the-custodian/workplans/CUST-WP-0064-sbom-controlled-scan-inputs.md
codex 03e28cecf5
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
workplans: record sbom runtime residuals
2026-08-22 23:06:58 +02:00

121 lines
4.6 KiB
Markdown

---
id: CUST-WP-0064
type: workplan
title: "Controlled scan inputs for authoritative daily SBOM catch-up"
domain: infotech
repo: the-custodian
status: active
owner: codex
topic_slug: custodian
planning_priority: high
planning_order: 64
created: "2026-08-22"
updated: "2026-08-22"
quality_dor: DoR-Ok
quality_dor_at: "2026-08-22"
quality_dor_by: codex
quality_dor_note: "Current no-checkout production evidence, owner boundaries, trust decisions, dependencies, acceptance evidence, and rollback requirements were reviewed against SBOM-WP-0002 and ACTIVITY-WP-0030/0033."
origin: residual
origin_ref: CUST-WP-0062
related:
- SBOM-WP-0002
- ACTIVITY-WP-0030
- ACTIVITY-WP-0033
- RMGR-WP-0011
state_hub_workstream_id: "c06ca8e9-8240-5cdf-8013-4e3a9ba8f1d8"
---
# Controlled scan inputs for authoritative daily SBOM catch-up
## Goal
Give the private SBOM Nexus production plane a controlled, revision-pinned
source input so bounded daily catch-up can produce authoritative ingested
snapshots. Current scheduling, ranking, fairness, and zero-task behavior are
proven, but production attempts are `no-checkout` because workstation paths
are not reachable inside the cluster.
This is a coordination workplan. SBOM Nexus owns scan semantics and durable
history; Repo Manager owns repository identity, active status, and source-path
projection; Activity Core owns recurrence and the at-most-N workflow bound;
the deployment package owns the runtime/network boundary.
## Select the source-transfer and trust-boundary contract
```task
id: CUST-WP-0064-T01
status: progress
priority: high
state_hub_task_id: "02ac7278-8536-5ce8-9027-39345aab0539"
```
Choose one controlled input shape—such as a revision-pinned Forgejo clone in a
short-lived scanner job or a content-addressed source artifact—without mounting
operator workstations into the cluster. Define repository/revision identity,
authentication custody, size/time limits, egress, provenance, unsupported repo
behavior, cleanup, and the boundary between preview and authoritative ingest.
Done when the four owning repos have one reviewable contract and rollback; do
not enable source transfer from a prose-only assumption.
**Started (2026-08-22):** live verification confirmed the private Nexus pod
cannot reach projected workstation checkout paths and that queue fairness is
therefore advancing through `no-checkout` outcomes. The Custodian fixed the
non-negotiable boundary—revision-pinned input, no workstation mount, bounded
credentials/egress/time/size, provenance, cleanup, and rollback—and routed
owner participation to SBOM Nexus (`95c1b226`), Repo Manager (`075e21de`),
Activity Core (`7233d2d1`), and the package owner (`e0af24b1`). Selection of
the concrete transfer mechanism remains in progress.
## Implement the Nexus-owned authoritative scan path
```task
id: CUST-WP-0064-T02
status: wait
priority: high
state_hub_task_id: "2029e525-0573-5fea-881c-d3a418b91c9d"
```
Depends on T01. Open and execute the SBOM Nexus/package child work needed to
consume the selected input, scan at a pinned revision, persist provenance, and
remove temporary source material. Preserve Nexus as the only snapshot writer
and enforce `CUST-IN-0013` operation idempotency on the mutation boundary.
## Retarget bounded catch-up without widening it
```task
id: CUST-WP-0064-T03
status: wait
priority: high
state_hub_task_id: "6c645778-be59-57b1-bf44-d974a3a1e49f"
```
Depends on T02 and `RMGR-WP-0011`. Supply the controlled input reference for
the already-fixed oldest-N target set. Activity Core must still process no more
than `catch_up_limit`, reuse the same targets and operation ids across retries,
and record terminal unsupported/failed inputs without advancing into a second
batch.
## Prove real daily freshness improvement
```task
id: CUST-WP-0064-T04
status: wait
priority: medium
state_hub_task_id: "664d90b0-1169-58fa-9a77-df53e739f957"
```
Run an attended bounded proof, then observe a normal scheduled fire. Require at
least one `ingested` outcome with repository slug, immutable revision, snapshot
id, and licence summary; zero spawned tasks; cleanup of transient source; and
truthful `last_success_at` / State Hub compatibility projection. Record the
remaining `never_count` and operator disable/rollback controls.
## Acceptance
- [ ] Production scans consume a controlled, revision-pinned source input
- [ ] No workstation filesystem is mounted or implicitly trusted
- [ ] Nexus remains the only authoritative snapshot writer
- [ ] One fire remains bounded to its original N targets across retries
- [ ] At least one normal scheduled fire produces real ingested snapshots
- [ ] Source cleanup, provenance, failure evidence, and rollback are verified