fix(onboarding): targets visibility + unified pipeline by default (#154)
CI / Check (push) Has been skipped
CI / Detect Changes (push) Successful in 3s
CI / Deploy Agent (push) Successful in 3m41s
CI / Deploy Dashboard (push) Successful in 2m46s
CI / Deploy Docs (push) Has been skipped
CI / Deploy MCP (push) Successful in 1m46s
CI / Check (push) Has been skipped
CI / Detect Changes (push) Successful in 3s
CI / Deploy Agent (push) Successful in 3m41s
CI / Deploy Dashboard (push) Successful in 2m46s
CI / Deploy Docs (push) Has been skipped
CI / Deploy MCP (push) Successful in 1m46s
This commit was merged in pull request #154.
This commit is contained in:
@@ -70,6 +70,26 @@ impl ComplianceAgent {
|
||||
}
|
||||
}
|
||||
|
||||
/// Run a scan for an onboarded target through the unified pipeline,
|
||||
/// unconditionally.
|
||||
///
|
||||
/// Unlike [`Self::run_scan`], this does *not* consult the
|
||||
/// `unified_pipeline` transition flag: the caller (the `/targets/{id}/scan`
|
||||
/// endpoint) operates on `onboarded_targets` by construction, so it must
|
||||
/// always dispatch to `run_target` regardless of how the legacy paths
|
||||
/// (scheduler, webhooks, `/repositories/{id}/scan`) are configured.
|
||||
pub async fn run_target_scan(
|
||||
&self,
|
||||
tenant_id: &str,
|
||||
target_id: &str,
|
||||
trigger: compliance_core::models::ScanTrigger,
|
||||
) -> Result<(), crate::error::AgentError> {
|
||||
let db = self.db_pool.for_tenant_id(tenant_id).await?;
|
||||
let orchestrator =
|
||||
PipelineOrchestrator::new(self.config.clone(), db, self.llm.clone(), self.http.clone());
|
||||
orchestrator.run_target(target_id, trigger).await
|
||||
}
|
||||
|
||||
/// Run a PR review: scan the diff and post review comments.
|
||||
pub async fn run_pr_review(
|
||||
&self,
|
||||
|
||||
@@ -375,8 +375,11 @@ pub async fn trigger_target_scan(
|
||||
let agent_clone = (*agent).clone();
|
||||
let tenant_id = tenant.0.tenant_id.clone();
|
||||
tokio::spawn(async move {
|
||||
// Always the unified target pipeline — this endpoint is about an
|
||||
// onboarded target by construction, independent of the global
|
||||
// `unified_pipeline` transition flag used by the legacy paths.
|
||||
if let Err(e) = agent_clone
|
||||
.run_scan(
|
||||
.run_target_scan(
|
||||
&tenant_id,
|
||||
&id,
|
||||
compliance_core::models::ScanTrigger::Manual,
|
||||
|
||||
@@ -47,9 +47,12 @@ pub fn load_config() -> Result<AgentConfig, AgentError> {
|
||||
.unwrap_or_else(|| "/tmp/compliance-scanner/repos".to_string()),
|
||||
artifact_store_base_path: env_var_opt("ARTIFACT_STORE_BASE_PATH")
|
||||
.unwrap_or_else(|| "/data/compliance-scanner/artifacts".to_string()),
|
||||
// Defaults ON: the unified onboarded-target pipeline is now the primary
|
||||
// path (no legacy `repositories` data in production). Set
|
||||
// `UNIFIED_PIPELINE=0` to fall back to the legacy repository pipeline.
|
||||
unified_pipeline: env_var_opt("UNIFIED_PIPELINE")
|
||||
.map(|v| v == "1" || v.eq_ignore_ascii_case("true"))
|
||||
.unwrap_or(false),
|
||||
.unwrap_or(true),
|
||||
ssh_key_path: env_var_opt("SSH_KEY_PATH")
|
||||
.unwrap_or_else(|| "/data/compliance-scanner/ssh/id_ed25519".to_string()),
|
||||
keycloak_url: env_var_opt("KEYCLOAK_URL"),
|
||||
|
||||
@@ -288,25 +288,25 @@ async fn scan_all_repos(agent: &ComplianceAgent, tenant_id: &str) {
|
||||
None => return,
|
||||
};
|
||||
|
||||
let cursor = match db.repositories().find(doc! {}).await {
|
||||
let cursor = match db.onboarded_targets().find(doc! {}).await {
|
||||
Ok(c) => c,
|
||||
Err(e) => {
|
||||
tracing::error!("Failed to list repos for tenant '{tenant_id}': {e}");
|
||||
tracing::error!("Failed to list targets for tenant '{tenant_id}': {e}");
|
||||
return;
|
||||
}
|
||||
};
|
||||
|
||||
let repos: Vec<_> = cursor.filter_map(|r| async { r.ok() }).collect().await;
|
||||
let targets: Vec<_> = cursor.filter_map(|r| async { r.ok() }).collect().await;
|
||||
|
||||
for repo in repos {
|
||||
let repo_id = repo.id.map(|id| id.to_hex()).unwrap_or_default();
|
||||
for target in targets {
|
||||
let target_id = target.id.map(|id| id.to_hex()).unwrap_or_default();
|
||||
if let Err(e) = agent
|
||||
.run_scan(tenant_id, &repo_id, ScanTrigger::Scheduled)
|
||||
.run_target_scan(tenant_id, &target_id, ScanTrigger::Scheduled)
|
||||
.await
|
||||
{
|
||||
tracing::error!(
|
||||
"Scheduled scan failed for {} (tenant '{tenant_id}'): {e}",
|
||||
repo.name
|
||||
target.name
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user