...
Project Name | Vuls Scan
| Lynis Scan
| Kube-Hunter Scan
| |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | 5G MEC/Slice System to Support Cloud Gaming, HD Video and Live Broadcasting Blueprint |
|
|
| ||||||||
2 | ||||||||||||
3 | Connected Vehicle Blueprint | 4 | Edge Video Processing | 5 | ELIOT: Edge Lightweight and IoT Blueprint Family | 6 | 7 | High:104 Medium:352 Low:74 High:61 Medium:280 Low:58 https://nexus.akraino.org/content/sites/logs/ huaweiblueprintsiotgateway/job/eliot-iotgateway-deploy- | Kube-Hunter: Exemption granted, this blueprint does not currently use Kubernetes per Thor Chin on 6/17/2020. | |||
4 | Edge Video Processing | |||||||||||
5 | ELIOT: Edge Lightweight and IoT Blueprint Family | |||||||||||
6 | ||||||||||||
7 | High:104 Medium:352 Low:74 https://nexus.akraino.org/content/sites/logs/huawei/blueprints/iotgateway/job/eliot-iotgateway-deploy-k8s-virtual-daily-master/430/results/os/vuls/ | https://nexus.akraino.org/content/sites/logs/huawei/blueprints/iotgateway/job/eliot-iotgateway-deploy-k8s-virtual-daily-master/430/results/os/lynis/ | ||||||||||
8 | High:87 Medium:168 Low:62 | |||||||||||
9 | Network Cloud and TF Integration Project | High:84 Medium:281 Low:59 https://nexus.akraino.org/content/sites/logs/juniper/validation/os/vuls/ | https://nexus.akraino.org/content/sites/logs/juniper/validation/os/lynis/ | Approved with exceptions. Upgrading K8s components causes the Airship deployment to fail and the regional controller becomes incompatible. The development team was told to use a specific version of the regional controller and airship (as the older versions are stable and newer are in flux and fragile). When the team upgraded to the new version as per the security team's suggestion, everything else fell apart. Making this change will require several months of work as the development team has to upgrade a component at a time to bring everything to the latest version of code. We will address this in the next release. | ||||||||
10 | Integrated Cloud Native NFV/App stack family (Short term: ICN) |
|
|
| ||||||||
11 | Integrated Edge Cloud (IEC) Blueprint Family | |||||||||||
12 | ||||||||||||
1213 | 13 | |||||||||||
14 | 2 | IEC) Blueprint Family | 14 | High:266 Medium:590 Low:106 | First Release - Kube-Hunter security scan not required. | |||||||
15 | High: | 266 61 Medium: | 590 280 Low: | 106First Release - Kube-Hunter security scan not required. | 15 | IEC Type 4: AR/VR oriented Edge Stack for Integrated Edge Cloud (IEC) Blueprint Family 58 https://nexus.akraino.org/content/sites/logs/ampere/iec-type4/logs/ | Kube-Hunter: Exemption granted, this blueprint does not currently use Kubernetes per Thor Chin on 6/17/2020. | |||||
16 | High:266 Medium:590 Low:106 https://nexus.akraino.org/content/sites/logs/bytedance/job/type5_security_scan/1/vuls.log | Hardening index : [63] [############ ] https://nexus.akraino.org/content/sites/logs/bytedance/job/type5_security_scan/1/lynis.log | Kube-Hunter: Exemption granted, this blueprint does not currently use Kubernetes. | |||||||||
17 | Kubernetes-Native Infrastructure (KNI) Blueprint Family | We have RHCOS on our cluster, so vuls doesn't apply to it | lynis.log | Fail. We request for exception as we are running OpenShift and not upstream Kubernetes, so we hit several failures: cluster.log , pod.log https://logs.akraino.org/redhat-kni/bluval_results/blueprint-pae/20200423-071856/results/k8s/kube-hunter/Kube-Hunter.Kube-Hunter/cluster.log , https://logs.akraino.org/redhat-kni/bluval_results/blueprint-pae/20200423-071856/results/k8s/kube-hunter/Kube-Hunter.Kube-Hunter | ||||||||
18 | First release - security scan not required. | First release - security scan not required. | First release - security scan not required. | |||||||||
19 | The AI Edge: School/Education Video Security Monitoring | https://nexus.akraino.org/content/sites/logs/baidu/job/security_scan/aiedge/1/vuls/ | https://nexus.akraino.org/content/sites/logs/baidu/job/security_scan/aiedge/1/lynis/ | https://nexus.akraino.org/content/sites/logs/baidu/job/security_scan/aiedge/1/kube-hunter/ | ||||||||
20 | Network Cloud Blueprint Family | |||||||||||
21 | StarlingX Far Edge Distributed Cloud | |||||||||||
22 | Telco Appliance Blueprint Family | |||||||||||
23 | Fail with Exceptions 0 CVEs are detected with OVA | Pass with Exceptions Tests performed: 287 | Pass with Exceptions All Critical Tests Passed KHV005 Access to API using service account token | |||||||||
24 | ||||||||||||
25 | The AI Edge Blueprint Family | |||||||||||
26 | ||||||||||||
27 | Public Cloud Edge Interface | Pass with exceptions High:41 Medium:239 Low:32 | Pass with exceptions Hardening index : 62 [############ ] https://nexus.akraino.org/content/sites/logs/cmti/job/lynis/ | No k8s cluster as part of deployment at the moment | ||||||||
28 | Enterprise Applications on Lightweight 5G Telco Edge | High:84 Medium:294 Low:53 | Hardening index : [57] [########### ] | cluster.log KHV002 Information Disclosure pod.log | ||||||||
29 | ||||||||||||
30 |
...