the-custodian/workplans/CUST-WP-0064-sbom-controlled-scan-inputs.md
codex c1756de260
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
workplans: close sbom extraction coordination
2026-08-22 22:56:52 +02:00

3.5 KiB

id type title domain repo status owner topic_slug planning_priority planning_order created updated origin origin_ref related
CUST-WP-0064 workplan Controlled scan inputs for authoritative daily SBOM catch-up infotech the-custodian ready codex custodian high 64 2026-08-22 2026-08-22 residual CUST-WP-0062
SBOM-WP-0002
ACTIVITY-WP-0030
ACTIVITY-WP-0033
RMGR-WP-0011

Controlled scan inputs for authoritative daily SBOM catch-up

Goal

Give the private SBOM Nexus production plane a controlled, revision-pinned source input so bounded daily catch-up can produce authoritative ingested snapshots. Current scheduling, ranking, fairness, and zero-task behavior are proven, but production attempts are no-checkout because workstation paths are not reachable inside the cluster.

This is a coordination workplan. SBOM Nexus owns scan semantics and durable history; Repo Manager owns repository identity, active status, and source-path projection; Activity Core owns recurrence and the at-most-N workflow bound; the deployment package owns the runtime/network boundary.

Select the source-transfer and trust-boundary contract

id: CUST-WP-0064-T01
status: todo
priority: high

Choose one controlled input shape—such as a revision-pinned Forgejo clone in a short-lived scanner job or a content-addressed source artifact—without mounting operator workstations into the cluster. Define repository/revision identity, authentication custody, size/time limits, egress, provenance, unsupported repo behavior, cleanup, and the boundary between preview and authoritative ingest.

Done when the four owning repos have one reviewable contract and rollback; do not enable source transfer from a prose-only assumption.

Implement the Nexus-owned authoritative scan path

id: CUST-WP-0064-T02
status: wait
priority: high

Depends on T01. Open and execute the SBOM Nexus/package child work needed to consume the selected input, scan at a pinned revision, persist provenance, and remove temporary source material. Preserve Nexus as the only snapshot writer and enforce CUST-IN-0013 operation idempotency on the mutation boundary.

Retarget bounded catch-up without widening it

id: CUST-WP-0064-T03
status: wait
priority: high

Depends on T02 and RMGR-WP-0011. Supply the controlled input reference for the already-fixed oldest-N target set. Activity Core must still process no more than catch_up_limit, reuse the same targets and operation ids across retries, and record terminal unsupported/failed inputs without advancing into a second batch.

Prove real daily freshness improvement

id: CUST-WP-0064-T04
status: wait
priority: medium

Run an attended bounded proof, then observe a normal scheduled fire. Require at least one ingested outcome with repository slug, immutable revision, snapshot id, and licence summary; zero spawned tasks; cleanup of transient source; and truthful last_success_at / State Hub compatibility projection. Record the remaining never_count and operator disable/rollback controls.

Acceptance

  • Production scans consume a controlled, revision-pinned source input
  • No workstation filesystem is mounted or implicitly trusted
  • Nexus remains the only authoritative snapshot writer
  • One fire remains bounded to its original N targets across retries
  • At least one normal scheduled fire produces real ingested snapshots
  • Source cleanup, provenance, failure evidence, and rollback are verified