the-custodian/workplans/CUST-WP-0064-sbom-controlled-scan-inputs.md
repo-manager 9751923028
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
chore(registrar): assign State Hub identifiers
2026-08-22 22:58:35 +02:00

3.8 KiB

id type title domain repo status owner topic_slug planning_priority planning_order created updated origin origin_ref related state_hub_workstream_id
CUST-WP-0064 workplan Controlled scan inputs for authoritative daily SBOM catch-up infotech the-custodian ready codex custodian high 64 2026-08-22 2026-08-22 residual CUST-WP-0062
SBOM-WP-0002
ACTIVITY-WP-0030
ACTIVITY-WP-0033
RMGR-WP-0011
c06ca8e9-8240-5cdf-8013-4e3a9ba8f1d8

Controlled scan inputs for authoritative daily SBOM catch-up

Goal

Give the private SBOM Nexus production plane a controlled, revision-pinned source input so bounded daily catch-up can produce authoritative ingested snapshots. Current scheduling, ranking, fairness, and zero-task behavior are proven, but production attempts are no-checkout because workstation paths are not reachable inside the cluster.

This is a coordination workplan. SBOM Nexus owns scan semantics and durable history; Repo Manager owns repository identity, active status, and source-path projection; Activity Core owns recurrence and the at-most-N workflow bound; the deployment package owns the runtime/network boundary.

Select the source-transfer and trust-boundary contract

id: CUST-WP-0064-T01
status: todo
priority: high
state_hub_task_id: "02ac7278-8536-5ce8-9027-39345aab0539"

Choose one controlled input shape—such as a revision-pinned Forgejo clone in a short-lived scanner job or a content-addressed source artifact—without mounting operator workstations into the cluster. Define repository/revision identity, authentication custody, size/time limits, egress, provenance, unsupported repo behavior, cleanup, and the boundary between preview and authoritative ingest.

Done when the four owning repos have one reviewable contract and rollback; do not enable source transfer from a prose-only assumption.

Implement the Nexus-owned authoritative scan path

id: CUST-WP-0064-T02
status: wait
priority: high
state_hub_task_id: "2029e525-0573-5fea-881c-d3a418b91c9d"

Depends on T01. Open and execute the SBOM Nexus/package child work needed to consume the selected input, scan at a pinned revision, persist provenance, and remove temporary source material. Preserve Nexus as the only snapshot writer and enforce CUST-IN-0013 operation idempotency on the mutation boundary.

Retarget bounded catch-up without widening it

id: CUST-WP-0064-T03
status: wait
priority: high
state_hub_task_id: "6c645778-be59-57b1-bf44-d974a3a1e49f"

Depends on T02 and RMGR-WP-0011. Supply the controlled input reference for the already-fixed oldest-N target set. Activity Core must still process no more than catch_up_limit, reuse the same targets and operation ids across retries, and record terminal unsupported/failed inputs without advancing into a second batch.

Prove real daily freshness improvement

id: CUST-WP-0064-T04
status: wait
priority: medium
state_hub_task_id: "664d90b0-1169-58fa-9a77-df53e739f957"

Run an attended bounded proof, then observe a normal scheduled fire. Require at least one ingested outcome with repository slug, immutable revision, snapshot id, and licence summary; zero spawned tasks; cleanup of transient source; and truthful last_success_at / State Hub compatibility projection. Record the remaining never_count and operator disable/rollback controls.

Acceptance

  • Production scans consume a controlled, revision-pinned source input
  • No workstation filesystem is mounted or implicitly trusted
  • Nexus remains the only authoritative snapshot writer
  • One fire remains bounded to its original N targets across retries
  • At least one normal scheduled fire produces real ingested snapshots
  • Source cleanup, provenance, failure evidence, and rollback are verified