Initial server source import
This commit is contained in:
@@ -0,0 +1,31 @@
|
||||
## Why
|
||||
|
||||
Large Docker images currently monopolize both Docker scan workers until the 600-second deadline and can retry indefinitely because timeout completion resets the target attempt counter. Over the measured 48-hour window, hard timeouts consumed about 32.7 worker-hours while repeated partial scans produced no usable LLM access, so full-image retries are reducing useful throughput without providing proportional coverage.
|
||||
|
||||
## What Changes
|
||||
|
||||
- Enforce the existing bounded target-attempt policy for Docker timeouts while preserving findings emitted before termination.
|
||||
- Resolve immutable image manifests into image configuration and ordered content-addressed layers with bounded size metadata.
|
||||
- Scan image configuration and selected layer content under an explicit per-image byte budget instead of treating every image as an indivisible download.
|
||||
- Deduplicate successful layer scans globally by immutable layer digest so shared base layers are not downloaded and scanned repeatedly.
|
||||
- Prioritize upper application layers and small layers; record oversized or out-of-budget layers as explicit uncovered scope rather than silently claiming complete image coverage.
|
||||
- Preserve the existing full-image path behind a rollout gate for controlled comparison and rollback.
|
||||
- Repair currently deferred Docker targets whose timeout attempts were incorrectly reset.
|
||||
|
||||
## Capabilities
|
||||
|
||||
### New Capabilities
|
||||
|
||||
- `docker-layer-content-scanning`: Bounded, content-addressed Docker config and layer scanning with global deduplication, explicit coverage, safe retry limits, and controlled rollout against the existing full-image scanner.
|
||||
|
||||
### Modified Capabilities
|
||||
|
||||
None.
|
||||
|
||||
## Impact
|
||||
|
||||
- Affects Docker Registry manifest/blob access, immutable Docker target planning, scan queue state, result metadata, and Docker source configuration.
|
||||
- Adds durable PostgreSQL state for layer identities, leases, coverage, attempts, and image-to-layer plans.
|
||||
- Reuses the existing authenticated Docker account pool, scan-slot limiter, Windows Job containment, bundle ingestion, findings projection, and keycheck pipeline.
|
||||
- Requires an offline additive runtime-safety migration before enabling production layer scanning.
|
||||
- Does not change Git, Hugging Face, keycheck classification, global guaranteed scan-slot capacity, or secret persistence boundaries.
|
||||
Reference in New Issue
Block a user