--- id: CUST-WP-0064 type: workplan title: "Controlled scan inputs for authoritative daily SBOM catch-up" domain: infotech repo: the-custodian status: active owner: codex topic_slug: custodian planning_priority: high planning_order: 64 created: "2026-08-22" updated: "2026-08-22" quality_dor: DoR-Ok quality_dor_at: "2026-08-22" quality_dor_by: codex quality_dor_note: "Current no-checkout production evidence, owner boundaries, trust decisions, dependencies, acceptance evidence, and rollback requirements were reviewed against SBOM-WP-0002 and ACTIVITY-WP-0030/0033." origin: residual origin_ref: CUST-WP-0062 related: - SBOM-WP-0002 - ACTIVITY-WP-0030 - ACTIVITY-WP-0033 - RMGR-WP-0011 state_hub_workstream_id: "c06ca8e9-8240-5cdf-8013-4e3a9ba8f1d8" --- # Controlled scan inputs for authoritative daily SBOM catch-up ## Goal Give the private SBOM Nexus production plane a controlled, revision-pinned source input so bounded daily catch-up can produce authoritative ingested snapshots. Current scheduling, ranking, fairness, and zero-task behavior are proven, but production attempts are `no-checkout` because workstation paths are not reachable inside the cluster. This is a coordination workplan. SBOM Nexus owns scan semantics and durable history; Repo Manager owns repository identity, active status, and source-path projection; Activity Core owns recurrence and the at-most-N workflow bound; the deployment package owns the runtime/network boundary. ## Select the source-transfer and trust-boundary contract ```task id: CUST-WP-0064-T01 status: progress priority: high state_hub_task_id: "02ac7278-8536-5ce8-9027-39345aab0539" ``` Choose one controlled input shape—such as a revision-pinned Forgejo clone in a short-lived scanner job or a content-addressed source artifact—without mounting operator workstations into the cluster. Define repository/revision identity, authentication custody, size/time limits, egress, provenance, unsupported repo behavior, cleanup, and the boundary between preview and authoritative ingest. Done when the four owning repos have one reviewable contract and rollback; do not enable source transfer from a prose-only assumption. **Started (2026-08-22):** live verification confirmed the private Nexus pod cannot reach projected workstation checkout paths and that queue fairness is therefore advancing through `no-checkout` outcomes. The Custodian fixed the non-negotiable boundary—revision-pinned input, no workstation mount, bounded credentials/egress/time/size, provenance, cleanup, and rollback—and routed owner participation to SBOM Nexus (`95c1b226`), Repo Manager (`075e21de`), Activity Core (`7233d2d1`), and the package owner (`e0af24b1`). Selection of the concrete transfer mechanism remains in progress. ## Implement the Nexus-owned authoritative scan path ```task id: CUST-WP-0064-T02 status: wait priority: high state_hub_task_id: "2029e525-0573-5fea-881c-d3a418b91c9d" ``` Depends on T01. Open and execute the SBOM Nexus/package child work needed to consume the selected input, scan at a pinned revision, persist provenance, and remove temporary source material. Preserve Nexus as the only snapshot writer and enforce `CUST-IN-0013` operation idempotency on the mutation boundary. ## Retarget bounded catch-up without widening it ```task id: CUST-WP-0064-T03 status: wait priority: high state_hub_task_id: "6c645778-be59-57b1-bf44-d974a3a1e49f" ``` Depends on T02 and `RMGR-WP-0011`. Supply the controlled input reference for the already-fixed oldest-N target set. Activity Core must still process no more than `catch_up_limit`, reuse the same targets and operation ids across retries, and record terminal unsupported/failed inputs without advancing into a second batch. ## Prove real daily freshness improvement ```task id: CUST-WP-0064-T04 status: wait priority: medium state_hub_task_id: "664d90b0-1169-58fa-9a77-df53e739f957" ``` Run an attended bounded proof, then observe a normal scheduled fire. Require at least one `ingested` outcome with repository slug, immutable revision, snapshot id, and licence summary; zero spawned tasks; cleanup of transient source; and truthful `last_success_at` / State Hub compatibility projection. Record the remaining `never_count` and operator disable/rollback controls. ## Acceptance - [ ] Production scans consume a controlled, revision-pinned source input - [ ] No workstation filesystem is mounted or implicitly trusted - [ ] Nexus remains the only authoritative snapshot writer - [ ] One fire remains bounded to its original N targets across retries - [ ] At least one normal scheduled fire produces real ingested snapshots - [ ] Source cleanup, provenance, failure evidence, and rollback are verified