SIGN IN SIGN UP

fix(malwaremanager): stop paying for a manager that cannot alert

A second review of this pull request found that removing the scanner was
not the end of the removal. Eight items, grouped by what they cost.

The manager ran on every event for nothing. With the scanner gone,
CreateMalwareManager still returned a real manager and the container
watcher kept it registered for exec and open — the highest-volume
tracers. Every open event took two mutexes, built a host path and
inserted into a set before iterating a zero-length slice, and
scannedFiles retained up to 10001 paths per container that nothing read.
HasScanners() now lets cmd/main.go use the existing mock instead, and it
logs why. That also puts the "no scanner registered" warning where it
can say something true: a guard inside the constructor tests a constant.

The documentation still told users to switch the capability on. Seven
places did, including the copy-pasteable install command, the minimal
config sample, the recommended ConfigMap and the "Full Security Suite"
example. A user following any of them got the warning and the overhead
and no detection. The root README also kept the malware-image demo step
and its table row after demo/README.md dropped the walkthrough.

A stale chart is now self-reporting. Deleting the CLAMAV_SOCKET lookup
removed the only reader of that variable, so an operator who upgrades
the agent before the chart keeps the sidecar on every node — 100m and
256Mi requested, plus freshclam downloads — with nothing saying the
variable is dead. The agent warns when it sees it.

The CI chart no longer enables a capability nothing tests, now that
Test_10 is gone. That capability was also, quietly, the profiler switch:
ENABLE_PROFILER was set inside `if capabilities.malwareDetection ==
enable`, which is why turning the capability off would have turned the
profiler off too. The profiler has its own value now, so the two are
independent and both keep working.

tests/testutils.GetMalwareAlerts is removed. I argued for keeping it as
useful to a future scanner; with no caller it only drifts against the
alertmanager label schema with nothing to catch the drift. The reviewer
is right.

The metrics document called the SBOM scanner a third-party sidecar. It
is built by this repo and this agent already instruments it, so the
example is dropped rather than swapped.

Not changed, deliberately: CreateMalwareManager keeps its error return
even though nothing can fail in it now. Dropping it breaks a downstream
caller's build for no functional gain.

Signed-off-by: Alon Liwsky <40373481+AlonLiwsky@users.noreply.github.com>
A
Alon Liwsky committed
7f05e386c739af11fcdd85c31a50dd3b17748dbf
Parent: 6dbab1b