32 lines
2.3 KiB
Markdown
32 lines
2.3 KiB
Markdown
## Why
|
|
|
|
Large Docker images currently monopolize both Docker scan workers until the 600-second deadline and can retry indefinitely because timeout completion resets the target attempt counter. Over the measured 48-hour window, hard timeouts consumed about 32.7 worker-hours while repeated partial scans produced no usable LLM access, so full-image retries are reducing useful throughput without providing proportional coverage.
|
|
|
|
## What Changes
|
|
|
|
- Enforce the existing bounded target-attempt policy for Docker timeouts while preserving findings emitted before termination.
|
|
- Resolve immutable image manifests into image configuration and ordered content-addressed layers with bounded size metadata.
|
|
- Scan image configuration and selected layer content under an explicit per-image byte budget instead of treating every image as an indivisible download.
|
|
- Deduplicate successful layer scans globally by immutable layer digest so shared base layers are not downloaded and scanned repeatedly.
|
|
- Prioritize upper application layers and small layers; record oversized or out-of-budget layers as explicit uncovered scope rather than silently claiming complete image coverage.
|
|
- Preserve the existing full-image path behind a rollout gate for controlled comparison and rollback.
|
|
- Repair currently deferred Docker targets whose timeout attempts were incorrectly reset.
|
|
|
|
## Capabilities
|
|
|
|
### New Capabilities
|
|
|
|
- `docker-layer-content-scanning`: Bounded, content-addressed Docker config and layer scanning with global deduplication, explicit coverage, safe retry limits, and controlled rollout against the existing full-image scanner.
|
|
|
|
### Modified Capabilities
|
|
|
|
None.
|
|
|
|
## Impact
|
|
|
|
- Affects Docker Registry manifest/blob access, immutable Docker target planning, scan queue state, result metadata, and Docker source configuration.
|
|
- Adds durable PostgreSQL state for layer identities, leases, coverage, attempts, and image-to-layer plans.
|
|
- Reuses the existing authenticated Docker account pool, scan-slot limiter, Windows Job containment, bundle ingestion, findings projection, and keycheck pipeline.
|
|
- Requires an offline additive runtime-safety migration before enabling production layer scanning.
|
|
- Does not change Git, Hugging Face, keycheck classification, global guaranteed scan-slot capacity, or secret persistence boundaries.
|