[AgentIT] Scan container: source-repo patch for pulse-agent - #2
Conversation
b00286a to
e9c2969
Compare
Requesting changes — clear-evidence overclaimThis PR pins only
Tip fix in AgentIT: path-bound Please do not merge as-is. Narrow |
|
Follow-up: AgentIT tip PR is alimobrem/AgentIT#201 (path-bound |
|
AgentIT tip landed: alimobrem/AgentIT#201 (merged). After deploy, Scan will refuse this overclaim shape pre-open. Please close or rewrite this PR to only claim findings the staged pin clears. |
e9c2969 to
dcb71fb
Compare
71e1ae3 to
7bb6bd7
Compare
7bb6bd7 to
8c86184
Compare
AgentIT Scan: container for pulse-agent
Targeted findings
container— base image is not ubi (red hat universal base image) in dockerfile.fastcontainer— no healthcheck defined in dockerfilecontainer— no healthcheck defined in dockerfile.depscontainer— no healthcheck defined in dockerfile.fastcontainer— using :latest tag in base image in dockerfilecontainer— using :latest tag in base image in dockerfile.depscontainer— using :latest tag in base image in dockerfile.fastExpected effect
Clears
containerby pinning the app Dockerfile/Containerfile base image (no :latest) (delivery: source, evidence:dockerfile_pin). App-repo source patch.Clears
containerby pinning the app Dockerfile/Containerfile base image (no :latest) (delivery: source, evidence:dockerfile_pin). App-repo source patch.Clears
containerby pinning the app Dockerfile/Containerfile base image (no :latest) (delivery: source, evidence:dockerfile_pin). App-repo source patch.Clears
containerby pinning the app Dockerfile/Containerfile base image (no :latest) (delivery: source, evidence:dockerfile_pin). App-repo source patch.Clears
containerby pinning the app Dockerfile/Containerfile base image (no :latest) (delivery: source, evidence:dockerfile_pin). App-repo source patch.Clears
containerby pinning the app Dockerfile/Containerfile base image (no :latest) (delivery: source, evidence:dockerfile_pin). App-repo source patch.Clears
containerby pinning the app Dockerfile/Containerfile base image (no :latest) (delivery: source, evidence:dockerfile_pin). App-repo source patch.Score lift expected in: security, observability, cicd, infrastructure, compliance, data_governance, ha_dr.
Finding-clear proof (post-merge)
After merge + Argo sync, re-Assess this app. AgentIT correlates
target_findingson the delivery row — skills stay unapproved until those keys are gone (correlate_delivery_finding→resolved). If they remain, Ledger shows still-present and skills are rejected.Validation
SSA dry-run (concrete YAML), clear-evidence simulation (contract evidence_kind), property checks for targeted findings, fleet HPA scaleTargetRef gate, and self-managed chart gate (#119) passed for this cluster.
Clear-evidence:
container: pinned base image in Dockerfile (no :latest);container: pinned base image in Dockerfile (no :latest);container: pinned base image in Dockerfile (no :latest);container: pinned base image in Dockerfile (no :latest);container: pinned base image in Dockerfile (no :latest);container: pinned base image in Dockerfile (no :latest);container: pinned base image in Dockerfile (no :latest)Dry-run notes (non-blocking — AgentIT SA Forbidden or optional CRD missing; not treated as invalid manifests):
Files
Dockerfile— Generated by skill containerfile — pin-only FROM on existing Dockerfile (no rewrite)Deploy path
Argo deploys after merge; AgentIT does not auto-merge. Humans merge on GitHub — that is the only deploy path (no Direct Apply).