Initial server source import

This commit is contained in:
sashatrask
2026-09-30 20:30:56 +03:00
commit 170dd941b9
498 changed files with 261563 additions and 0 deletions
@@ -0,0 +1,68 @@
## ADDED Requirements
### Requirement: Managed repository search is authenticated
The system SHALL authenticate every standard and recent DockerHub repository-search request through the configured DockerHub account pool using a Hub bearer token.
#### Scenario: Configured account performs search
- **WHEN** a managed DockerHub source cycle searches for repositories with an available account
- **THEN** the system sends the search request with that account's bearer authorization and records success under the `hub_search` endpoint identity
#### Scenario: Explicit pool has no usable account
- **WHEN** an explicit DockerHub account pool is configured but no account can authenticate or leave cooldown
- **THEN** the system fails the repository search without making an anonymous fallback request
#### Scenario: Search authorization is rejected
- **WHEN** a search request receives an account-specific 401, 403, or 429 response
- **THEN** the system refreshes a rejected bearer once where applicable and rotates to another usable account within the configured pool
### Requirement: Authenticated pagination is bounded
The system SHALL support up to 30 DockerHub search pages per query and SHALL cap larger requested page counts at 30.
#### Scenario: Thirty-page authenticated search
- **WHEN** a query requests 30 pages and the first page reports at least 30 pages of results
- **THEN** the system requests the complete page range from 1 through 30
#### Scenario: Request exceeds safety cap
- **WHEN** a query requests more than 30 pages
- **THEN** the system limits the search to pages 1 through 30 and records that the requested range was capped
#### Scenario: Reported result set is shorter
- **WHEN** page one reports fewer results than the requested page range would contain
- **THEN** the system requests only the pages required by that reported count
### Requirement: Page acquisition is bounded and complete
The system SHALL give each expected search page at most two transient transport/server attempts and SHALL not return partial repository results when any expected page remains unavailable.
#### Scenario: Transient failure recovers
- **WHEN** an expected page receives a retryable transport error or transient HTTP status on its first attempt and succeeds on its second attempt
- **THEN** the system includes that page and completes discovery without another transient attempt
#### Scenario: Expected page remains unavailable
- **WHEN** an expected page still fails after bounded retry and account handling
- **THEN** the system raises a DockerHub discovery transport failure before tag resolution or repository enqueue
#### Scenario: Every expected page succeeds
- **WHEN** all expected pages return valid payloads
- **THEN** the system combines their repositories in page order and proceeds with existing deduplication and resolution behavior
### Requirement: Failed pagination preserves query rotation
The system SHALL record incomplete DockerHub pagination as a failed source cycle and SHALL keep the current query cursor unchanged.
#### Scenario: Source cycle receives pagination failure
- **WHEN** repository discovery raises a DockerHub discovery transport failure
- **THEN** the source cycle finishes with failed status, enqueues no partial search result, and selects the same query for the next cycle
#### Scenario: Complete source cycle succeeds
- **WHEN** repository discovery and the remaining source cycle complete normally
- **THEN** the existing query-advance policy remains unchanged
### Requirement: Search authentication is secret-safe and isolated
The system MUST NOT expose account credentials or bearer tokens through search logs, errors, or auth events, and SHALL preserve existing tag, Registry, immutable-digest, and scan-retry behavior.
#### Scenario: Search request fails
- **WHEN** an authenticated search request fails or exhausts the account pool
- **THEN** emitted diagnostics identify only the safe endpoint/status category without including usernames, credentials, bearer values, or request authorization headers
#### Scenario: Repository search implementation changes
- **WHEN** authenticated search pagination is deployed
- **THEN** existing DockerHub tag resolution, Registry authentication, target deduplication, and scan retry contracts remain unchanged