Skip to content

feat(supply-chain): backfill enrichment at start and add Helm extraEnv - #118

Merged
balcsida merged 2 commits into
mainfrom
feat/supply-chain-proxy-and-backfill
Sep 26, 2026
Merged

balcsida merged 2 commits into
mainfrom
feat/supply-chain-proxy-and-backfill

Conversation

@balcsida

Copy link
Copy Markdown
Owner

Follow-up to #117 so the fix is actually usable on a proxied cluster with existing inventories.

What

  • Enrichment backfill at start (license.Worker.Backfill, wired in startSupplyChain). A registry route configured after inventories exist was never consulted for them: enrichment queued only on publication, and a repeat collection of an unchanged export publishes nothing, so existing snapshots showed the producer's NOASSERTION forever. The worker now queues every stream's current snapshot before it starts processing. EnqueueEnrichment already skips coordinates with fresh evidence or an active job, so the pass is idempotent across restarts. New Store.LatestSnapshotIDs (one indexed query on supply_chain_streams).
  • Helm server.extraEnv: plain string map rendered into the server ConfigMap, for HTTPS_PROXY/NO_PROXY on clusters whose only egress is a proxy. Schema-validated (stringMap), documented in the chart README; render.sh asserts presence with optional values and absence with minimal values.
  • docs/operations.md, CHANGELOG.md updated (also adds the missing [#117] link).

User-visible behaviour

On start with routes configured, the log reports supply chain enrichment backfill queued jobs=N once; subsequent starts queue nothing unless evidence expired. No behaviour change without routes. Chart default extraEnv: {} renders nothing.

Security

extraEnv renders into a ConfigMap, so it is documented as non-secret only. No new outbound destinations: backfill uses the same route-bound fetcher.

Verification

make fmt lint staticcheck helm-lint helm-test
GOWORK=off go test -race -count=1 ./internal/supplychain/... ./internal/postgres/

balcsida and others added 2 commits September 24, 2026 07:59
A registry route configured after inventories exist was never consulted
for them: enrichment queued only on publication, and a repeat collection
of an unchanged export publishes nothing, so existing snapshots kept
showing the producer's NOASSERTION forever. The enrichment worker now
queues every stream's current snapshot before it starts processing;
EnqueueEnrichment already skips coordinates with fresh evidence or an
active job, so the pass is idempotent across restarts.

The chart gains `server.extraEnv`, a plain string map rendered into the
server ConfigMap, so a cluster whose only egress is an HTTP proxy can
set HTTPS_PROXY/NO_PROXY without patching the Deployment. The render
test covers presence with optional values and absence with minimal
values.

Co-Authored-By: Claude <noreply@anthropic.com>
@balcsida
balcsida merged commit af818e7 into main Sep 26, 2026
11 of 12 checks passed
@balcsida
balcsida deleted the feat/supply-chain-proxy-and-backfill branch September 26, 2026 20:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant