Clustara

요약. Clustara: 자율 개선 회차 30회, 릴리즈 19건. 최근 릴리즈 v0.9.281 (자산 3개). 건강 C 14일: 릴리즈 19, 실패 0, 경고 2, 회귀 1

현황

저장소
https://github.com/hkjang/clustara
마지막 회차
2026-09-10 17:50 KST — 🚀 릴리즈 merged PR #20, released v0.9.281
최근 릴리즈
v0.9.281 — released · 자산 3개 (이전 v0.9.280: 3개) 전체 릴리즈 →

회차 이력

일시프로젝트결과
2026-09-10 17:50Clustara배포 준비 완료 merged PR #20, released v0.9.281
3파일 +252/−31 · 테스트 1 — fix(capacity): another cluster's nodes and Pods were counted into this cluster's capacity
2026-09-10 09:11Clustara배포 준비 완료 merged PR #19, released v0.9.280
7파일 +270/−21 · 테스트 2 — fix(security): a pod that sets `runAsUser: 0` at the pod level was not reported as root
2026-09-09 13:30Clustara배포 준비 완료 merged PR #18, released v0.9.279
5파일 +177/−11 · 테스트 1 — fix(images): an untagged image behind a registry port passed the mutable-tag checks
2026-09-09 05:03Clustara배포 준비 완료 merged PR #17, released v0.9.278
5파일 +269/−37 · 테스트 3 — fix(connectivity): another cluster's Pods and Services satisfied this cluster's checks
2026-09-08 23:21Clustara배포 준비 완료 merged PR #16, released v0.9.277
6파일 +394/−41 · 테스트 3 — fix(exposure): a wildcard-certificate Ingress was reported as plaintext
2026-09-08 18:10Clustara배포 준비 완료 merged PR #15, released v0.9.276
5파일 +252/−26 · 테스트 2 — fix(security): a certificate that expired 6 hours ago was reported as valid
2026-09-08 11:18Clustara배포 준비 완료 assets-only, assets for v0.9.275
2026-09-08 11:15Clustara릴리즈 진행 중 assets-only, assets for v0.9.275, asset manifest failed, ASSETS MISSING
2026-09-08 10:56Clustara배포 준비 완료 merged PR #14, released v0.9.275, asset manifest failed
9파일 +469/−35 · 테스트 4 — fix(terminal): a root wipe spelled `r"m" -rf /` passed every gate and ran
2026-09-07 07:07Clustara배포 준비 완료 merged PR #13, released v0.9.274, asset manifest failed
8파일 +365/−15 · 테스트 2 — fix(security): a scan stored as "unknown" was read by the Trivy parser (v0.9.274)
2026-09-06 21:45Clustara릴리즈 진행 중 merged PR #12, released v0.9.273, asset manifest failed, ASSETS MISSING
8파일 +249/−24 · 테스트 2 — fix(security): the unhardened pods were the ones labelled "restricted" (v0.9.273)
2026-09-06 00:17Clustara검토 대기 review held, PR open PR #11
9파일 +337/−74 · 테스트 1 — fix(capacity): finished pods held node capacity, cost and GPU slots (v0.9.272)
2026-09-05 17:13Clustara배포 준비 완료 merged PR #10, released v0.9.271
12파일 +510/−57 · 테스트 4 — fix(action): an approved delete_pod on a Deployment deleted a Pod instead (v0.9.271)
2026-09-05 11:08Clustara배포 준비 완료 merged PR #9, released v0.9.270 +3 assets
2026-09-04 22:19Clustara배포 준비 완료 merged PR #8, released v0.9.269 +3 assets
2026-09-04 11:23Clustara변경 없음 assets-only v0.9.262, assets for v0.9.262 +3 assets
2026-09-04 11:21Clustara변경 없음 assets-only v0.9.263, assets for v0.9.263 +3 assets
2026-09-04 11:20Clustara변경 없음 assets-only v0.9.264, assets for v0.9.264 +3 assets
2026-09-04 11:18Clustara변경 없음 assets-only v0.9.265, assets for v0.9.265 +3 assets
2026-09-04 11:16Clustara변경 없음 assets-only v0.9.266, assets for v0.9.266 +3 assets
2026-09-04 11:14Clustara변경 없음 assets-only v0.9.267, assets for v0.9.267 +3 assets
2026-09-04 07:02Clustara변경 없음 assets-only, assets for v0.9.268 +3 assets
2026-09-04 03:41Clustara배포 준비 완료 merged PR #7, released v0.9.268
2026-09-03 20:00Clustara배포 준비 완료 merged PR #6, released v0.9.267
2026-09-03 12:04Clustara배포 준비 완료 merged PR #5, released v0.9.266
2026-09-03 06:29Clustara배포 준비 완료 merged PR #4, released v0.9.265
2026-09-03 00:29Clustara배포 준비 완료 merged PR #3, released v0.9.264
2026-09-02 18:00Clustara배포 준비 완료 merged PR #2, released v0.9.263
2026-09-02 17:41Clustara배포 준비 완료 release-only, released v0.9.262
2026-09-02 12:45Clustara병합 완료 merged (옛 러너 경로에서 수행된 회차 원장 이관)

비용·사용량

최근 30세션
시각프로젝트단계시간비용토큰 입력/출력종료
17:48Clustara릴리즈5분30$1.321.1M / 12Ksuccess
17:43Clustarareview2분18$0.94740K / 8Ksuccess
17:40Clustara개선10분65$4.014.2M / 38Ksuccess
09:09Clustara릴리즈4분28$1.391.2M / 10Ksuccess
09:05Clustarareview5분17$0.97642K / 11Ksuccess
08:58Clustara개선8분48$3.343.2M / 29Ksuccess
13:28Clustara릴리즈4분26$1.13854K / 11Ksuccess
13:20Clustara개선7분40$3.112.8M / 30Ksuccess
05:01Clustara릴리즈4분26$1.24947K / 11Ksuccess
04:56Clustarareview6분37$2.092.0M / 18Ksuccess
04:49Clustara개선10분72$4.224.8M / 36Ksuccess
23:19Clustara릴리즈4분24$1.12779K / 11Ksuccess
23:14Clustarareview3분16$1.03684K / 11Ksuccess
23:10Clustara개선11분55$3.633.6M / 36Ksuccess
18:08Clustara릴리즈5분29$1.381.1M / 11Ksuccess
18:03Clustarareview3분13$0.71437K / 8Ksuccess
17:59Clustara개선9분43$2.922.3M / 34Ksuccess
11:18Clustara자산2분21$0.87544K / 7Ksuccess
11:01Clustara자산2분21$0.86606K / 6Ksuccess
10:54Clustara릴리즈5분28$1.511.1M / 13Ksuccess
10:49Clustarareview7분24$1.51805K / 20Ksuccess
10:41Clustara개선11분55$4.194.1M / 44Ksuccess
07:07Clustara릴리즈4분20$0.91600K / 8Ksuccess
07:03Clustarareview6분23$1.481.1M / 16Ksuccess
06:56Clustara개선28분53$4.244.3M / 40Ksuccess
21:31Clustara릴리즈4분19$0.99676K / 9Ksuccess
21:26Clustarareview5분26$1.461.2M / 14Ksuccess
21:21Clustara개선11분47$4.074.0M / 36Ksuccess
00:17Clustarareview5분26$1.921.5M / 18Ksuccess
00:11Clustara개선12분62$4.714.8M / 40Ksuccess

아이디어 백로그 — 대기 13 / 전체 14

에이전트가 회차마다 재평가한다. 가치 높고 위험 낮은 대기 항목이 다음 회차 후보다.
아이디어가치/위험/크기상태메모갱신
.github 에 CI 워크플로 없음 — build/vet/test 게이트 추가3/1/S대기2026-09-10 재확인, 여전히 .github 에는 FUNDING.yml 만. go test ./... 는 캐시 없이 약 80초(proxy 62s + store 16s)라 CI 게이트에 충분. gofmt -l 은 기존 미포맷 파일이 60개 이상이라 fmt 게이트는 넣지 말 것(별도 정리 필요).2026-09-10
PSS Restricted 검사에 seccompProfile 항목이 없음3/2/S대기restrictedProfileViolations 는 runAsNonRoot·allowPrivilegeEscalation·capabilities drop ALL 만 본다. 추가하면 사실상 모든 기존 Pod 가 baseline 으로 내려가고 enforce_pss_restricted Deny 게이트가 기존 Stack 을 막을 수 있으므로 포스처 점수·게이트 영향을 먼저 확인할 것.2026-09-10
취약점 import 가 파싱하지 못한 아티팩트를 '취약점 0건 완료' 스캔으로 저장3/3/S대기v0.9.274 는 summary.parse_notice·scanner_detected 로 신호만 남기고 import 는 성공시킨다. 형식 미인식 + findings 0건을 400 으로 거절하거나 Status 를 parse_failed 로 저장하는 편이 Admission 게이트에는 안전 — 기존 CI 파이프라인 영향 확인 필요. AnalyzeTLS(v0.9.276)가 같은 원칙을 파싱 실패 Secret 에 적용했다.2026-09-10
AnalyzeCapacity 가 종료된(Succeeded/Failed) Pod 를 노드 packing·비용에 계속 셈3/3/M대기2026-09-10 재확인 — 스케줄러가 계산하지 않는 완료 Job Pod 가 인벤토리에 남아 packing/GPU/비용에 잡힌다. 2026-09-06 에 같은 취지의 변경(+init 컨테이너 max 계산)을 담은 PR 이 사람에게 반려된 이력이 있으므로 같은 접근을 반복하지 말 것. 다시 시도한다면 집계 의미를 바꾸는 대신 '종료된 Pod 제외' 를 별도 표시/옵션으로 드러내는 등 다른 접근이 필요하다.2026-09-10
PodSecurityResult 에 cluster_id 가 없음2/1/S대기SecFinding 은 2026-09-09 에, 용량 리포트 5종은 2026-09-10 에 cluster_id 를 채웠지만 PodSecurityResult(SEC-01 Pod Security 표)와 DW export 는 아직 없다. /admin/k8s/security 도 cluster_id 가 선택 파라미터라 두 클러스터의 동명 워크로드가 구분되지 않는다. 추가는 omitempty 로 additive.2026-09-10
capacity 의 GPU 집계는 nvidia 만, node_monitoring 은 amd·intel 도 셈2/1/S대기capacity.podRequestGPU 와 nodePackingAndGPU 의 allocatable 이 nvidia.com/gpu 만 읽는다(2026-09-10 확인). 벤더 키를 늘리려면 requests·allocatable 을 함께 맞춰야 하고, cost.go 가 같은 podRequestGPU 를 쓰므로 AMD/Intel GPU 가 0원에서 GPU 단가로 바뀌는 비용 영향도 함께 확인할 것. 벤더 키 목록을 node_monitoring 과 공유하는 최소 변경으로.2026-09-10
podControllerOwned 가 라벨 휴리스틱만 봐서 ownerReferences 로만 소유된 Pod 를 standalone 으로 판정2/1/S대기pod-template-hash / controller-revision-hash / job-name 라벨이 없는 커스텀 컨트롤러 소유 Pod 에 '자동 복구 없음' 승인 사유가 붙는다(fail-safe 방향이라 위험 낮음). 수집기가 ownerReferences 를 Spec 에 저장하는지 먼저 확인 필요.2026-09-10
securityScanRunViews/DW export 가 scanner fallback 여부를 표시하지 않음2/1/S대기v0.9.274 가 summary.scanner_detected 를 저장하므로 스캔 목록 UI·export 에 '형식 미인식 fallback' 배지를 붙일 수 있다. 저장은 되고 표시만 없음.2026-09-10
Exposure Center 가 Gateway·HTTPRoute 를 실제로는 수집하지 않음2/1/S대기AnalyzeExposure 는 Kind "Gateway"/"HTTPRoute" 를 채점할 수 있고 문서·주석도 그렇게 적었지만, handleK8sExposures 의 switch 는 Ingress·Service 만 본다. 수집기가 gateway.networking.k8s.io 리소스를 인벤토리에 담는지 먼저 확인하고, 담지 않는다면 문서 문구를 사실에 맞추는 편이 정직하다.2026-09-10
isSensitivePath 가 substring 매칭이라 참조 이름까지 마스킹2/2/S대기imagePullSecrets·volumes[].secret.secretName 같은 참조 이름까지 *** 로 덮어 manifest 원장 diff 에 잡음이 생긴다. 마스킹을 좁히는 방향이므로 노출 위험이 없는지 경로별로 확인 필요.2026-09-10
AnalyzeExposure 의 wildcard host 점수가 host 수만큼 누적2/2/S대기host 하나당 +15 라 와일드카드 host 4개면 그것만으로 60점(high)이 된다. 같은 성격의 위험이 host 수로 등급을 밀어 올리는 셈. 다만 RiskScore/RiskLevel 은 UI 정렬과 저장된 기대치라 조정이 곧 등급 변동이므로 영향 확인 후.2026-09-10
Runtime Security Profile 의 AllowPrivEsc 는 명시적 true 만 셈2/2/S대기Kubernetes 는 allowPrivilegeEscalation 미설정을 true 로 취급하므로 아무것도 적지 않은 컨테이너가 런타임 보안 점수에서 0점을 받는다. restrictedProfileViolations 는 이미 미설정을 위반으로 본다(같은 Pod 를 두 화면이 다르게 표현). 다만 미설정이 압도적 다수라 그대로 켜면 거의 모든 Pod 가 medium 으로 올라가 화면이 무의미해질 수 있어 점수 배분을 먼저 설계할 것.2026-09-10
터미널 allowlist 는 명령의 첫 프로그램만 검사 — 체이닝된 뒤 명령은 대조되지 않음2/3/M대기terminalCommandMatches 는 prefix/substring 이라 'cat x && mv /data /tmp' 가 allowlist "cat" 으로 통과한다. 다만 Pod exec 는 셸 없이 argv 를 그대로 실행하므로 sh -c 없이는 뒤 명령이 실제로 실행되지 않고, 체이닝은 ParseCommandRisk 가 medium → guided 승인으로 올린다. 실효 위험은 낮고 allow 쪽을 세그먼트 단위로 바꾸면 기존 정책이 깨질 수 있어 보류.2026-09-10
용량 리포트가 노드·Pod 를 이름만으로 교차 참조해 다른 클러스터 값이 섞임 (SCALE-03/04/05/07/08)4/1/M완료2026-09-10 구현. /admin/k8s/capacity 는 cluster_id 가 선택 파라미터. nodePackingAndGPU·ProjectNodeCapacity·allocFinding 이 모두 이름만으로 조인해 동명 노드가 한 행으로 합쳐지고 다른 클러스터 메트릭이 이 클러스터 Pod 의 request 와 비교됐다. 같은 패키지 node_monitoring 은 이미 nodeKey(cluster,node) 사용. 결과 타입 5종에 cluster_id(omitempty) 추가, map 순회 순서를 cluster→node 정렬로 고정, UI 노드 표 조인과 YAML 딥링크도 행의 클러스터를 쓰게 함.2026-09-10

교훈 (깨졌던 변경)

원장 (에이전트가 남긴 기록)

2026-09-02

2026-09-02

2026-09-03

2026-09-03

2026-09-03

2026-09-03

2026-09-04

2026-09-04

2026-09-05

2026-09-06

← 대시보드 · 교훈 모음