Adopt Alpine as the sanctioned base; release candidate scans clean
Operator adopted Alpine/musl as the base and trivy as the scanner. Containerfile.alpine is promoted to Containerfile and the Debian slim variant is retired rather than kept as an option -- it shipped three perl-base CRITICALs with no upstream fix, in a package this service never invokes. Promoting Alpine left 7 HIGH and 1 MEDIUM, all libuuid 2.42.1-r0 as shipped by the pinned Alpine 3.24.1, and all with fixes in 2.42.3. The runtime stage now requires libuuid>=2.42.3-r1. That is a version floor, not a floating upgrade: the base stays digest-pinned and reproducible, and a vulnerable libuuid fails the build instead of shipping. The candidate scans 0 CRITICAL / 0 HIGH / 0 MEDIUM / 0 LOW. Verified on that exact artifact: non-root uid 10001, pip absent, schema v3, tenant default tenant:platform, fresh-store migrate and verify clean, restart persistence via re-verify on the same volume, both production fail-closed refusals, 111 tests on musl, kubectl dry-run passing. The gate is now reproducible instead of a one-off. make image-scan fails on any CRITICAL or HIGH, and make image-release runs build then scan then push, so a failing scan blocks the push by construction rather than by whoever remembers to look. Not released. docker push was attempted and refused by this session's sandbox as an outward-facing publish, and was not worked around. No release digest exists, so the manifest deliberately keeps REPLACE_WITH_RELEASE_DIGEST -- it must be pinned to the registry manifest digest, never the tag and never the local image id. T03 stays wait on that push plus the still-unmaterialized KeyCape registrations and audit sender credential. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PM5HnEAhokxdfcPqBNpT7D Assistant: claude-code Assistant-Model: opus Assistant-Process: 715850@bnt-lap001 Assistant-Session: eb557e93-7cb1-45d0-9e57-7d15b3edc60e
This commit is contained in:
parent
f88a92fb37
commit
d7a9fe53db
5 changed files with 154 additions and 75 deletions
|
|
@ -232,6 +232,36 @@ carries `REPLACE_WITH_RELEASE_DIGEST`. Awaiting an owner answer on the base
|
|||
(Alpine, a documented perl exception on glibc, or distroless — unevaluated) and
|
||||
on which scanner is sanctioned.
|
||||
|
||||
2026-09-06 both answered; release candidate scans clean. The operator adopted
|
||||
Alpine/musl as the sanctioned base and trivy as the sanctioned scanner.
|
||||
`Containerfile.alpine` is promoted to `Containerfile` and the Debian variant is
|
||||
retired rather than kept as an option.
|
||||
|
||||
Promoting Alpine left 7 HIGH and 1 MEDIUM, all `libuuid` 2.42.1-r0 and all with
|
||||
fixes in 2.42.3. The runtime stage now requires `libuuid>=2.42.3-r1` — a version
|
||||
floor rather than a floating upgrade, so the base stays digest-pinned and a
|
||||
vulnerable libuuid fails the build instead of shipping. **The candidate now
|
||||
scans 0 CRITICAL / 0 HIGH / 0 MEDIUM / 0 LOW.**
|
||||
|
||||
Verified on that exact artifact: non-root `uid=10001`, pip absent, schema v3,
|
||||
tenant default `tenant:platform`, fresh-store `migrate`+`verify` clean, restart
|
||||
persistence via re-`verify` on the same volume, both production fail-closed
|
||||
refusals, 111 tests on musl, and `kubectl --dry-run` passing.
|
||||
|
||||
The gate is now reproducible rather than a one-off: `make image-scan` fails on
|
||||
any CRITICAL or HIGH, and `make image-release` runs build then scan then push so
|
||||
a failing scan blocks the push by construction.
|
||||
|
||||
Still `wait`, and now for exactly one reason: `docker push` was attempted and
|
||||
refused by this session's sandbox as an outward-facing publish. It was not
|
||||
worked around. No release digest exists, so the manifest keeps
|
||||
`REPLACE_WITH_RELEASE_DIGEST`; an operator must run `make image-release` (or the
|
||||
push and `docker inspect`) and pin the returned registry manifest digest — never
|
||||
the tag, never the local image id
|
||||
`sha256:73333f5ceb55e48192e3095cb2e2a741cdc6ff0be2f18128301072b4a6b6eb9d`.
|
||||
Rollout, restart and restore evidence remain gated on the KeyCape registrations
|
||||
and audit sender credential.
|
||||
|
||||
## Wire outbox delivery and reconciliation
|
||||
|
||||
```task
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue