Files
2026-09-30 20:30:56 +03:00

2.3 KiB

Why

Large Docker images currently monopolize both Docker scan workers until the 600-second deadline and can retry indefinitely because timeout completion resets the target attempt counter. Over the measured 48-hour window, hard timeouts consumed about 32.7 worker-hours while repeated partial scans produced no usable LLM access, so full-image retries are reducing useful throughput without providing proportional coverage.

What Changes

  • Enforce the existing bounded target-attempt policy for Docker timeouts while preserving findings emitted before termination.
  • Resolve immutable image manifests into image configuration and ordered content-addressed layers with bounded size metadata.
  • Scan image configuration and selected layer content under an explicit per-image byte budget instead of treating every image as an indivisible download.
  • Deduplicate successful layer scans globally by immutable layer digest so shared base layers are not downloaded and scanned repeatedly.
  • Prioritize upper application layers and small layers; record oversized or out-of-budget layers as explicit uncovered scope rather than silently claiming complete image coverage.
  • Preserve the existing full-image path behind a rollout gate for controlled comparison and rollback.
  • Repair currently deferred Docker targets whose timeout attempts were incorrectly reset.

Capabilities

New Capabilities

  • docker-layer-content-scanning: Bounded, content-addressed Docker config and layer scanning with global deduplication, explicit coverage, safe retry limits, and controlled rollout against the existing full-image scanner.

Modified Capabilities

None.

Impact

  • Affects Docker Registry manifest/blob access, immutable Docker target planning, scan queue state, result metadata, and Docker source configuration.
  • Adds durable PostgreSQL state for layer identities, leases, coverage, attempts, and image-to-layer plans.
  • Reuses the existing authenticated Docker account pool, scan-slot limiter, Windows Job containment, bundle ingestion, findings projection, and keycheck pipeline.
  • Requires an offline additive runtime-safety migration before enabling production layer scanning.
  • Does not change Git, Hugging Face, keycheck classification, global guaranteed scan-slot capacity, or secret persistence boundaries.