the-custodian/workplans/CUST-WP-0064-sbom-controlled-scan-inputs.md
codex 03e28cecf5
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
workplans: record sbom runtime residuals
2026-08-22 23:06:58 +02:00

4.6 KiB

id type title domain repo status owner topic_slug planning_priority planning_order created updated quality_dor quality_dor_at quality_dor_by quality_dor_note origin origin_ref related state_hub_workstream_id
CUST-WP-0064 workplan Controlled scan inputs for authoritative daily SBOM catch-up infotech the-custodian active codex custodian high 64 2026-08-22 2026-08-22 DoR-Ok 2026-08-22 codex Current no-checkout production evidence, owner boundaries, trust decisions, dependencies, acceptance evidence, and rollback requirements were reviewed against SBOM-WP-0002 and ACTIVITY-WP-0030/0033. residual CUST-WP-0062
SBOM-WP-0002
ACTIVITY-WP-0030
ACTIVITY-WP-0033
RMGR-WP-0011
c06ca8e9-8240-5cdf-8013-4e3a9ba8f1d8

Controlled scan inputs for authoritative daily SBOM catch-up

Goal

Give the private SBOM Nexus production plane a controlled, revision-pinned source input so bounded daily catch-up can produce authoritative ingested snapshots. Current scheduling, ranking, fairness, and zero-task behavior are proven, but production attempts are no-checkout because workstation paths are not reachable inside the cluster.

This is a coordination workplan. SBOM Nexus owns scan semantics and durable history; Repo Manager owns repository identity, active status, and source-path projection; Activity Core owns recurrence and the at-most-N workflow bound; the deployment package owns the runtime/network boundary.

Select the source-transfer and trust-boundary contract

id: CUST-WP-0064-T01
status: progress
priority: high
state_hub_task_id: "02ac7278-8536-5ce8-9027-39345aab0539"

Choose one controlled input shape—such as a revision-pinned Forgejo clone in a short-lived scanner job or a content-addressed source artifact—without mounting operator workstations into the cluster. Define repository/revision identity, authentication custody, size/time limits, egress, provenance, unsupported repo behavior, cleanup, and the boundary between preview and authoritative ingest.

Done when the four owning repos have one reviewable contract and rollback; do not enable source transfer from a prose-only assumption.

Started (2026-08-22): live verification confirmed the private Nexus pod cannot reach projected workstation checkout paths and that queue fairness is therefore advancing through no-checkout outcomes. The Custodian fixed the non-negotiable boundary—revision-pinned input, no workstation mount, bounded credentials/egress/time/size, provenance, cleanup, and rollback—and routed owner participation to SBOM Nexus (95c1b226), Repo Manager (075e21de), Activity Core (7233d2d1), and the package owner (e0af24b1). Selection of the concrete transfer mechanism remains in progress.

Implement the Nexus-owned authoritative scan path

id: CUST-WP-0064-T02
status: wait
priority: high
state_hub_task_id: "2029e525-0573-5fea-881c-d3a418b91c9d"

Depends on T01. Open and execute the SBOM Nexus/package child work needed to consume the selected input, scan at a pinned revision, persist provenance, and remove temporary source material. Preserve Nexus as the only snapshot writer and enforce CUST-IN-0013 operation idempotency on the mutation boundary.

Retarget bounded catch-up without widening it

id: CUST-WP-0064-T03
status: wait
priority: high
state_hub_task_id: "6c645778-be59-57b1-bf44-d974a3a1e49f"

Depends on T02 and RMGR-WP-0011. Supply the controlled input reference for the already-fixed oldest-N target set. Activity Core must still process no more than catch_up_limit, reuse the same targets and operation ids across retries, and record terminal unsupported/failed inputs without advancing into a second batch.

Prove real daily freshness improvement

id: CUST-WP-0064-T04
status: wait
priority: medium
state_hub_task_id: "664d90b0-1169-58fa-9a77-df53e739f957"

Run an attended bounded proof, then observe a normal scheduled fire. Require at least one ingested outcome with repository slug, immutable revision, snapshot id, and licence summary; zero spawned tasks; cleanup of transient source; and truthful last_success_at / State Hub compatibility projection. Record the remaining never_count and operator disable/rollback controls.

Acceptance

  • Production scans consume a controlled, revision-pinned source input
  • No workstation filesystem is mounted or implicitly trusted
  • Nexus remains the only authoritative snapshot writer
  • One fire remains bounded to its original N targets across retries
  • At least one normal scheduled fire produces real ingested snapshots
  • Source cleanup, provenance, failure evidence, and rollback are verified