Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

ActionDescriptionStatusDue DateAssigned to

Service Architecture Documented

Make a reference drawing of service architecture

Seamless Access Deployment Architecture

Status
colourGreen
titledone


Marina, consult with Leif
Update the requirements for service operations

To reflect the service architecture that was documented

Seamless Access Operational Requirements

Status
colourGreen
titledone


Marina, consult with Leif
Deploy beta service

First node deployed by end of November. Docker environment was prepared and remaining nodes deployment should be an easy exercise.

Two production nodes in SUNET network are created. 

 Maria to check with Leif on creating the AWS machines.

Status
titleIN progress

Two production nodes are done


Maria, Leif
Definition for the hosting environment firewall capabilities

That will be implemented in all different environment. 

This becomes part of the service definition for baseline operations.

Seamless Access Operational Documentation

Status
colourGreen
titledone


Leif
Prepare the OLA

Marina received the GEANT template OLA 

https://docs.google.com/document/d/1vw-V9VsdRmiGa4lAI-wZlaHzHwSZ9GSMXcXRcg1JfA4/edit

Draft OLA prepared: https://wiki.geant.org/pages/resumedraft.action?draftId=114921107&draftShareId=f423f5ac-a6c2-40a8-8e97-7220fbf6ccb7&

Marina created draft, was checked with GEANT ops team. It was shared on 26th Nov with Jonny from sunet noc. 

Status
titleIN progress


First draft till 10th OctoberMarina (consult with Jonny)
Pen testing of the beta service

Agreed with DFN cert that the pen testing will be 3rd week of November. We should let them know about our readiness on first week of November.

2 types of pen testing will be done: no info then full info. First just give the domain. End then we give them the zone file.

Talk to heather  - report of the audit that was alreday done for the privacy audit. WAYF Cloud and P3W Security & Privacy Recommendations

First round done in 28th Nov.

Marina Adomeit to arrange with Klaus/dfn cert for the next pen testing round. 

Status
titleIN progress

Dependent on deploying beta serviceMarina via DFN cert (consult Leif, inform Jonny of results)
Code testing of code that is running as web app

Audit for modern Java Script. Marina is checking with Marcin. There seams to be capability for Java Script testing. Waiting to get info from Leif. 

Marina Adomeit to check again!




Marina via Marcin (consult Leif, inform Jonny of results)
Get budget for the monitoring, and clean up the ops budget

status.io, pingdom.com

Marina will prepare the CR from Elena ... use 20 k and move to monitoring and VMs

Marina Adomeit to do the budget assignment 

Marina Adomeit remind Leif to agree which kind of licence we need for those  

WP5 leaders approved the 10k budget, need to make the CRFirst week OctoberMarina
Configure internal monitoring

Setup an idenpendent Nagios instance in SUNET.

Maria did the most of the work. Some minor things and integration with Slack is left over.

Status
titleIN progress


Maria
Organise purchase of supporting services

status.io

pingdom.com

CDN

Marina Adomeit to talk to Nicole to do the PO for this

Status
colourGreen
titledone
 for status.io and pingdom.con 

Status
titlenot started
 for CDN

End November....Marina to initiate via Task 3
Configure external monitoring

Nagios - done!!!, integration in slack in progress

status.io - 

Pingdom - 

Once licence is available move to the licensed instance

Status
colourGreen
titleIN progressdone

End October (with deployment of beta service)Maria
Prepare the financial consumption reporting

when all supporting services are purchasedMarina
Prepare the ops reportingMarina regular checks with Maria, every Friday 12:00

Status
colourGreen
titledone


Marina
Check the GDPR

User never touches any of the nodes that are maintained by seamless access.org. The only interaction point is the CDN. Their privacy policy and DPA should be checked!!! 

technology-compliance

Document the data flow for Seamless Access https://docs.google.com/presentation/d/1emWsyTn6trMRCCNbTHrGHYHrajtHfOZl0--T70BFe_o/edit?usp=sharing 

Based on the data flow, Magdalena can review the GDPR

external audit on privacy statements - in 2020 as service proves viable

Status
titleIN progress


Marina via GEANT project GDPR
Check the IPR

Leif needs to put the SUNET licence and check the the libraries

Magdalena organised code scanning for the libraries used and on 06.12.2019 confirmed all is in order: 

Regarding scanning of the code provided https://github.com/TheIdentitySelector in most of the files no source/binary files were detected, consequently no licence/vulnerabilities were detected. In the js-storage-master file there were 3 licences detected (MIT licences) – as this is permissive licence, there are no further issues with it. 

Marina Adomeit

Status
colourGreen
titleIN progressdone


Leif, Marina to connect Leif to Magdalena
Configuration change, Release management, Regular updates process

Define the configuration change process. Should be reflected in the OLA. Have in mind other ops regions

Marina Adomeit to start writing this! 



Marina (consult with Jonny)
Support processDefine who the support process flow, the actors etc. Should be reflected in the OLA. Have in mind other ops regions. 

Marina (consult with Jonny) and take up with Heather
Service on boarding process



Formulate the L3 support Leif + certain members from the Technical Sterring group

Marina to take up with Heather
Service operations definition

Prepare a definition of the service ops baseline for additional operators of the service.

Security groups and firewall



Marina and Maria, consult with Leif, Tech Steerting group for approval. 

...