Files
truf-server/openspec/changes/run-bounded-rank1-breadth-experiment/proposal.md
T
2026-09-30 20:30:56 +03:00

2.4 KiB

Why

The completed portion of the Docker depth pilot found every currently alive credential in the newest selected image and no additional alive credential in older image ranks. A larger but still bounded rank-1 cohort is needed to test whether spending the same capacity on repository breadth produces better credential and currently-alive yield than blanket image depth.

What Changes

  • Add a separate rank-1-only Docker breadth experiment over exactly 2,000 previously unscanned physical repository anchors from the existing complete frozen discovery pass, excluding the current depth-pilot cohort.
  • Balance the cohort without using prior yield: each of the 52 keywords with an eligible remaining pool receives 38 repositories and 24 deterministically selected keywords receive one additional repository; the 9 exhausted keywords retain explicit zero coverage.
  • Deduplicate physical repositories across keywords while preserving all fresh keyword provenance, and scan at most one newest eligible immutable image per selected repository.
  • Keep the new experiment fail-closed until the current depth experiment is terminal and its cold rows have passed reviewed release; never run two Docker experiment authorities concurrently.
  • Persist a reviewable immutable cohort plan before activation and retain the existing lease, reservation, fencing, finite-retry, capacity, and reversible hold guarantees.
  • Report globally deduplicated credentials, currently alive credentials, repository/image coverage, and both yield measures per scanner-hour, with per-keyword attribution and no secret or target material.

Capabilities

New Capabilities

  • docker-rank1-breadth-experiment: A balanced, deterministic, physically deduplicated 2,000-repository rank-1 experiment with reviewed authority handoff, bounded execution, and secret-safe yield reporting.

Modified Capabilities

Impact

  • Docker experiment validation, cohort planning, authority handoff, resolver admission, rank-1 target scheduling, and aggregate reporting.
  • Managed PostgreSQL experiment state and audit evidence, with migrations only where the existing depth-experiment schema cannot represent the new plan.
  • Docker experiment configuration and focused unit/PostgreSQL integration coverage.
  • Runtime operations require canonical stop, reviewed release of the completed depth experiment, reviewed activation of this change, and canonical restart.