Files
truf-server/openspec/changes/run-bounded-rank1-breadth-experiment/proposal.md
T
2026-09-30 20:30:56 +03:00

51 lines
2.4 KiB
Markdown

## Why
The completed portion of the Docker depth pilot found every currently alive
credential in the newest selected image and no additional alive credential in
older image ranks. A larger but still bounded rank-1 cohort is needed to test
whether spending the same capacity on repository breadth produces better
credential and currently-alive yield than blanket image depth.
## What Changes
- Add a separate rank-1-only Docker breadth experiment over exactly 2,000
previously unscanned physical repository anchors from the existing complete
frozen discovery pass, excluding the current depth-pilot cohort.
- Balance the cohort without using prior yield: each of the 52 keywords with an
eligible remaining pool receives 38 repositories and 24 deterministically
selected keywords receive one additional repository; the 9 exhausted
keywords retain explicit zero coverage.
- Deduplicate physical repositories across keywords while preserving all fresh
keyword provenance, and scan at most one newest eligible immutable image per
selected repository.
- Keep the new experiment fail-closed until the current depth experiment is
terminal and its cold rows have passed reviewed release; never run two Docker
experiment authorities concurrently.
- Persist a reviewable immutable cohort plan before activation and retain the
existing lease, reservation, fencing, finite-retry, capacity, and reversible
hold guarantees.
- Report globally deduplicated credentials, currently alive credentials,
repository/image coverage, and both yield measures per scanner-hour, with
per-keyword attribution and no secret or target material.
## Capabilities
### New Capabilities
- `docker-rank1-breadth-experiment`: A balanced, deterministic, physically
deduplicated 2,000-repository rank-1 experiment with reviewed authority
handoff, bounded execution, and secret-safe yield reporting.
### Modified Capabilities
## Impact
- Docker experiment validation, cohort planning, authority handoff, resolver
admission, rank-1 target scheduling, and aggregate reporting.
- Managed PostgreSQL experiment state and audit evidence, with migrations only
where the existing depth-experiment schema cannot represent the new plan.
- Docker experiment configuration and focused unit/PostgreSQL integration
coverage.
- Runtime operations require canonical stop, reviewed release of the completed
depth experiment, reviewed activation of this change, and canonical restart.