5.3 KiB
Pipeline Quarantine Audit
Initial snapshot and remediation: 2026-08-15
Current Impact
- PostgreSQL quarantine rows:
177 - Accounted capacity:
4354 items / 1,817,503,389 bytes - Configured admission limit:
10000 items / 1,073,741,824 bytes - New scan admission is closed because the byte limit is exceeded.
49,215admission intents have already ended withquarantine_admission_closed.
pipeline: ready means that PostgreSQL and workers are healthy. It does not mean that new scan admission is open.
Result Bundles
Two rows account for 4004 items / 1,212,153,856 bytes.
| Quarantine ID | Source | Original error | Physical size | Read-only validation now |
|---|---|---|---|---|
29 |
Hugging Face spaces |
Transient Windows Permission denied |
2,870 B |
Valid; 3 frames, no findings/errors/candidates |
91 |
Docker Hub query tokenizer |
Transient Windows Permission denied |
5,354 B |
Valid; 8 frames, 1 finding, 4 errors, no candidates |
The bundle contents are valid. Their large capacity cost comes from worst-case reservations transferred into quarantine, not their physical file sizes.
Current code now reports a temporarily unavailable private bundle as an availability error. Result ingester defers it instead of classifying it as invalid content.
Recommendation: recover both bundles through an audited offline path rather than discard them. ID 91 contains one finding and must not be deleted without an explicit decision.
Keycheck Quarantine
There are 175 pending keycheck quarantine rows.
| Class | Rows | Distinct credentials | Assessment |
|---|---|---|---|
| Repeated DeepSeek unconsumed rechecks | 104 |
1 |
Duplicate hourly retries; current state is now NO_CONTEXT |
| DeepSeek unconsumed findings | 15 |
6 |
Legitimate historical candidates filtered by routing |
| Azure Foundry unconsumed | 15 |
12 |
Historical provider-consumption issue |
| Hugging Face unconsumed | 7 |
5 |
Historical provider-consumption issue |
| Replicate unconsumed | 6 |
3 |
Historical provider-consumption issue |
| xAI unconsumed | 3 |
3 |
Historical provider-consumption issue |
| DeepSeek route mismatch | 24 |
14 |
Misrouted non-DeepSeek detectors; source findings remain in PostgreSQL |
| Azure route mismatch | 1 |
1 |
Historical Azure Foundry route mismatch; current state is UNKNOWN |
The active growth came from one DeepSeek credential whose current state was NETWORK. Hourly network retry created a fresh candidate, provider routing silently rejected it, and the candidate entered quarantine after three unconsumed attempts.
Preventive Changes
- Non-DeepSeek routing decisions now complete as
NO_CONTEXTinstead of leaving a leased candidate unconsumed. - DeepSeek has a canonical
deepseekNoContext.txtstatus projection. - Recheck generation now refuses to enqueue a credential while it has an unresolved
provider_candidate_unconsumedorcandidate_provider_route_mismatchquarantine row. - Temporarily unavailable result bundle files are deferred instead of quarantined as validation failures.
Verification:
- Targeted tests:
60 passed. - Manual
recheck deepseek network: code0, no candidates processed. - DeepSeek unconsumed quarantine remained exactly
119; no new row was created.
Approved Remediation
- Stop sources and acquire the offline migration guard.
- Recover bundle IDs
29and91through deterministic re-ingestion. - Discard the
104duplicate DeepSeek retry rows after exact manifest review. - Discard the
24confirmed DeepSeek route-mismatch rows after exact manifest review. - Requeue one current candidate per distinct credential from the remaining legitimate unconsumed groups; keep source attribution.
- Review the single Azure route mismatch separately.
- Resolve superseded duplicate candidate rows with an audited discard manifest.
- Verify physical artifacts, capacity accounting, projections and reopened scan admission before restarting sources.
All destructive decisions must use an exact private truf-pipeline-quarantine-review-v1 manifest containing quarantine ID, reason code, payload hash and action. The offline review command requires both --apply and --sources-stopped.
Applied Result
The user approved recovery plus selective cleanup.
- Manifest:
runtime/control/quarantine-remediation-20260815.json - Manifest SHA-256:
c3143e6b0e15e07b6afacffd50b449444b9932e75001f633ac82b5b79e21fe3f - Reviewed:
177 - Approved retry:
32 - Audited discard:
145 - Duplicate/conflicting reviews:
0 - Final quarantine capacity:
0 items / 0 bytes
Bundle outcomes:
| Quarantine ID | Final reservation | Final bundle | Target disposition | Preserved contents |
|---|---|---|---|---|
29 |
acknowledged |
acknowledged |
done |
Clean empty result |
91 |
acknowledged |
acknowledged |
deferred |
1 finding, 4 errors |
Keycheck outcomes from the retried unique credentials:
| Service | Final current statuses |
|---|---|
| Azure | 12 FOUNDRY_UNRESOLVED, 1 UNKNOWN |
| DeepSeek | 6 NO_CONTEXT |
| Hugging Face | 5 NO_CONTEXT |
| Replicate | 3 NO_CONTEXT |
| xAI | 3 NO_CONTEXT |
The malformed legacy provider candidates are now terminal current-state records instead of repeatedly deferred/quarantined candidates. Scan admission reopened and scanner workers returned to 3/3 active operation.