feat(supply-chain): backfill enrichment at start and add Helm extraEnv - #118
Merged
Merged
Conversation
A registry route configured after inventories exist was never consulted for them: enrichment queued only on publication, and a repeat collection of an unchanged export publishes nothing, so existing snapshots kept showing the producer's NOASSERTION forever. The enrichment worker now queues every stream's current snapshot before it starts processing; EnqueueEnrichment already skips coordinates with fresh evidence or an active job, so the pass is idempotent across restarts. The chart gains `server.extraEnv`, a plain string map rendered into the server ConfigMap, so a cluster whose only egress is an HTTP proxy can set HTTPS_PROXY/NO_PROXY without patching the Deployment. The render test covers presence with optional values and absence with minimal values. Co-Authored-By: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #117 so the fix is actually usable on a proxied cluster with existing inventories.
What
license.Worker.Backfill, wired instartSupplyChain). A registry route configured after inventories exist was never consulted for them: enrichment queued only on publication, and a repeat collection of an unchanged export publishes nothing, so existing snapshots showed the producer'sNOASSERTIONforever. The worker now queues every stream's current snapshot before it starts processing.EnqueueEnrichmentalready skips coordinates with fresh evidence or an active job, so the pass is idempotent across restarts. NewStore.LatestSnapshotIDs(one indexed query onsupply_chain_streams).server.extraEnv: plain string map rendered into the server ConfigMap, forHTTPS_PROXY/NO_PROXYon clusters whose only egress is a proxy. Schema-validated (stringMap), documented in the chart README;render.shasserts presence with optional values and absence with minimal values.docs/operations.md,CHANGELOG.mdupdated (also adds the missing[#117]link).User-visible behaviour
On start with routes configured, the log reports
supply chain enrichment backfill queued jobs=Nonce; subsequent starts queue nothing unless evidence expired. No behaviour change without routes. Chart defaultextraEnv: {}renders nothing.Security
extraEnvrenders into a ConfigMap, so it is documented as non-secret only. No new outbound destinations: backfill uses the same route-bound fetcher.Verification