Ingest. Queue. Recover.
VulnFlow accepts scanner reports, stores the payload privately and processes it asynchronously into normalized results. Duplicate delivery and failures between upload, publication and processing are treated as expected operating conditions.
Data flow
- 01 / SOURCEAgent / TrivyCreates the scanner report.
- 02 / INGESTVPS APIReceives and validates the upload.
- 03 / STOREPrivate S3Holds the durable report payload.
- 04 / PUBLISHPostgreSQL outboxRecords work before queue publication.
- 05 / PROCESSSQSDelivers asynchronous work to the consumer.
- 06 / PERSISTJava Lambda + DynamoDBNormalizes and stores the result.
SQS failure path
Retries exhausted → DLQ
Operational boundaries
Terraform provisions AWS · CloudWatch logs · IAM Roles Anywhere issues VPS credentials
Deliberate decisions
Durable payloads
S3 holds reports; events reference work.
S3 holds reports; events reference work.
Reliable publication
The outbox records work before queue publication.
The outbox records work before queue publication.
Idempotent processing
Event identity protects against at-least-once delivery.
Event identity protects against at-least-once delivery.
Recoverable failure
Retries, partial batches and DLQ redrive are explicit.
Retries, partial batches and DLQ redrive are explicit.