Files
git.stella-ops.org/docs/modules/scheduler
master b1e78fe412
Some checks failed
Docs CI / lint-and-preview (push) Has been cancelled
feat: Implement vulnerability token signing and verification utilities
- Added VulnTokenSigner for signing JWT tokens with specified algorithms and keys.
- Introduced VulnTokenUtilities for resolving tenant and subject claims, and sanitizing context dictionaries.
- Created VulnTokenVerificationUtilities for parsing tokens, verifying signatures, and deserializing payloads.
- Developed VulnWorkflowAntiForgeryTokenIssuer for issuing anti-forgery tokens with configurable options.
- Implemented VulnWorkflowAntiForgeryTokenVerifier for verifying anti-forgery tokens and validating payloads.
- Added AuthorityVulnerabilityExplorerOptions to manage configuration for vulnerability explorer features.
- Included tests for FilesystemPackRunDispatcher to ensure proper job handling under egress policy restrictions.
2025-11-03 10:04:10 +02:00
..

StellaOps Scheduler

Scheduler detects advisory/VEX deltas, computes impact windows, and orchestrates re-evaluations across Scanner and Policy Engine.

Responsibilities

  • Maintain impact cursors and queues for re-scan/re-evaluate jobs.
  • Expose APIs for policy-triggered rechecks and runtime hooks.
  • Emit DSSE-backed completion events for downstream consumers (UI, Notify).
  • Provide SLA-aware retry logic with deterministic evaluation windows.

Key components

  • StellaOps.Scheduler.WebService control plane.
  • StellaOps.Scheduler.Worker job executor.
  • Shared libraries under StellaOps.Scheduler.*.

Integrations & dependencies

  • MongoDB for impact models.
  • Redis/NATS for queueing.
  • Policy Engine, Scanner, Notify.

Operational notes

  • Monitoring assets in ./operations/worker-grafana-dashboard.json & worker-prometheus-rules.yaml.
  • Operational runbook ./operations/worker.md.
  • ./operations/worker.md
  • ./operations/worker-grafana-dashboard.json
  • ./operations/worker-prometheus-rules.yaml

Backlog references

  • SCHED-MODELS-20-001 (policy run DTOs) and related tasks in ../../TASKS.md.
  • Scheduler observability follow-ups in src/Scheduler/**/TASKS.md.

Epic alignment

  • Epic 2 Policy Engine & Editor: orchestrate incremental re-evaluation and simulation runs when raw facts or policies change.
  • Epic 6 Vulnerability Explorer: feed triage workflows with up-to-date job status, explain traces, and ledger hooks.
  • Epic 9 Orchestrator Dashboard: expose job telemetry, throttling, and replay controls through orchestration dashboards.