Make sure that the TCA Control Loop Name matches what robot pushed to Policy

https://gerrit.onap.org/r/#/c/integration/+/90052/1/docs/docs_vfw.rst

Has some documentation on the update to TCA Control Loop name needed (I might 
have provided this already so apoligize if its a duplicate)

Brian


From: [email protected] <[email protected]> On Behalf Of 
Michal Ptacek via Lists.Onap.Org
Sent: Friday, June 21, 2019 10:30 AM
To: DRAGOSH, PAM <[email protected]>; [email protected]; 
[email protected]
Subject: [onap-discuss] [Dublin-vFW] is really Dublin policy framework already 
adapted to work offline ?

Hi Pam and Liam,

we are trying to reproduce vFWCL demo on top of sign-off Dublin using latest 
enhancements of robot framework,
it looks to be progressing quite well, but CL part is still not happening … I 
believe problem lies in policy framework

can you please help me by answering following questions:

not sure if I still need to execute 
oom/kubernetes/policy/resources/config/pe/push-policies.sh.
Current documentation from integration team is quite empty 
https://docs.onap.org/en/dublin/submodules/integration.git/docs/docs_vfw.html<https://urldefense.proofpoint.com/v2/url?u=https-3A__docs.onap.org_en_dublin_submodules_integration.git_docs_docs-5Fvfw.html&d=DwMFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=e3d1ehx3DI5AoMgDmi2Fzw&m=9nPH5w15KuU4w1GFslbxb8LheQ55xYYeAlta8RIngvk&s=xG-gPvSgOuRfIDsJVQ5e99clydyluOQH16fmryvE-k4&e=>
 as it’s starting point is that vFWCL is already happening
So it’s covering only part to verify that it’s working “demo-k8s.sh <namespace> 
vfwclosedloop <pgn-ip-address>” …
But in Casablanca 
https://docs.onap.org/en/casablanca/submodules/integration.git/docs/docs_vfw.html<https://urldefense.proofpoint.com/v2/url?u=https-3A__docs.onap.org_en_casablanca_submodules_integration.git_docs_docs-5Fvfw.html&d=DwMFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=e3d1ehx3DI5AoMgDmi2Fzw&m=9nPH5w15KuU4w1GFslbxb8LheQ55xYYeAlta8RIngvk&s=gKqM7Vo7kGM7gKYc7YzNeP0FDKOnEr3btzvdP2E8HHM&e=>
 they are still reffering to using push_policies script

Q1) Do I need to execute that script to insert policies ??  it’s downloading 
old drools file in first step
wget -O cl-amsterdam-template.drl 
https://git.onap.org/policy/drools-applications/plain/controlloop/templates/archetype-cl-amsterdam/src/main/resources/archetype-resources/src/main/resources/__closedLoopControlName__.drl<https://urldefense.proofpoint.com/v2/url?u=https-3A__git.onap.org_policy_drools-2Dapplications_plain_controlloop_templates_archetype-2Dcl-2Damsterdam_src_main_resources_archetype-2Dresources_src_main_resources_-5F-5FclosedLoopControlName-5F-5F.drl&d=DwQFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=e3d1ehx3DI5AoMgDmi2Fzw&m=9nPH5w15KuU4w1GFslbxb8LheQ55xYYeAlta8RIngvk&s=4kf5ssmW06onPUeNLuFvG5UzQIYH_iEAhnosXqWGtjs&e=>

[cid:[email protected]]


Q2) Do I need to also update policy afterwards using 
oom/kubernetes/policy/charts/drools/resources/scripts/update-vfw-op-policy.sh 
or is it also deprecated ??

I expect that for Brian’s team it works smoothly and they are using robot 
instantiateVFWCL tag which I also get working in our lab
It seem to be updating operational policy correctly even setting-up of APPC 
mount point (at least it did not detect any problem)


[root@tomas-infra robot]# ./demo-k8s.sh onap instantiateVFW
Number of parameters:
2
KEY:
instantiateVFW
++ kubectl --namespace onap get pods
++ sed 's/ .*//'
++ grep robot
+ POD=onap-robot-robot-54dbc8d877-6zsg9
+ ETEHOME=/var/opt/ONAP
++ kubectl --namespace onap exec onap-robot-robot-54dbc8d877-6zsg9 -- bash -c 
'ls -1q /share/logs/ | wc -l'
+ export GLOBAL_BUILD_NUMBER=7
+ GLOBAL_BUILD_NUMBER=7
++ printf %04d 7
+ OUTPUT_FOLDER=0007_demo_instantiateVFW
+ DISPLAY_NUM=97
+ VARIABLEFILES='-V /share/config/vm_properties.py -V 
/share/config/integration_robot_properties.py -V 
/share/config/integration_preload_parameters.py'
+ kubectl --namespace onap exec onap-robot-robot-54dbc8d877-6zsg9 -- 
/var/opt/ONAP/runTags.sh -V /share/config/vm_properties.py -V 
/share/config/integration_robot_properties.py -V 
/share/config/integration_preload_parameters.py -v GLOBAL_BUILD_NUMBER:14065 -d 
/share/logs/0007_demo_instantiateVFW -i instantiateVFW --display 97
Starting Xvfb on display :97 with res 1280x1024x24
Executing robot tests at log level TRACE
==============================================================================
Testsuites
==============================================================================
Testsuites.Demo :: Executes the VNF Orchestration Test cases including setu...
==============================================================================
Instantiate VFW
Downloaded:service-Vfw20190621063917-csar.csar
Set VNF ProvStatus: 7117f108-7e2d-4d23-bd7b-291c5784fed6 to ACTIVE
Customer Name=DemoCust_0b305416-f7c7-4c2e-9ea4-21a37d37d808
VNF Module Name=Vfmodule_Ete_vFW_0b305416_0
Update old vFWCL Policy for 
ModelInvariantID=33e12efd-fd5e-4d06-9ad6-2dffde4422d3
Create vFWCL Monitoring Policy
Create vFWCL Operational Policy
{u'content': 
u'controlLoop%3A%0A++++version%3A+2.0.0%0A++++controlLoopName%3A+ControlLoop-vFirewall-33e12efd-fd5e-4d06-9ad6-2dffde4422d3%0A++++trigger_policy%3A+unique-policy-id-1-modifyConfig%0A++++timeout%3A+1200%0A++++abatement%3A+false%0Apolicies%3A%0A++++-+id%3A+unique-policy-id-1-modifyConfig%0A++++++name%3A+modify_packet_gen_config%0A++++++description%3A%0A++++++actor%3A+APPC%0A++++++recipe%3A+ModifyConfig%0A++++++target%3A%0A++++++++++resourceID%3A+33e12efd-fd5e-4d06-9ad6-2dffde4422d3%0A++++++++++type%3A+VNF%0A++++++payload%3A%0A++++++++++streams%3A+%27%7B%22active-streams%22%3A5%7D%27%0A++++++retry%3A+0%0A++++++timeout%3A+300%0A++++++success%3A+final_success%0A++++++failure%3A+final_failure%0A++++++failure_timeout%3A+final_failure_timeout%0A++++++failure_retries%3A+final_failure_retries%0A++++++failure_exception%3A+final_failure_exception%0A++++++failure_guard%3A+final_failure_guard%0A',
 u'policy-id': u'operational.modifyconfig'}
Push vFWCL To PDP Group
Validate vFWCL Policy
APPC Mount Point for VNF Module Name=Vfmodule_Ete_vFW_0b305416_0
| PASS |
------------------------------------------------------------------------------
Testsuites.Demo :: Executes the VNF Orchestration Test cases inclu... | PASS |
1 critical test, 1 passed, 0 failed
1 test total, 1 passed, 0 failed
==============================================================================
Testsuites                                                            | PASS |
1 critical test, 1 passed, 0 failed
1 test total, 1 passed, 0 failed
==============================================================================
Output:  /share/logs/0007_demo_instantiateVFW/output.xml
Log:     /share/logs/0007_demo_instantiateVFW/log.html
Report:  /share/logs/0007_demo_instantiateVFW/report.html

However I am not able to verify that as pdp in Dublin is not exposed to port 
8081:30221 (just 8081)
pdp                                ClusterIP      None            <none>        
                         8081/TCP                                               
       33h

but from pdp pod directly I can’t verify presence of controller

bash-4.4$ curl -k --silent --user '[email protected]:demo123456!' -X GET 
https://127.0.0.1:8081/policy/pdp/engine/controllers/amsterdam/
<!doctype html><html lang="en"><head><title>HTTP Status 404 – Not 
Found</title><style type="text/css">h1 
{font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;font-size:22px;}
 h2 
{font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;font-size:16px;}
 h3 
{font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;font-size:14px;}
 body {font-family:Tahoma,Arial,sans-serif;color:black;background-color:white;} 
b {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;} p 
{font-family:Tahoma,Arial,sans-serif;background:white;color:black;font-size:12px;}
 a {color:black;} a.name {color:black;} .line 
{height:1px;background-color:#525D76;border:none;}</style></head><body><h1>HTTP 
Status 404 – Not Found</h1><hr class="line" /><p><b>Type</b> Status 
Report</p><p><b>Message</b> Not found</p><p><b>Description</b> The origin 
server did not find a current representation for the target resource or is not 
willing to disclose that one exists.</p><hr class="line" /><h3>Apache 
Tomcat/9.0.16</h3></body></html>bash-4.4$

It looks there is no drools controller ??

[root@tomas-infra helm_charts]# kubectl exec -it onap-policy-drools-0 -n onap 
bash
bash-4.4$ policy status

[drools-pdp-controllers]
L []: Policy Management (pid 1069) is running
        0 cron jobs installed.

[features]
name                   version         status
----                   -------         ------
controlloop-management 1.4.2           enabled
healthcheck            1.4.0           enabled
controlloop-utils      1.4.2           disabled
controlloop-usecases   1.4.2           enabled
lifecycle              1.4.0           enabled
controlloop-trans      1.4.2           enabled
controlloop-amsterdam  1.4.2           enabled
distributed-locking    1.4.0           enabled

Q3) Do we need any drools controller in Dublin ?

Furthemore on DDF it was said that policy don’t have any runtime dependencies 
and it’s not even using brmsgw but I see some build errors when downloading 
some maven artifacts in brmsgw.log.

[INFO] ------------------------------------------------------------------------
[INFO] BUILD FAILURE
[INFO] ------------------------------------------------------------------------
[INFO] Total time:  5.632 s
[INFO] Finished at: 2019-06-21T13:08:49Z
[INFO] ------------------------------------------------------------------------
[ERROR] Plugin org.apache.maven.plugins:maven-clean-plugin:2.5 or one of its 
dependencies could not be resolved: Failed to read artifact descriptor for 
org.apache.maven.plugins:maven-clean-
plugin:jar:2.5: Could not transfer artifact 
org.apache.maven.plugins:maven-clean-plugin:pom:2.5 from/to central 
(https://repo.maven.apache.org/maven2<https://urldefense.proofpoint.com/v2/url?u=https-3A__repo.maven.apache.org_maven2&d=DwQFaQ&c=LFYZ-o9_HUMeMTSQicvjIg&r=e3d1ehx3DI5AoMgDmi2Fzw&m=9nPH5w15KuU4w1GFslbxb8LheQ55xYYeAlta8RIngvk&s=OlxEIwulXDKq6utIf9mCAO961ETvl0GX2sCNy8vdRZg&e=>):
 repo.maven.apache.org: Try again: Unk
nown host repo.maven.apache.org: Try again -> [Help 1]
[ERROR]
[ERROR] To see the full stack trace of the errors, re-run Maven with the -e 
switch.
[ERROR] Re-run Maven using the -X switch to enable full debug logging.

Q4) Do I need to collect all those maven artifacts for vFWCL or is it some old 
way I don’t need to reinvent in Dublin when trying to run vFWCL demo in new way 
?

if you have any other clues, please share … I guess more people will try to 
reproduce this scenario and I did not find any place where it is described for 
Dublin ☹

thanks a lot,
Michal





 [cid:[email protected]]

[http://ext.w1.samsung.net/mail/ext/v1/external/status/update?userid=m.ptacek&do=bWFpbElEPTIwMTkwNjIxMTQyOTQzZXVjYXMxcDExNmY4NjY0Zjg5MWVmYjA2MzA4ZDIxMDZiNmQ5OGI0ZSZyZWNpcGllbnRBZGRyZXNzPW9uYXAtZGlzY3Vzc0BsaXN0cy5vbmFwLm9yZw__]


-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.

View/Reply Online (#17689): https://lists.onap.org/g/onap-discuss/message/17689
Mute This Topic: https://lists.onap.org/mt/32158968/21656
Group Owner: [email protected]
Unsubscribe: https://lists.onap.org/g/onap-discuss/unsub  
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to