Add e2e tier 18: SBOM-driven CVE sweep and zero-downtime bundle remediation - #141
Merged
Bruno Borges (brunoborges) merged 2 commits intoSep 30, 2026
Conversation
…iation Rehearses a Log4Shell-style CVE in a managed dependency bundle: identify affected prod workloads from running pods' SBOMs, publish a patched bundle, recompose the unchanged thin JARs, and roll out by digest with zero dropped requests. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
main added tier 18 (patched JDK rollout). Move the dependency CVE tier to 19, add it to the CI matrix and reset namespaces, and run its offline sweep tests in CI. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Bruno Borges (brunoborges)
deleted the
brunoborges-log4j-cve-sbom-hot-redeploy-test
branch
September 30, 2026 21:21
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR adds a test for the "Log4Shell day" scenario. An app runs on a managed dependency bundle, and a library in that bundle gets a critical CVE. The test answers three questions: how do we find which prod apps are affected, how do we release a fixed bundle, and how do we redeploy without downtime.
Brewlet does not record which bundle a
JavaApplicationor pod uses. So the new sweep,integration-tests/e2e/cve_sweep.py, starts from what is actually running. For each pod it follows: digest-pinned image ->brewlet inspectmanaged-dependency evidence -> the bundle's CycloneDX SBOM -> components and purls. It then checks each component against the advisory's version range. If it cannot trace an image to an SBOM, it fails closed instead of reporting that image as clean.New tier 19 (
tier19-cve-remediation.sh):log4j-core2.14.1. The fixture inintegration-tests/fixtures/log4j-cve-appuses a neutral package, not Apache code.prod/ordersandprod/billing. Checks that a fleet-wide sweep also seesstaging/orders.applicationJarDigeststay the same and only the classpath layer changes.maxUnavailable: 0) while a client polls the Service continuously. Asserts zero failed requests and that the JVMs now load 2.17.1."Hot redeploy" here means recompose plus a rolling update. Brewlet does not swap classpath layers inside a running JVM (SPECIFICATION section 11).
Other changes:
run.sh, thereset.shnamespace list, and the CI matrix ine2e.yml. The CI entry also runs the offline sweep tests. Tier 18 was already taken by the patched-JDK rollout from Add patched-JDK rollout e2e (tier 18) and fix two provisioner bugs #140.cve_sweep_test.py, using a fake CLI).integration-tests/AGENTS.md.docs/managed-dependency-bundles.md.Validation
integration-tests/e2e/run.sh --tier 19on Docker Desktop kind (3 nodes, arm64 worker, go1.27.1, JDK 25): 21 passed, 0 failed, 0 skipped. It passed both before and after merging main (it was tier 18 before the merge). In the first run the client made 114 requests during the rollout with 0 failures.PYTHONDONTWRITEBYTECODE=1 python3 -m unittest discover -s integration-tests/e2e -p 'cve_sweep_test.py' -v: 5 tests OK.bash -n run.sh reset.sh tier19-cve-remediation.sh: OK. shellcheck is not installed locally, so it was not run.Compatibility and operations
None. This PR adds a test tier, test tooling, a fixture, documentation, and a CI matrix entry. It does not change the product. Tier 19 skips when there is no cluster, Docker, Go, Python 3, JDK, or schedulable local containerd node.
Checklist