Personal project / 01

VulnFlow

Asynchronous vulnerability-report processing from scanner upload to queryable cloud results.

Public replay available on the landing page; production scans remain authenticated.

JavaSpring BootAWSTerraformSQSLambdaDynamoDBS3PostgreSQL

Ingest. Queue. Recover.

VulnFlow accepts scanner reports, stores the payload privately and processes it asynchronously into normalized results. Duplicate delivery and failures between upload, publication and processing are treated as expected operating conditions.

Data flow

  1. 01 / SOURCEAgent / TrivyCreates the scanner report.
  2. 02 / INGESTVPS APIReceives and validates the upload.
  3. 03 / STOREPrivate S3Holds the durable report payload.
  4. 04 / PUBLISHPostgreSQL outboxRecords work before queue publication.
  5. 05 / PROCESSSQSDelivers asynchronous work to the consumer.
  6. 06 / PERSISTJava Lambda + DynamoDBNormalizes and stores the result.
SQS failure path
Retries exhausted → DLQ
Operational boundaries
Terraform provisions AWS · CloudWatch logs · IAM Roles Anywhere issues VPS credentials

Deliberate decisions

Durable payloads
S3 holds reports; events reference work.
Reliable publication
The outbox records work before queue publication.
Idempotent processing
Event identity protects against at-least-once delivery.
Recoverable failure
Retries, partial batches and DLQ redrive are explicit.