151 lines
6.6 KiB
Markdown
151 lines
6.6 KiB
Markdown
---
|
|
id: CUST-WP-0064
|
|
type: workplan
|
|
title: "Controlled scan inputs for authoritative daily SBOM catch-up"
|
|
domain: infotech
|
|
repo: the-custodian
|
|
status: active
|
|
owner: codex
|
|
topic_slug: custodian
|
|
planning_priority: high
|
|
planning_order: 64
|
|
created: "2026-08-22"
|
|
updated: "2026-08-23"
|
|
quality_dor: DoR-Ok
|
|
quality_dor_at: "2026-08-22"
|
|
quality_dor_by: codex
|
|
quality_dor_note: "Current no-checkout production evidence, owner boundaries, trust decisions, dependencies, acceptance evidence, and rollback requirements were reviewed against SBOM-WP-0002 and ACTIVITY-WP-0030/0033."
|
|
origin: residual
|
|
origin_ref: CUST-WP-0062
|
|
related:
|
|
- SBOM-WP-0002
|
|
- ACTIVITY-WP-0030
|
|
- ACTIVITY-WP-0033
|
|
- RMGR-WP-0011
|
|
state_hub_workstream_id: "c06ca8e9-8240-5cdf-8013-4e3a9ba8f1d8"
|
|
---
|
|
|
|
# Controlled scan inputs for authoritative daily SBOM catch-up
|
|
|
|
## Goal
|
|
|
|
Give the private SBOM Nexus production plane a controlled, revision-pinned
|
|
source input so bounded daily catch-up can produce authoritative ingested
|
|
snapshots. Current scheduling, ranking, fairness, and zero-task behavior are
|
|
proven, but production attempts are `no-checkout` because workstation paths
|
|
are not reachable inside the cluster.
|
|
|
|
This is a coordination workplan. SBOM Nexus owns scan semantics and durable
|
|
history; Repo Manager owns repository identity, active status, and source-path
|
|
projection; Activity Core owns recurrence and the at-most-N workflow bound;
|
|
the deployment package owns the runtime/network boundary.
|
|
|
|
## Select the source-transfer and trust-boundary contract
|
|
|
|
```task
|
|
id: CUST-WP-0064-T01
|
|
status: done
|
|
priority: high
|
|
state_hub_task_id: "02ac7278-8536-5ce8-9027-39345aab0539"
|
|
```
|
|
|
|
Choose one controlled input shape—such as a revision-pinned Forgejo clone in a
|
|
short-lived scanner job or a content-addressed source artifact—without mounting
|
|
operator workstations into the cluster. Define repository/revision identity,
|
|
authentication custody, size/time limits, egress, provenance, unsupported repo
|
|
behavior, cleanup, and the boundary between preview and authoritative ingest.
|
|
|
|
Done when the four owning repos have one reviewable contract and rollback; do
|
|
not enable source transfer from a prose-only assumption.
|
|
|
|
**Done (2026-08-22):** live verification confirmed the private Nexus pod
|
|
cannot reach projected workstation checkout paths and that queue fairness is
|
|
therefore advancing through `no-checkout` outcomes. The Custodian fixed the
|
|
non-negotiable boundary—revision-pinned input, no workstation mount, bounded
|
|
credentials/egress/time/size, provenance, cleanup, and rollback—and routed
|
|
owner participation to SBOM Nexus (`95c1b226`), Repo Manager (`075e21de`),
|
|
Activity Core (`7233d2d1`), and the package owner (`e0af24b1`). Selection of
|
|
the concrete transfer mechanism is recorded in
|
|
`docs/sbom-controlled-scan-input-contract-v1.md`: a public Coulomb Forgejo
|
|
archive addressed by a full commit SHA, fetched and safely scanned by Nexus
|
|
from a bounded ephemeral volume. A live full-SHA archive fetch succeeded; v1
|
|
therefore needs no source credential and explicitly forbids reuse of the
|
|
Forgejo administrator PAT.
|
|
|
|
## Implement the Nexus-owned authoritative scan path
|
|
|
|
```task
|
|
id: CUST-WP-0064-T02
|
|
status: progress
|
|
priority: high
|
|
state_hub_task_id: "2029e525-0573-5fea-881c-d3a418b91c9d"
|
|
```
|
|
|
|
Depends on T01. Open and execute the SBOM Nexus/package child work needed to
|
|
consume the selected input, scan at a pinned revision, persist provenance, and
|
|
remove temporary source material. Preserve Nexus as the only snapshot writer
|
|
and enforce `CUST-IN-0013` operation idempotency on the mutation boundary.
|
|
|
|
**Started (2026-08-22):** the selected v1 contract fixes the application and
|
|
package changes, additive skip reasons, safety limits, durable replay rule,
|
|
and rollback sequence. Implementation handoffs now carry one shared contract
|
|
instead of separate mechanism proposals.
|
|
|
|
**Implementation checkpoint (2026-08-23):** three indexed child workplans are
|
|
now committed and pushed. `SBOM-WP-0003` (`dc07cc14`) implements migration
|
|
`0002`, durable operation receipts/replay, controlled full-SHA fetch and safe
|
|
extraction, provenance, source projection, and additive outcomes at application
|
|
revision `879012c` (25 tests passed, one conditional PostgreSQL skip; Ruff
|
|
clean; real archive scan returned 33 entries and zero errors).
|
|
`RAPP-SBOM-NEXUS-WP-0002` (`63ba3813`) stages the feature dark with a 768 MiB
|
|
ephemeral volume and Forgejo-only egress at package revision `7d8f76e` (6 tests
|
|
passed; server-side cluster admission dry-run passed). `ACTIVITY-WP-0034`
|
|
(`409c06c0`) freezes and submits the exact source reference across retries and
|
|
accepts the new terminal outcomes at revision `e690170` (434 tests passed, one
|
|
conditional integration skip; 28 focused tests passed). No production digest,
|
|
migration, feature flag, or schedule was changed. Remaining T02 work is the
|
|
reviewed image build/pin, migration `0002`, dark verification, and attended
|
|
one-repository canary. Repo Manager subsequently reported its direct producer
|
|
interface ready at revision `e6cc18b`: `rmgr sbom source-ref` resolves and
|
|
projects the full-SHA reference, verifies Nexus returns it unchanged, and
|
|
projects no workstation path. T03 therefore waits only on the Nexus/package
|
|
dark canary rather than new Repo Manager implementation.
|
|
|
|
## Retarget bounded catch-up without widening it
|
|
|
|
```task
|
|
id: CUST-WP-0064-T03
|
|
status: wait
|
|
priority: high
|
|
state_hub_task_id: "6c645778-be59-57b1-bf44-d974a3a1e49f"
|
|
```
|
|
|
|
Depends on T02 and `RMGR-WP-0011`. Supply the controlled input reference for
|
|
the already-fixed oldest-N target set. Activity Core must still process no more
|
|
than `catch_up_limit`, reuse the same targets and operation ids across retries,
|
|
and record terminal unsupported/failed inputs without advancing into a second
|
|
batch.
|
|
|
|
## Prove real daily freshness improvement
|
|
|
|
```task
|
|
id: CUST-WP-0064-T04
|
|
status: wait
|
|
priority: medium
|
|
state_hub_task_id: "664d90b0-1169-58fa-9a77-df53e739f957"
|
|
```
|
|
|
|
Run an attended bounded proof, then observe a normal scheduled fire. Require at
|
|
least one `ingested` outcome with repository slug, immutable revision, snapshot
|
|
id, and licence summary; zero spawned tasks; cleanup of transient source; and
|
|
truthful `last_success_at` / State Hub compatibility projection. Record the
|
|
remaining `never_count` and operator disable/rollback controls.
|
|
|
|
## Acceptance
|
|
|
|
- [ ] Production scans consume a controlled, revision-pinned source input
|
|
- [ ] No workstation filesystem is mounted or implicitly trusted
|
|
- [ ] Nexus remains the only authoritative snapshot writer
|
|
- [ ] One fire remains bounded to its original N targets across retries
|
|
- [ ] At least one normal scheduled fire produces real ingested snapshots
|
|
- [ ] Source cleanup, provenance, failure evidence, and rollback are verified
|