Repository navigation
Deployment Container Security
Cryptographically pinned, non-root, multi-stage container images with automated vulnerability scanning and CVE patch workflows.
Spector cognitive memory runs in security-critical environments where data integrity, low latency, and zero supply chain compromises are mandatory. To protect against malicious upstream image modifications, supply chain drift, and runtime privilege escalations, Spector enforces a defense-in-depth container security posture across all build and runtime targets.
Standard Docker tags (such as :latest, :25-jre, or :22-alpine) are mutable pointers. Relying on floating tags creates two critical security hazards:
- Supply Chain Poisoning: If an upstream repository or registry credential is compromised, malicious code or backdoored layers can be injected into production builds without modifying the Dockerfile.
- Non-Reproducible Builds: Upstream maintainers regularly rebuild tags with updated OS packages. A build that succeeded yesterday may fail or introduce unforeseen regressions today due to untracked transitive package changes.
To guarantee bit-for-bit build reproducibility and eliminate supply chain poisoning, all stages in deploy/docker/Dockerfile are pinned to immutable upstream cryptographic SHA-256 manifest list digests.
| Stage | Image Tag & Platform | Pinned SHA-256 Digest | Purpose |
|---|---|---|---|
| Stage 1: Cortex Builder |
node:22.22.3-alpine (--platform=$BUILDPLATFORM) |
sha256:e58326d0d441090181ac150dc2078d3e2cf6a0d42e809aebba3ef5880935ffdd |
Compiles Angular 22 Cortex 3D neural dashboard |
| Stage 2: Synapse Builder |
maven:3.9-eclipse-temurin-25 (--platform=$BUILDPLATFORM) |
sha256:dd8e01b3be719853578c07b57ff8d9bbbbfe746f802226f05b19689420815221 |
Compiles Java 25 reactor modules & packages fat JAR |
| Stage 3: Gateway Builder |
maven:3.9-eclipse-temurin-25 (--platform=$BUILDPLATFORM) |
sha256:dd8e01b3be719853578c07b57ff8d9bbbbfe746f802226f05b19689420815221 |
Packages dedicated reactive ingress router JAR |
| Stage 4: Gateway Runtime | eclipse-temurin:25-jre |
sha256:bb036ed6cfdc57e3da7c22634d15f1b840d2caf76183861c80e81ca4b5104abb |
Lean JRE runtime for Cell Ingress Router (ADR-0081) |
| Stage 5: Synapse Runtime | eclipse-temurin:25-jre |
sha256:bb036ed6cfdc57e3da7c22634d15f1b840d2caf76183861c80e81ca4b5104abb |
Full Spector node runtime (Synapse + Cortex + Nginx) |
All pinned digests reference multi-architecture manifest lists (OCI image indexes) supporting both linux/amd64 and linux/arm64. Using the index digest rather than an architecture-confined child digest ensures that:
- Host cross-compilation with
--platform=$BUILDPLATFORMoperates seamlessly. - Target multi-platform builds produce native binaries for both Intel/AMD and Apple Silicon / AWS Graviton architectures without syntax changes.
# Example from deploy/docker/Dockerfile
FROM --platform=$BUILDPLATFORM node:22.22.3-alpine@sha256:e58326d0d441090181ac150dc2078d3e2cf6a0d42e809aebba3ef5880935ffdd AS builder-cortex
FROM --platform=$BUILDPLATFORM maven:3.9-eclipse-temurin-25@sha256:dd8e01b3be719853578c07b57ff8d9bbbbfe746f802226f05b19689420815221 AS builder-synapse
FROM eclipse-temurin:25-jre@sha256:bb036ed6cfdc57e3da7c22634d15f1b840d2caf76183861c80e81ca4b5104abb AS runtimeBoth the lean Gateway and the all-in-one Runtime targets implement defense-in-depth container hardening:
- Neither root nor the default cloud image user (
ubuntu) is permitted to run processes. - A dedicated service account
spector(UID1000, GID1000) is provisioned with/bin/bashshell and no sudo privileges. - Default users (
ubuntu) and lingering dev binaries (/usr/bin/pebble) are stripped from the base image. - Both
gatewayandruntimestages declareUSER 1000:1000.
-
Java processes running directly as PID 1 do not properly reap orphaned child processes or route POSIX termination signals (
SIGTERM,SIGINT). -
tiniis installed and invoked as the containerENTRYPOINT:ENTRYPOINT ["/usr/bin/tini", "--", "/app/entrypoint.sh"]
-
This ensures clean shutdown sequences, flushing all in-flight off-heap slabs (
Arena.ofShared()) and persisting partition summaries to disk before the container stops.
-
Build Tool Segregation: Compilers (
javac,mvn,npm), header files, and source code remain isolated in intermediate builder stages and are absent from the runtime stages. -
Apt Cleanup: Package indexes (
/var/lib/apt/lists/*) are purged immediately after utility installation to minimize footprint. -
Package Patching: Key utilities (
perl-base,gpgv) are explicitly upgraded in the base layer to neutralize dormant base-image vulnerabilities.
Every runtime image defines an explicit container healthcheck:
HEALTHCHECK --interval=10s --timeout=3s --start-period=20s --retries=3 \
CMD curl -sf http://127.0.0.1:7070/actuator/health || exit 1Orchestrators (Kubernetes, Docker Compose, ECS) automatically monitor service availability and route traffic away from degrading nodes.
Pinning digests without automation risks image staleness, leaving container images vulnerable as security patches are published upstream. Spector automates base image pin maintenance using GitHub Dependabot.
The repository includes a dedicated docker package ecosystem entry monitoring /deploy/docker:
- package-ecosystem: "docker"
directory: "/deploy/docker"
schedule:
interval: "weekly"
labels:
- "dependencies"
- "docker"
open-pull-requests-limit: 5flowchart LR
A[Upstream Image Updated] --> B[Dependabot Weekly Check]
B --> C[Compute New SHA-256 Digest]
C --> D[Open Automated PR]
D --> E[Run CI & Trivy Scan]
E -->|Clean Scan| F[Jarvis / Nexus Review & Merge]
E -->|Vulnerabilities Found| G[Hold PR & Investigate]
-
Scheduled Scan: Every Monday, Dependabot parses
deploy/docker/Dockerfileand checks registry APIs for new digest releases on the referenced tags (node:22.22.3-alpine,maven:3.9-eclipse-temurin-25,eclipse-temurin:25-jre). -
Automated Pull Request: When an upstream update is detected, Dependabot submits a PR updating the
@sha256:digest string in place. -
CI Validation: The PR automatically triggers:
- Full reactor compilation and unit test passes.
-
container-security.ymlbuilding the image and executing Trivy vulnerability scanning. -
mvn license:checkverifying Apache 2.0 license compliance.
-
Merge Protocol: Once all quality gates pass without new security advisories, the PR is reviewed and merged into
main.
All container modifications and weekly builds are subjected to automated static vulnerability scanning via Trivy.
-
Triggers:
-
pushtomainmodifyingdeploy/docker/**,**/Dockerfile*, orpom.xml. -
pull_requesttargetingmaintouching container definitions. - Scheduled weekly scan every Monday at 04:00 UTC (
cron: '0 4 * * 1'). - Manual trigger via
workflow_dispatch.
-
- name: Scan Docker image with Trivy (Console & Step Summary)
uses: aquasecurity/trivy-action@master
with:
image-ref: 'spector:scan-target'
format: 'table'
severity: 'CRITICAL,HIGH,MEDIUM,LOW'
ignore-unfixed: true
exit-code: '0'
- name: Generate Trivy SARIF Report
uses: aquasecurity/trivy-action@master
with:
image-ref: 'spector:scan-target'
format: 'sarif'
output: 'trivy-results.sarif'
severity: 'CRITICAL,HIGH,MEDIUM,LOW'
ignore-unfixed: true
- name: Upload SARIF to GitHub Code Scanning
uses: github/codeql-action/upload-sarif@v4
if: always()
with:
sarif_file: 'trivy-results.sarif'
category: 'container-docker'-
Vulnerability Filtering: Scans evaluate OS packages, Node dependencies, and Java runtime JARs. Unfixed upstream CVEs (
ignore-unfixed: true) are filtered to avoid spurious build breaks while highlighting actionable patches. - Code Scanning Integration: SARIF results are published to the repository's Security > Code Scanning Alerts dashboard, providing line-level attribution and historical tracking.
When a zero-day or high-severity CVE is disclosed affecting an upstream base image (such as an OpenSSL, glibc, or OpenJDK security advisory), Spector maintainers execute an accelerated emergency patch runbook.
In accordance with SECURITY.md:
| Severity | CVSS v3.1 Range | Acknowledgment SLA | Target Fix Window | Escalation Channel |
|---|---|---|---|---|
| Critical | 9.0 – 10.0 | < 24 hours | < 48 hours (Emergency Fast-Track) |
@nexus + @jarvis
|
| High | 7.0 – 8.9 | < 48 hours | 7 calendar days | @nexus |
| Medium | 4.0 – 6.9 | < 48 hours | 14 calendar days | Next Dependabot cycle |
| Low | 0.1 – 3.9 | < 5 business days | Next scheduled release | Backlog |
For Critical vulnerabilities (CVSS
Retrieve the new upstream digest published by Eclipse Adoptium or Docker Official Images:
# Example: Inspect upstream multi-arch index digest for Temurin 25 JRE
TOKEN=$(curl -s "https://auth.docker.io/token?service=registry.docker.io&scope=repository:library/eclipse-temurin:pull" | sed -E 's/.*"token":"([^"]+)".*/\1/')
curl -s -I -H "Authorization: Bearer $TOKEN" \
-H "Accept: application/vnd.oci.image.index.v1+json" \
"https://registry-1.docker.io/v2/library/eclipse-temurin/manifests/25-jre" | grep -i docker-content-digest- Create hotfix branch:
git checkout -b hotfix/cve-<cve-id>-base-image - Update the
@sha256:digest indeploy/docker/Dockerfile. - Update this document (
docs/deployment/container-security.md) with the new digest.
# Verify Dockerfile syntax and resolution
docker build --check -f deploy/docker/Dockerfile .
# Verify license compliance
mvn license:check
# Run local Trivy scan against the candidate build
docker build -t spector:hotfix-test -f deploy/docker/Dockerfile .
trivy image --severity CRITICAL,HIGH spector:hotfix-test- Submit PR with title
fix(docker): patch CVE-<year>-<id> by advancing <base-image> digest pin. - Ensure commit carries DCO 1.1 sign-off (
git commit -s). - Maintainers (
@nexus,@jarvis) review and merge immediately upon passing CI gates. - CI publishes patched images to
ghcr.io/spectrayan/spectorand triggers release notifications.
- Home
-
Getting Started
- Quick Start
- Installation
- Developer Guide
- JDK API Status
- MCP Server
- Java SDK
- Java API Reference
- Python SDK
- TypeScript SDK
- Spring AI Integration
- CLI Reference
- REST API
- API Playground
- Error Codes
- Configuration
- Deployment
-
Cognitive Memory
- Overview
- Getting Started
- Use Cases
- API Reference
- Concepts
- Pathways
- Scoring features
- Profiles
- Experimental
- Internals
- Design ancestry
-
Memory Kernel
- Overview
- Bundle Architecture
- Memory Shapes
- Binary Layouts & Tags
- WAL & Durability
-
Region Reference
- Overview & Index
- Partition Regions
-
Runtime Regions
- Working Memory
- Co-Activation Matrix
- Index MIDX
- Index IDPL
- Hebbian Graph
- Temporal Chains
- Temporal Facts
- Entity Directory
- Entity Names Pool
- HyperEntity Graph
- Entity Types Registry
- Relation Types Registry
- BM25 Lexical Index
- Checkpoint
- Insula (Somatic Self-Model)
- Continuity
- Provenance
- SPLADE Sparse Index
- Entity Reverse Index
- Identity Regions
- Synapse & Cortex
-
Architecture
- System Overview
- Core Concepts
- Ingestion Pipeline
- MCP Integration
- Distributed Mode
- Event Notifications
- Namespace Sharding
- Single-Namespace Scale & Capacity Limits
- Scale Benchmark Empirical Results
- Writer Quiesce Pause Empirical Results
- Kill-Owner Failover Empirical Results
- Salience & Importance Architecture
- GPU Acceleration
- Performance Tuning
- Test Framework & LLM Judge
- Chat & Visual Test Infrastructure
- Security & Data
-
Architecture Decision Records (ADRs)
- Overview
- Template
- Master Catalog (0001-0085)
-
Memory Kernel & Storage Formats
- ADR-0001: Graph Compression Strategy for Entity Graph
- ADR-0002: Multi-Partition Recall Fan-Out & Frozen Reten...
- ADR-0003: Completing Hypergraph Entity-Graph Graduation
- ADR-0004: Mmap Bundle Architecture & File Descriptor Sc...
- ADR-0005: spector-memory Technical Debt Hardening
- ADR-0042: Graph Recall Architecture and Cognitive Trave...
- ADR-0043: Single-VMA Bundle Layout Specification
- ADR-0044: Memory Kernel Isolation, Composition, and Layout
- ADR-0045: Spector Memory Import & Export Pipeline
- ADR-0046: Single Engram, Four Stores Storage Architecture
- ADR-0047: Episodic Memory and Engram Model Hierarchy
- ADR-0057: Remediation of Hardcoded Memory Offsets and Alignment Constants
- ADR-0062: Spector Memory Organization — Three-Plane Architecture
- ADR-0082: Index Plane Lifecycle, Derived Views, and Reconciliation
-
Active Inference Self-Model Engine (AISME)
- ADR-0006: Episodic Conversation Architecture
- ADR-0007: ReflectPathway — Biological Sleep Consolidation
- ADR-0008: Cognitive Substrate Evolution (TANGLE, GPM, M...
- ADR-0009: AISME Phase 1 — Homeostatic Affective Core
- ADR-0010: AISME Phase 2 — Free-Energy Guided Recall
- ADR-0011: AISME Phase 3 — Modern Hopfield Associative M...
- ADR-0012: AISME Phase 4 — Neural Manifold Distance (NMD)
- ADR-0013: AISME Phase 5 — Predictive Coding Narrative Self
- ADR-0014: AISME Phase 6 — Consciousness Continuity Metr...
- ADR-0015: AISME Phase 7 — Synaptic Relay Wiring & Pathw...
- ADR-0016: AISME Phase 8 — Closed-Loop Epistemic Learning
- ADR-0017: AISME Phase 9 — Generative Counterfactuals & ...
- ADR-0018: AISME Phase 10 — WanderPathway & Kernel Conti...
- ADR-0019: AISME Phase 11 — Expected Free Energy Policy ...
- ADR-0020: AISME Phase 12 — Continuous Self-Dynamics
- ADR-0023: AISME Complete Loop Closure & CognitiveVector...
- ADR-0024: Polymorphic SoulContext Hierarchy in AISME
- ADR-0027: Soul-Conditioned & Salience-Modulated Persona...
- ADR-0048: Cross-Capture Graph & CoActivation Kernel
- ADR-0049: Identity Trajectory Lyapunov Stability
- ADR-0050: Event Density Gating and Dynamic Epistemic Co...
- ADR-0051: Bayesian Online Change-Point Episode Segmenta...
- ADR-0052: Differential Privacy and Edge Anonymization
- ADR-0053: Multimodal Composite Importance Scoring
- ADR-0054: Lifespan-Adaptive Forgetting & Retention Kernel
- ADR-0055: LSR & RFF Dense Associative Memory Engineerin...
- ADR-0056: Log-Sum-ReLU (LSR) & Random Fourier Features ...
- ADR-0058: Linguistic & Vocal Prosody Expression Engine
- ADR-0063: Spacetime Vector Search and Synaptic Relay Architecture
- ADR-0064: Spacetime Simulation on Wander, Dream, and Express Pathways
- ADR-0071: Remember Cognitive Pathway Architecture
- ADR-0072: Six-Phase Fused Cognitive Scoring Pipeline
- ADR-0073: Recall Cognitive Pathway and Multi-Phase Retrieval Architecture
- ADR-0074: Reflect Cognitive Pathway and Sleep Consolidation Architecture
- ADR-0078: Salience Network and Thalamic Cognitive Profiles Architecture
-
Platform, Synapse & Clustering
- ADR-0021: Nucleus Symmetric Hardware Abstraction Layer ...
- ADR-0022: Embodied Kinesics & Phenomenological MCP Engine
- ADR-0025: Declarative MCP Tool Definitions via JSON Sch...
- ADR-0026: Dual-Plane Concurrency & Async Queue Backpres...
- ADR-0028: Dual-Plane Memory Audit Architecture (Separat...
- ADR-0029: Episodic→Semantic Lineage Provenance Region
- ADR-0030: Unified Engram Encoding Header Architecture
- ADR-0031: Unified Configuration Architecture & Bypass E...
- ADR-0032: Persona Enactment — Soul as Policy over Memory
- ADR-0033: Decoupling Cognitive & Mathematical Kernels t...
- ADR-0034: Cell Topology, Namespace Ownership, and HA Cl...
- ADR-0035: Cognitive Pathway Framework Rearchitecture
- ADR-0036: Pathway Error Handling, Isolation, and Circui...
- ADR-0037: Ingestion Boundary and Sensory Relocation
- ADR-0038: SIMD-Accelerated BM25 Lexical Scoring Optimiz...
- ADR-0039: Robust Unified Rate Limiting Architecture
- ADR-0040: Universal Apache Camel Messaging Channels
- ADR-0041: Unified Connector Architecture for Ingestion
- ADR-0059: Java 27 Upgrade Strategy and Value Class Migration
- ADR-0060: Cognitive Continuity Layer and Decoded Mind Streams
- ADR-0061: In-Memory Multi-Tenant Quartz Scheduler
- ADR-0065: Client SDK Architecture, OpenAPI, and MCP Integration
- ADR-0066: Engine & CLI Stabilization — Issue #727 Hardening
- ADR-0067: Cell-Based High Availability and Namespace-Sticky Sharding
- ADR-0068: Phileas PII Redaction Engine for Spector Synapse
- ADR-0069: Synapse-Owned Tool Access Policy
- ADR-0070: Unified Error Taxonomy and Exception Handling Architecture
- ADR-0075: Extensible LLM and Multimodal Embedding Provider SPI
- ADR-0076: Zero-Dependency Pluggable Cache Abstraction
- ADR-0077: Model B Asynchronous Task Queue and Concurrency
- ADR-0079: Asynchronous Memory Event and Telemetry Notification Bus
- ADR-0080: Observed Memory and Pathway Metrics Telemetry Architecture
- ADR-0081: Dedicated Reactive Ingress and In-Process Path Router
- ADR-0083: Namespace-Isolated Memory Analytics & Telemetry
- ADR-0084: Dual-Plane Conversation Persistence
- ADR-0085: Dynamic Synapse Configuration Overrides and Runtime Propagation
-
Modules Registry
- Overview
- Foundation Layer (/nucleus)
- Cognitive Layer (/memory)
- Gateway Layer (/synapse)
- Benchmarks & UI
- Deep Dives
-
Community
- Governance
- Contributing
- FAQ
- Glossary
- Roadmap
- 🔬 Labs
- Third-Party Legal