2.4 KiB
2.4 KiB
Why
The completed portion of the Docker depth pilot found every currently alive credential in the newest selected image and no additional alive credential in older image ranks. A larger but still bounded rank-1 cohort is needed to test whether spending the same capacity on repository breadth produces better credential and currently-alive yield than blanket image depth.
What Changes
- Add a separate rank-1-only Docker breadth experiment over exactly 2,000 previously unscanned physical repository anchors from the existing complete frozen discovery pass, excluding the current depth-pilot cohort.
- Balance the cohort without using prior yield: each of the 52 keywords with an eligible remaining pool receives 38 repositories and 24 deterministically selected keywords receive one additional repository; the 9 exhausted keywords retain explicit zero coverage.
- Deduplicate physical repositories across keywords while preserving all fresh keyword provenance, and scan at most one newest eligible immutable image per selected repository.
- Keep the new experiment fail-closed until the current depth experiment is terminal and its cold rows have passed reviewed release; never run two Docker experiment authorities concurrently.
- Persist a reviewable immutable cohort plan before activation and retain the existing lease, reservation, fencing, finite-retry, capacity, and reversible hold guarantees.
- Report globally deduplicated credentials, currently alive credentials, repository/image coverage, and both yield measures per scanner-hour, with per-keyword attribution and no secret or target material.
Capabilities
New Capabilities
docker-rank1-breadth-experiment: A balanced, deterministic, physically deduplicated 2,000-repository rank-1 experiment with reviewed authority handoff, bounded execution, and secret-safe yield reporting.
Modified Capabilities
Impact
- Docker experiment validation, cohort planning, authority handoff, resolver admission, rank-1 target scheduling, and aggregate reporting.
- Managed PostgreSQL experiment state and audit evidence, with migrations only where the existing depth-experiment schema cannot represent the new plan.
- Docker experiment configuration and focused unit/PostgreSQL integration coverage.
- Runtime operations require canonical stop, reviewed release of the completed depth experiment, reviewed activation of this change, and canonical restart.