Run the scan gate; harden the image and stop short of release
glas-harness asked for a scanned immutable image. The scan ran, and it failed on the base we had sanctioned, so no image was pushed. Every finding is inherited from the base image or its distro packages; none is in approval_engine code. Two fixes applied here: The base pin was stale. It named a Debian 13.5 build of python:3.12-slim while upstream is 13.6. Bumping the digest removes 30 HIGH and 47 MEDIUM on its own. Still a digest, not a floating tag. pip is gone from the runtime image. All 10 MEDIUM Python findings were in pip itself, a build-time tool with no business in a running approval service. The build is now two-stage, and pip is removed from both the venv and the base's /usr/local, so command -v pip returns nothing. What remains is a decision rather than a task. Three CRITICALs persist on Debian, all perl-base (CVE-2026-13221, CVE-2026-42496, CVE-2026-8376), none with an upstream fix, in a package this service never invokes and that Debian marks Essential. An Alpine variant carries no perl and scans 0 CRITICAL / 7 HIGH / 1 MEDIUM against Debian's 3 / 51 / 56. Alpine is proven viable rather than asserted: musl wheels resolve with no toolchain, the full suite passes on musl at 111 tests, and non-root uid 10001, schema v3, tenant:platform, fresh-store migrate/verify and both production fail-closed gates all hold in the built image. It is parked in Containerfile.alpine as a candidate; Containerfile remains sanctioned. Nothing was released. Pushing the Debian variant would pin three unfixable CRITICALs into a release digest, and choosing the runtime C library for this service is not a call to make silently. The manifest still carries REPLACE_WITH_RELEASE_DIGEST. Full record in docs/image-scan-2026-09-06.md. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PM5HnEAhokxdfcPqBNpT7D Assistant: claude-code Assistant-Model: opus Assistant-Process: 715850@bnt-lap001 Assistant-Session: eb557e93-7cb1-45d0-9e57-7d15b3edc60e
This commit is contained in:
parent
6d18f62a90
commit
f88a92fb37
4 changed files with 214 additions and 5 deletions
|
|
@ -203,6 +203,35 @@ inventory a scanner needs is the pinned base above plus
|
|||
T03 stays `wait`: still no release digest, no KeyCape/audit credentials, no
|
||||
rollout, and no restart/restore evidence. Nothing here is a deploy.
|
||||
|
||||
2026-09-06 scan gate — run, and it failed on the sanctioned base. Full record in
|
||||
`docs/image-scan-2026-09-06.md`. Scanned with trivy (no scanner was installed;
|
||||
this one needed none). Findings are all inherited from the base image, none in
|
||||
`approval_engine` code.
|
||||
|
||||
Two fixes applied. The base pin was stale at Debian 13.5 while upstream is
|
||||
13.6 — bumping the digest removed 30 HIGH and 47 MEDIUM. And pip, which held all
|
||||
10 MEDIUM Python findings, is now absent from the runtime image via a two-stage
|
||||
build; it is a build-time tool and had no business in a running approval
|
||||
service.
|
||||
|
||||
What remains is a decision, not a task. Three CRITICALs persist on Debian, all
|
||||
`perl-base` (`CVE-2026-13221`, `CVE-2026-42496`, `CVE-2026-8376`), **none with
|
||||
an upstream fix**, in a package this service never invokes and which Debian
|
||||
marks `Essential: yes`. An Alpine variant carries no perl and scans 0 CRITICAL /
|
||||
7 HIGH / 1 MEDIUM against Debian's 3 / 51 / 56. It is proven viable — musl
|
||||
wheels resolve without a toolchain, the full suite passes on musl at 111, and
|
||||
non-root identity, schema v3, `tenant:platform`, fresh-store migrate/verify and
|
||||
both production fail-closed gates all hold in the image. It is parked in
|
||||
`Containerfile.alpine` as a candidate; `Containerfile` remains the sanctioned
|
||||
base.
|
||||
|
||||
Nothing was pushed. Pushing the Debian variant would pin three unfixable
|
||||
CRITICALs into a release digest, and choosing the runtime C library for this
|
||||
service is not a call to make silently. `deploy/approval-engine.yaml` still
|
||||
carries `REPLACE_WITH_RELEASE_DIGEST`. Awaiting an owner answer on the base
|
||||
(Alpine, a documented perl exception on glibc, or distroless — unevaluated) and
|
||||
on which scanner is sanctioned.
|
||||
|
||||
## Wire outbox delivery and reconciliation
|
||||
|
||||
```task
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue