Files
truf-server/openspec/changes/run-bounded-docker-depth-experiment/proposal.md
T
2026-09-30 20:30:56 +03:00

2.3 KiB

Why

DockerHub discovery admitted a large deduplicated repository backlog, but FIFO resolution and the hidden three-image selector cap cannot produce a fair, bounded comparison across all configured keywords. A controlled 24-48 hour experiment is needed to measure keyword yield and the marginal value of image versions beyond the current first three without allowing the backlog to monopolize runtime capacity.

What Changes

  • Add durable many-to-many DockerHub keyword-to-repository provenance so deduplicated targets retain every discovery attribution.
  • Add a reversible experiment hold and a round-robin cohort planner that takes up to ten genuinely fresh repositories per configured keyword after one complete pinned deep pass, preserving honest shortfalls without substituting historical targets.
  • Scan one current image from each cohort repository and up to ten distinct image graphs from one version-rich deep probe per keyword.
  • Enforce a global experiment ceiling of 1,200 unique immutable images and keep non-cohort/new repositories cold until reviewed reactivation.
  • Replace the hidden three-image clamp with explicit fail-closed configuration validation and deterministic selection beyond the third image.
  • Persist image rank, selection reason, manifest layer graph, layer digest, and base/top layer positions for per-keyword experiment reporting.
  • Report first-three versus later-version yield using deduplicated findings, credential identities, verification outcomes, scan time, and coverage.

Capabilities

New Capabilities

  • docker-depth-experiment: Durable provenance, bounded fair cohort scheduling, configurable image depth, reversible holds, layer attribution, and experiment reporting.

Modified Capabilities

Impact

  • PostgreSQL schema and managed migrations for Docker discovery provenance, experiment cohorts, image selection metadata, and durable reporting state.
  • DockerHub page admission, repository resolver scheduling, immutable target creation, and finding attribution in app/scanner_db.py, app/scanner.py, and app/console_runner.py.
  • DockerHub configuration and validation in app/config.yaml and runner argument construction.
  • Focused unit/PostgreSQL integration tests plus canonical offline migration and supervised runtime rollout.