51 lines
2.4 KiB
Markdown
51 lines
2.4 KiB
Markdown
## Why
|
|
|
|
The completed portion of the Docker depth pilot found every currently alive
|
|
credential in the newest selected image and no additional alive credential in
|
|
older image ranks. A larger but still bounded rank-1 cohort is needed to test
|
|
whether spending the same capacity on repository breadth produces better
|
|
credential and currently-alive yield than blanket image depth.
|
|
|
|
## What Changes
|
|
|
|
- Add a separate rank-1-only Docker breadth experiment over exactly 2,000
|
|
previously unscanned physical repository anchors from the existing complete
|
|
frozen discovery pass, excluding the current depth-pilot cohort.
|
|
- Balance the cohort without using prior yield: each of the 52 keywords with an
|
|
eligible remaining pool receives 38 repositories and 24 deterministically
|
|
selected keywords receive one additional repository; the 9 exhausted
|
|
keywords retain explicit zero coverage.
|
|
- Deduplicate physical repositories across keywords while preserving all fresh
|
|
keyword provenance, and scan at most one newest eligible immutable image per
|
|
selected repository.
|
|
- Keep the new experiment fail-closed until the current depth experiment is
|
|
terminal and its cold rows have passed reviewed release; never run two Docker
|
|
experiment authorities concurrently.
|
|
- Persist a reviewable immutable cohort plan before activation and retain the
|
|
existing lease, reservation, fencing, finite-retry, capacity, and reversible
|
|
hold guarantees.
|
|
- Report globally deduplicated credentials, currently alive credentials,
|
|
repository/image coverage, and both yield measures per scanner-hour, with
|
|
per-keyword attribution and no secret or target material.
|
|
|
|
## Capabilities
|
|
|
|
### New Capabilities
|
|
|
|
- `docker-rank1-breadth-experiment`: A balanced, deterministic, physically
|
|
deduplicated 2,000-repository rank-1 experiment with reviewed authority
|
|
handoff, bounded execution, and secret-safe yield reporting.
|
|
|
|
### Modified Capabilities
|
|
|
|
## Impact
|
|
|
|
- Docker experiment validation, cohort planning, authority handoff, resolver
|
|
admission, rank-1 target scheduling, and aggregate reporting.
|
|
- Managed PostgreSQL experiment state and audit evidence, with migrations only
|
|
where the existing depth-experiment schema cannot represent the new plan.
|
|
- Docker experiment configuration and focused unit/PostgreSQL integration
|
|
coverage.
|
|
- Runtime operations require canonical stop, reviewed release of the completed
|
|
depth experiment, reviewed activation of this change, and canonical restart.
|