fix(k8scontainer): use audit timeline creation time inventory instead of querying builder state - #1086
fix(k8scontainer): use audit timeline creation time inventory instead of querying builder state#1086kyasbal wants to merge 3 commits into
Conversation
…ing builder state TAG=agy
There was a problem hiding this comment.
Code Review
This pull request introduces a new task framework to discover and aggregate timeline paths written by Kubernetes audit logs, replacing the previous reliance on checking the state of the timeline accumulator directly. Specifically, it adds TimelinePathInventoryTask and TimelinePathDiscoveryTask under pkg/task/inspection/common/k8saudit, registers them, and refactors containerLogPodPhaseTimelineMapper to depend on the new inventory task. Unused methods such as HasRevision and HasEvent have been removed from TimelineAccumulator and TimelineBuilder. Additionally, tests have been updated to align with these changes, including mocking the new inventory task results and asserting correct timestamps. No review comments were provided, so there is no further feedback to address.
…eationTimeInventoryTask TAG=agy
…ated task TAG=agy
Background & Problem
containerLogPodPhaseTimelineMappersynthesizes fallback Pod, Binding, and PodPhase revisions from container log labels when a Pod's creation revision is not already recorded by audit logs. Previously, this mapper had three issues:builder.TimelineAccumulator.HasRevision(...). However,TimelineBuilder.HasRevision()only inspected in-memory slice length (len(b.revisions) > 0). WheneverTimelineAccumulatorflushed pending items to disk (FlushPendingItems),b.revisionswas cleared tonil, causingHasRevision()to returnfalseeven for timelines already populated byk8saudit. Furthermore, parser/mapper tasks should not read back mutated state fromTimelineBuilderorTimelineAccumulator.state != nil),containerLogPodPhaseTimelineMapperstill hardcodedChangedTime: time.Unix(0, 0)instead of usingl.Timestamp. This caused subsequent revisions to be placed at1970-01-01T00:00:00Zand appear before earlier audit log revisions.time.Unix(0, 0)revision from container logs will corrupt an existing timeline is whether the target timeline path already has resolvedcreationTimes (frommetadata.creationTimestamporVerbCreateaudit logs). Moreover, a single timeline path can observe multiplecreationTimes when a resource with the same name is deleted and recreated during the inspection window.Solution Approach
HasRevisionandHasEventfromTimelineBuilderandTimelineAccumulator:HasRevision()andHasEvent()fromTimelineBuilderandTimelineAccumulator, along with the test-onlyAddTestRevision()helper, enforcing a write-only accumulator contract for timeline mappers.TimelineCreationTimeInventoryTaskwith Dedicated Resource and PodPhase Discovery Tasks:ResourceTimelineCreationTimeDiscoveryTaskandPodPhaseTimelineCreationTimeDiscoveryTaskinpkg/task/inspection/common/k8sauditto collect observed creation timestamps (map[*khifilev6.TimelinePath][]time.Time, deduplicated and sorted chronologically) for resource/subresource timelines and PodPhase timelines discovered from non-dry-run audit logs that have a resolved creation time (metadata.creationTimestamporVerbCreatelog timestamp).TagTimelineCreationTimeDiscoveryand are aggregated byTimelineCreationTimeInventoryTask.containerLogPodPhaseTimelineMapperto depend onTimelineCreationTimeInventoryTaskIDinstead ofResourceRevisionLogToTimelineMapperTaskID,PodPhaseLogToTimelineMapperTaskID, andTimelineAccumulator.HasRevision.l.Timestampfor Subsequent Container Log Revisions:containerLogPodPhaseTimelineMapperto usetime.Unix(0, 0)only for the initial synthesized revision (state == nil) andl.Timestampfor subsequent revisions (state != nil).Task Graph Changes
flowchart LR manifest_gen["k8saudit: ManifestGeneratorTask"] extractor["k8saudit: K8sAuditLogExtractor"] res_discovery["k8saudit: ResourceTimelineCreationTimeDiscoveryTask"] pod_phase_discovery["k8saudit: PodPhaseTimelineCreationTimeDiscoveryTask"] inventory["k8saudit: TimelineCreationTimeInventoryTask"] container_mapper["k8scontainer: PodPhaseTimelineMapperTask"] manifest_gen --> res_discovery extractor --> res_discovery manifest_gen --> pod_phase_discovery extractor --> pod_phase_discovery res_discovery -.->|"TagTimelineCreationTimeDiscovery"| inventory pod_phase_discovery -.->|"TagTimelineCreationTimeDiscovery"| inventory inventory --> container_mapperRemaining Issues & Future Work
None.