workers.securityworker: find eligible tag images
This commit is contained in:
parent
16ccc946f3
commit
904b902295
2 changed files with 18 additions and 4 deletions
|
@ -2,7 +2,7 @@ import logging
|
|||
|
||||
from uuid import uuid4
|
||||
|
||||
from peewee import IntegrityError
|
||||
from peewee import IntegrityError, JOIN_LEFT_OUTER
|
||||
from data.model import (image, db_transaction, DataModelException, _basequery,
|
||||
InvalidManifestException, TagAlreadyCreatedException, StaleTagException)
|
||||
from data.database import (RepositoryTag, Repository, Image, ImageStorage, Namespace, TagManifest,
|
||||
|
@ -13,6 +13,20 @@ from data.database import (RepositoryTag, Repository, Image, ImageStorage, Names
|
|||
logger = logging.getLogger(__name__)
|
||||
|
||||
|
||||
def get_tags_images_eligible_for_scan(clair_version):
|
||||
Parent = Image.alias()
|
||||
ParentImageStorage = ImageStorage.alias()
|
||||
|
||||
return _tag_alive(Image
|
||||
.select(Image, ImageStorage, Parent, ParentImageStorage, RepositoryTag)
|
||||
.join(RepositoryTag, on=(RepositoryTag.image == Image.id))
|
||||
.join(ImageStorage, on=(Image.storage == ImageStorage.id))
|
||||
.switch(Image)
|
||||
.join(Parent, JOIN_LEFT_OUTER, on=(Image.parent == Parent.id))
|
||||
.join(ParentImageStorage, JOIN_LEFT_OUTER, on=(ParentImageStorage.id == Parent.storage))
|
||||
.where(Image.security_indexed_engine < clair_version))
|
||||
|
||||
|
||||
def _tag_alive(query, now_ts=None):
|
||||
if now_ts is None:
|
||||
now_ts = get_epoch_timestamp()
|
||||
|
|
Reference in a new issue