMAN, BRIAN D <[email protected] <mailto:[email protected]> > 
Sent: Tuesday, June 18, 2019 8:22 PM
To: [email protected] <mailto:[email protected]> ; 
[email protected] <mailto:[email protected]> ; PLATANIA, 
MARCO <[email protected] <mailto:[email protected]> >
Subject: RE: [onap-discuss] vFWCL in Dublin should work out of the box ?

 

Several things.

 

1.      Vfwclosedloop takes the external IP of the packet generator that had 
been instantiated by a instantiateVFWCL. 

a.      Its also the IP address that robot puts in the netconf mount to the 
packet generator
b.      What robot is going to do is use HTTP to update the number of streams 
to 10 then poll on device to see it reset to 5, then set it to 1 and look for 
the reset to 5 , then set it to 5 in case of failure.
c.      There is a step we added to match the control loop name in DCAE TCA to 
the policy name robot pushes to policy
d.      https://gerrit.onap.org/r/#/c/integration/+/90052/ 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__gerrit.onap.org_r_-23_c_integration_-2B_90052_&d=DwMFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=e3d1ehx3DI5AoMgDmi2Fzw&m=kg9hg5dGjHo2r-lqh8GFgpeJamF12Kgtzx-bd3CLjBs&s=c4o2klURIVopgXa7hfb_i1o6W6MBvhmqnJbfNI58_GQ&e=>
 

2.      404 on calling openstack heat might be a lab setup incompatibility with 
robot. 

a.      Is that stack created and just not in the return for the heat engine 
query that robot is doing ?
b.      If the stack is created but the heat bridge and activate stage is not 
functioning in robot then you only need to do those steps to set the VNF to 
Active in AAI and create the netconf mount
c.      Seems like robot isnt quite in synch with your openstack for some reason

3.      We dont use that demo_preload.robot API in our standard testing so we 
missed updating the v8 to v14 

a.      Can you try v14 in your curl ?

4.

 

From: [email protected] <mailto:[email protected]>  
<[email protected] <mailto:[email protected]> > 
Sent: Tuesday, June 18, 2019 2:01 PM
To: [email protected] <mailto:[email protected]> ; FREEMAN, 
BRIAN D <[email protected] <mailto:[email protected]> >; PLATANIA, MARCO 
<[email protected] <mailto:[email protected]> >
Subject: [onap-discuss] vFWCL in Dublin should work out of the box ?

 

Hi Brian & Marco,

 

thanks for great presentation on DDF in Kista regarding Robot improvements,

 

I am wondering if you can help me with following issues.

It seems I must be doing something completely wrong, as you mentioned that 
vFWCL is fully automated (since Beijing).

And also it was already verified within integration team efforts

https://wiki.onap.org/display/DW/Dublin+Release+Integration+Testing+Status 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.onap.org_display_DW_Dublin-2BRelease-2BIntegration-2BTesting-2BStatus&d=DwMFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=e3d1ehx3DI5AoMgDmi2Fzw&m=Rc6hju_emTybKopcbMxa22DqvGvzGjOPJc-dbXhM4So&s=_pJ_J9wzzfGDcftzQPAS3-ZV_IszchncieX4TQzfuFA&e=>
 

 

 

I started by checking how integration team documented our most beloved ONAP 
demo usecase in there:

https://docs.onap.org/en/dublin/submodules/integration.git/docs/docs_vfw.html 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__docs.onap.org_en_dublin_submodules_integration.git_docs_docs-5Fvfw.html&d=DwMFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=e3d1ehx3DI5AoMgDmi2Fzw&m=Rc6hju_emTybKopcbMxa22DqvGvzGjOPJc-dbXhM4So&s=JBVPpbkTU9q-U-2anNw3v1tEb3aDvp1PH4uyMfyvm90&e=>
 

 

Description is pretty straightforward, just launch:

bash oom/kubernetes/robot/demo-k8s.sh <namespace> vfwclosedloop <pgn-ip-address>

it took just a moment to discover what pgn-ip-address might mean in this 
context (if run w/o this param it’s complaining about something what should be 
listening on 8183 port)

 

InvalidURL: Invalid URL 
u'http://:8183/restconf/config/stream-count:stream-count/streams': No host 
supplied

 

which is 

 

[root@tomas-infra robot]# kubectl get services -n onap | grep 8183

sdc-dcae-fe                        NodePort       10.43.231.35    <none>        
                         8183:30263/TCP,9444:30264/TCP                          
       6h20m

 

 

so I launched full of expectations using

 

./demo-k8s.sh onap vfwclosedloop 10.43.231.35

 

It crashed almost instantly with

 

VFWCL Closed Loop Test

| FAIL |

404 != 200

 

according to logs it’s trying to connect to „ Connect To Packet Generator 
${host}, alias=${alias}“ 

 

Q1) how  this can work at this step ?? no VM’s are yet spawned in openstack !!

 

so I reverted to what is documented for Casablanca, hoping for some more 
details over the scenario

 

https://docs.onap.org/en/casablanca/submodules/integration.git/docs/docs_vfw.html
 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__docs.onap.org_en_casablanca_submodules_integration.git_docs_docs-5Fvfw.html&d=DwMFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=e3d1ehx3DI5AoMgDmi2Fzw&m=Rc6hju_emTybKopcbMxa22DqvGvzGjOPJc-dbXhM4So&s=5LrSnP09jRdF7QbsDPFyBoSb7yDmgdUYCLg9xSm9w8M&e=>
 

 

the suggestion from there is to use following tag:

 

bash oom/kubernetes/robot/ete-k8s.sh <namespace> instantiateVFWCL

 

this failed after 10mins of timeout with following error 404 „The resource 
could not be found“

 

<image001.jpg>

 

Q2) Do you know what is needed in there ? If it’s some misconfiguration I would 
expect rather some 401 unauthorized problems …. not that it failes to detect 
stack it is supposed to create ??

 

I have no other option for easy progress than to revert our instructions we 
collected when doing vFWCL on Casablanca with all workarounds and „hidden 
configuration“ settings and trying to see if it still works in Dublin

 

Complete procedure was upstreamed as a part of our offline installer repo …

https://gerrit.onap.org/r/gitweb?p=oom/offline-installer.git;a=blob;f=docs/vFWCL-notes.rst;h=690b6dc9ec3c19cc225f6f495c8711b098f91008;hb=refs/heads/casablanca
 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__gerrit.onap.org_r_gitweb-3Fp-3Doom_offline-2Dinstaller.git-3Ba-3Dblob-3Bf-3Ddocs_vFWCL-2Dnotes.rst-3Bh-3D690b6dc9ec3c19cc225f6f495c8711b098f91008-3Bhb-3Drefs_heads_casablanca&d=DwMFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=e3d1ehx3DI5AoMgDmi2Fzw&m=Rc6hju_emTybKopcbMxa22DqvGvzGjOPJc-dbXhM4So&s=RrOfQr98wlRNE8o4jl6hWl7BHxRfDX6nNzTSnTFemF0&e=>
 

 

it looked promising at first but then it bumped in Step7) SDNC topology preload

 

where robot script failed to insert topology preload for VNF’s created in VID 
GUI in previous step

 

./demo-k8s.sh onap preload vFWSNK-1 vFWSNK-Module-1

 

console output is not very helpful

 

Preload VNF                                                           | FAIL |

VNF Name: vFWSNK-1 is not found.

------------------------------------------------------------------------------

Testsuites.Demo :: Executes the VNF Orchestration Test cases inclu... | FAIL |

1 critical test, 0 passed, 1 failed

1 test total, 0 passed, 1 failed

 

But in log it’s visible that it failed with 410 response because it’s using 
retired API ??

 

<image002.png>

 

This step is easily reproducable

 

curl -k -i -X GET --user [email protected]:demo123456 
<mailto:[email protected]:demo123456> ! -H 'Accept: application/json' -H 
'Content-Type: application/json' -H 'X-FromAppId: MSO' -H 'X-TransactionId: 
89273498' -d '{"availability-zone-name": "AZ1", "hypervisor-type": 
"hypervisor"}' https://tomas-node0:30233/aai/v8/network/generic-vnfs 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__tomas-2Dnode0-3A30233_aai_v8_network_generic-2Dvnfs&d=DwQFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=e3d1ehx3DI5AoMgDmi2Fzw&m=Rc6hju_emTybKopcbMxa22DqvGvzGjOPJc-dbXhM4So&s=AAxc_bhwC5FzSDjtkJ5Pr9cDsEQBWdo23ovhFxKAIZ8&e=>
  --insecure

HTTP/1.1 410 Gone

Date: Tue, 18 Jun 2019 17:53:46 GMT

X-AAI-TXID: 1-aai-resources-190618-17:53:46:011-97349

Content-Type: application/json

Content-Length: 285

Strict-Transport-Security: max-age=16000000; includeSubDomains; preload;

 

{"requestError":{"serviceException":{"messageId":"SVC3007","text":"This version 
(%1) of the API is retired, please migrate to %2 (msg=%3) 
(ec=%4)","variables":["PUT","v8/network/generic-vnfs","This version (%1) of the 
API is retired, please migrate to %2","ERR.5.6.3007","v8","v16"]}}}

 

 

 

Q3) What I am doing wrong ??

 

I did not spend much time in analyzing all those issues, it’s coming from my 
today’s attempt only, but I think replying on this might help also others 
unless it’s some silly problem I overlooked 😊

 

Please advise,

Thanks in advance,

 

Michal

 

  
<http://ext.w1.samsung.net/mail/ext/v1/external/status/update?userid=m.ptacek&do=bWFpbElEPTIwMTkwNjE4MTgwMTA1ZXVjYXMxcDExZTIwZDVhNmJmZDg2NzRkNDlmZTMyOTZmMzIzODJjZSZyZWNpcGllbnRBZGRyZXNzPWJmMTkzNkBhdHQuY29t>
 

 

  
<http://ext.w1.samsung.net/mail/ext/v1/external/status/update?userid=m.ptacek&do=bWFpbElEPTIwMTkwNjIwMTkyNjU1ZXVjYXMxcDI3ZDc4ZmJkOGQ1MjFjY2MzYzNlMTFjYmZiZTUxMjkwZiZyZWNpcGllbnRBZGRyZXNzPWJmMTkzNkBhdHQuY29t>
 


 

 




  
<http://ext.w1.samsung.net/mail/ext/v1/external/status/update?userid=m.ptacek&do=bWFpbElEPTIwMTkwNjIxMTA1MzQ4ZXVjYXMxcDFlNzI5NjU5YzQ4MmJkMDlmMjQzNGQyZmRkODZhOGYzZiZyZWNpcGllbnRBZGRyZXNzPW9uYXAtZGlzY3Vzc0BsaXN0cy5vbmFwLm9yZw__>
 




-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.

View/Reply Online (#17683): https://lists.onap.org/g/onap-discuss/message/17683
Mute This Topic: https://lists.onap.org/mt/32157175/21656
Group Owner: [email protected]
Unsubscribe: https://lists.onap.org/g/onap-discuss/unsub  
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to