{"schema_version":1,"research_id":"eoa_inverse_innovation_exp04_external_evaluation_20260802","source_assessment_id":"layer_decay_and_expiration_management__computer_science:SENTINEL_MATCHED:v0","cell_id":"layer_decay_and_expiration_management__computer_science","search_queries":["site:docs.gitlab.com container registry cleanup policy storage untagged manifests","site:docs.github.com packages container registry retention delete restore package","site:docs.aws.amazon.com Amazon ECR lifecycle policies reference images production rules","OCI distribution specification deletion garbage collection manifest references","container registry storage growth cleanup policy case study official registry stale images","site:about.gitlab.com container registry storage cleanup customer storage cost","site:goharbor.io docs retention policy garbage collection immutable tags","site:learn.microsoft.com Azure Container Registry retention policy untagged manifests lock","site:docs.gitlab.com cleanup policy container registry Owner Maintainer permission","site:docs.gitlab.com container registry cleanup policy protected tags production rollback","site:goharbor.io docs tag retention dry run retain pulled pushed image","site:cloud.google.com artifact registry cleanup policies dry run keep policy tags","container image cleanup live Kubernetes deployments dependency aware registry cleanup tool","werf cleanup container registry Kubernetes images in use git history policies official docs","site:werf.io docs cleanup images Kubernetes deployments git history","registry cleanup preserve images used in Kubernetes cluster official","site:docs.aws.amazon.com ECR archive restore images lifecycle policy restore archive","site:docs.aws.amazon.com Amazon ECR archive storage pricing restore image limitations","site:docs.gitlab.com container registry cleanup policy permissions Maintainer Owner","site:docs.github.com artifact attestations retention container images provenance delete","Amazon ECR pricing archive storage 2026 per GB month official","GitLab container registry storage pricing per GB 2026 official","Google Artifact Registry pricing storage per GB official"],"sources":[{"source_id":"S1","title":"Clean up Your Container Images with Amazon ECR Lifecycle Policies","publisher":"Amazon Web Services","url":"https://aws.amazon.com/blogs/compute/clean-up-your-container-images-with-amazon-ecr-lifecycle-policies/","source_class":"COMMERCIAL_FIRST_PARTY","publication_date":"2017-10-11","accessed_at":"2026-08-02","claims_supported":["Active ECR users often accumulate many image versions, making important revisions harder to find and adding storage costs.","Lifecycle policies and previews automate removal of old or unused images.","Rollback needs and organization-specific retention periods constrain cleanup."]},{"source_id":"S2","title":"Set a Retention Policy to Retain Untagged Manifests","publisher":"Microsoft Azure","url":"https://learn.microsoft.com/en-us/azure/container-registry/container-registry-retention-policy","source_class":"OFFICIAL_PRODUCT_DOCUMENTATION","publication_date":"2026-07","accessed_at":"2026-08-02","claims_supported":["Untagged manifests can fill registries with unneeded artifacts and incur storage costs.","Azure supports timed retention, manifest reference counting, and per-manifest delete locks.","Deletion is unrecoverable and can break systems that pull images by digest, demonstrating the hidden-consumer hazard.","The policy has format and temporal-coverage limitations, including incomplete OCI-manifest coverage."]},{"source_id":"S3","title":"Reduce container registry storage","publisher":"GitLab","url":"https://docs.gitlab.com/user/packages/container_registry/reduce_container_registry_storage/","source_class":"OFFICIAL_PRODUCT_DOCUMENTATION","publication_date":"undated living documentation","accessed_at":"2026-08-02","claims_supported":["Unmanaged registries grow, consume storage, and make image or tag listings slower.","GitLab cleanup supports age, name, keep-count, protected-tag, and immutable-tag rules.","Removing tags does not itself remove underlying manifests and layers; separate garbage collection is required.","Maintainer, project Owner, or namespace Owner roles can inspect registry usage, identifying plausible operational authorizers."]},{"source_id":"S4","title":"Configure cleanup policies","publisher":"Google Cloud","url":"https://docs.cloud.google.com/artifact-registry/docs/repositories/cleanup-policy","source_class":"OFFICIAL_PRODUCT_DOCUMENTATION","publication_date":"2026-07-17","accessed_at":"2026-08-02","claims_supported":["Artifact Registry supports dry-run cleanup before deletion.","Keep policies override delete policies and can preserve immutable or recent artifacts.","Cleanup can be filtered by tag state, age, package, version, and tag prefixes."]},{"source_id":"S5","title":"Automate the cleanup of images by using lifecycle policies in Amazon ECR","publisher":"Amazon Web Services","url":"https://docs.aws.amazon.com/AmazonECR/latest/userguide/LifecyclePolicies.html","source_class":"OFFICIAL_PRODUCT_DOCUMENTATION","publication_date":"undated living documentation","accessed_at":"2026-08-02","claims_supported":["ECR can preview, prioritize, archive, or expire images through lifecycle rules.","Lifecycle actions are recorded in AWS CloudTrail.","Manifest-list references constrain expiration or archival, while associated reference artifacts follow their subject image.","Age, image count, pull activity, and archival age are established lifecycle selectors."]},{"source_id":"S6","title":"Archiving an image in Amazon ECR","publisher":"Amazon Web Services","url":"https://docs.aws.amazon.com/AmazonECR/latest/userguide/archive_restore_image.html","source_class":"OFFICIAL_PRODUCT_DOCUMENTATION","publication_date":"undated living documentation","accessed_at":"2026-08-02","claims_supported":["ECR provides a lower-cost archive class for rarely accessed images retained for compliance or long-term reference.","Archived images can be restored to standard storage, normally within 20 minutes.","Restored images return to normal scanning, replication, and lifecycle processing."]},{"source_id":"S7","title":"Container registry cleanup","publisher":"werf","url":"https://werf.io/docs/v2/usage/cleanup/cr_cleanup.html","source_class":"OFFICIAL_PRODUCT_DOCUMENTATION","publication_date":"2026-07","accessed_at":"2026-08-02","claims_supported":["werf explicitly describes rapid accumulation, registry storage growth, and cost pressure.","werf cleanup checks live Kubernetes objects and refuses to delete an image used by them.","It combines deployment-reference checks with Git-history, recency, and configurable keep policies.","Its visibility is limited to configured Kubernetes contexts and its own build and Git metadata, and registry garbage collection remains separate."]},{"source_id":"S8","title":"Open Container Initiative Distribution Specification","publisher":"Open Container Initiative","url":"https://github.com/opencontainers/distribution-spec/blob/main/spec.md","source_class":"STANDARD","publication_date":"undated main branch","accessed_at":"2026-08-02","claims_supported":["OCI registries contain digest-addressed blobs, manifests, indexes, and mutable human-readable tags.","Manifests can reference other manifests and blobs, making deletion graph-sensitive.","Registry deletion and tag deletion are optional and vary by implementation.","The standard defines content-management API semantics but not a cross-system retention, legal-hold, or deployment-dependency policy."]}],"problem_evidence":{"support":"STRONG","rationale":"AWS, Azure, GitLab, and werf independently state that image versions or unneeded artifacts accumulate, increase storage costs, slow or clutter discovery, and require lifecycle controls. Azure warns that deleting an apparently untagged image can break digest-based consumers, while AWS and GitLab emphasize rollback and preservation exceptions. Prevalence and realized loss are not quantified for the proposed adopter, but the structural problem is directly visible across multiple registry implementations.","source_ids":["S1","S2","S3","S5","S7","S8"]},"stakeholder_evidence":{"support":"MODERATE","rationale":"Development teams, registry operators, and GitLab Maintainer/Owner roles are identifiable users and authorizers; multiple vendors have shipped lifecycle products in response to the need. However, no named organization has committed to this exact pilot, and the sources do not establish that a release, security, compliance, or legal authority has approved the proposed integrated policy.","source_ids":["S1","S3","S5","S7"]},"prior_art":{"proximity":"ESTABLISHED_PRACTICE","closest_analogues":[{"name":"werf container-registry cleanup","similarity":"Very close on the central dependency-gated mechanism: it inventories image versions, evaluates Git relevance, scans live Kubernetes resources, and will not delete deployed images.","remaining_difference":"It does not demonstrate comprehensive external-digest discovery, legal or investigation holds, reversible quarantine, tombstones, archive restore drills, or heterogeneous non-Kubernetes dependency coverage.","source_ids":["S7"]},{"name":"Amazon ECR lifecycle and archive policies","similarity":"Close on lifecycle rules, previews, ordered exceptions, archival, permanent expiration, audit events, subject-reference handling, and restoration.","remaining_difference":"The documented selectors are primarily age, count, tags, pull activity, and manifest relationships rather than a live cross-control-plane deployment and hold graph; periodic restore testing is not documented.","source_ids":["S5","S6"]},{"name":"Google Artifact Registry cleanup policies","similarity":"Close on dry runs, delete and keep rules, immutable-tag protection, age filters, and background execution.","remaining_difference":"No documented live deployment-reference gate, quarantine/restore workflow, legal-hold register, or stale-discoverability detector.","source_ids":["S4"]},{"name":"Azure Container Registry retention policy","similarity":"Close on TTL-style expiry, manifest reference counting, deletion locks, and explicit recognition of digest-based hidden consumers.","remaining_difference":"The policy is limited largely to untagged manifests, deletion is unrecoverable, OCI coverage is incomplete, and external consumers are handled by warning rather than discovery.","source_ids":["S2"]},{"name":"GitLab container-registry cleanup policy","similarity":"Close on scheduled age/name/keep-count cleanup with protected and immutable exceptions.","remaining_difference":"It removes tags rather than underlying data, uses tag-oriented inference, and requires separate garbage collection; live deployment dependencies and archive restoration are not documented.","source_ids":["S3"]}],"distinctive_claim_remaining":"In one bounded registry namespace, adding a unified live-deployment, provenance, external-digest, and hold gate plus reversible quarantine, deletion markers, and sampled archive-restore drills to ordinary age/tag cleanup will produce at least 20% more confirmed-safe stale bytes per operator-hour and at least 25% lower obsolete-artifact discoverability, while quarantining zero live or held artifacts and restoring every sampled archive digest-identically within 30 minutes. This is a local incremental claim, not a world-novelty claim.","confidence":"HIGH"},"implementation_evidence":{"support":"MODERATE","rationale":"All major technical primitives exist: registry inventory and deletion APIs, dry-run lifecycle rules, protected or immutable exceptions, manifest reference counting, Kubernetes deployment scanning, archival, restore, and audit events. A 500-artifact nonproduction pilot is therefore technically credible. The unverified work is integration: enumerating external digest consumers, correlating CI/provenance and deployment systems, encoding organization-specific holds, preserving deletion markers, and proving restoration across formats. Azure and OCI also show that deletion behavior and format coverage vary by registry.","source_ids":["S2","S3","S4","S5","S6","S7","S8"]},"scores":{"meaningful_impact":{"score":4,"rationale":"Multiple independent operators identify storage, cost, retrieval, and rollback consequences; impact magnitude for a particular namespace is still unknown.","source_ids":["S1","S2","S3","S7"]},"stakeholder_pull":{"score":3,"rationale":"Vendor investment and explicit operator guidance show broad pull, and registry Owners/Maintainers are identifiable authorizers, but no committed pilot partner was found.","source_ids":["S1","S3","S5"]},"incremental_advantage":{"score":3,"rationale":"Dependency and hold gates could materially reduce unsafe deletions relative to age-only cleanup, but werf already implements the most important live-Kubernetes reference check.","source_ids":["S2","S7"]},"distinctiveness_plausibility":{"score":2,"rationale":"Lifecycle rules, keep exceptions, dependency checks, archival, restoration, and auditing are established. Only their broader cross-system integration and measured operating advantage remain contrastive.","source_ids":["S2","S4","S5","S6","S7"]},"technical_implementability":{"score":4,"rationale":"The necessary APIs and mechanisms are documented and deployed, though hidden external consumers and heterogeneous registry semantics prevent a fully automatic safety guarantee.","source_ids":["S2","S4","S5","S6","S7","S8"]},"adoption_authority_feasibility":{"score":3,"rationale":"Registry Owners, Maintainers, and administrators can configure or execute lifecycle policies, but production deletion also requires service-owner and organization-specific security, compliance, incident, and legal approval.","source_ids":["S2","S3","S5"]},"evidence_readiness":{"score":3,"rationale":"A dry-run and quarantine pilot can collect decisive operational evidence, but required dependency, usage, hold, and deployment data are proprietary and unavailable through web research.","source_ids":["S3","S4","S5","S7"]},"safety_net_benefit":{"score":5,"rationale":"No-hard-delete piloting, dry runs, locks, keep rules, quarantine, archive restoration, and audit records directly address irreversible deletion and rollback hazards.","source_ids":["S2","S4","S5","S6"]},"scalability":{"score":3,"rationale":"Scheduled vendor lifecycle engines scale operationally, but cross-cluster dependency enumeration, hidden digest consumers, policy exceptions, and per-format restore verification may scale poorly without reliable metadata ownership.","source_ids":["S3","S5","S7","S8"]}},"score_confidence":"MODERATE","costs":{"first_evidence":{"band_2026_usd":"UNDER_10K","scope":"Read-only export and classification of at most 500 artifacts, two policy dry runs, baseline search-exposure measurement, and a short owner review; no archival or deletion.","confidence":"MODERATE","assumptions":["One registry namespace already exposes image, tag, age, and size metadata.","Approximately 40-60 engineer or analyst hours at a 2026 resource-equivalent rate of $100-$150 per hour.","Existing GitLab, Google, AWS, or equivalent preview APIs are reused.","No legal analysis beyond confirming that the selected nonproduction namespace has no regulated records."],"source_ids":["S3","S4","S5"]},"initial_deployment_startup":{"band_2026_usd":"10K_TO_50K","scope":"Build the bounded nonproduction connector and policy configuration, ingest Kubernetes and CI references, implement hold vetoes and audit output, archive and restore a sample, and train two operators.","confidence":"MODERATE","assumptions":["Two to eight engineer-weeks plus limited release/security review.","At most one registry, one orchestration control plane, and 500 artifacts.","Native archive, preview, and audit capabilities are available or can be approximated without a new storage platform.","Hard deletion remains disabled."],"source_ids":["S4","S5","S6","S7"]},"operational_launch":{"band_2026_usd":"50K_TO_250K","scope":"Production hardening across registry, CI/provenance, deployment, incident-hold, and compliance workflows; access controls, monitoring, runbooks, canary rollout, restore drills, and independent safety review.","confidence":"LOW","assumptions":["A medium organization with several namespaces and clusters.","Three to twelve engineer-months distributed across platform, release, security, and compliance roles.","External digest consumers require discovery or registration mechanisms.","This excludes enterprise-wide registry replacement and major historical-data migration."],"source_ids":["S2","S3","S5","S6","S7","S8"]},"annual_recurring":{"band_2026_usd":"10K_TO_50K","scope":"Policy review, exception revalidation, monthly sampled restore tests, incident response, connector maintenance, audit review, and incremental archive/retrieval charges for a limited deployment.","confidence":"LOW","assumptions":["Approximately 0.1-0.25 full-time-equivalent operations effort.","Native vendor lifecycle and archive services remain available.","Storage and retrieval volume is moderate; exact bytes, egress, and vendor pricing were not supplied.","Major legal disputes, migrations, and 24x7 dedicated staffing are excluded."],"source_ids":["S3","S5","S6","S7"]}},"verified_pipeline_gates":{"externally_supported_problem":{"status":"YES","reason":"Several official, independent registry publishers directly document accumulation, storage cost, slower discovery, and unsafe-deletion risks.","source_ids":["S1","S2","S3","S7"]},"externally_credible_adopter_or_authorizer":{"status":"YES","reason":"Registry-owning development teams are explicit users, while GitLab identifies Maintainer, project Owner, namespace Owner, and administrator roles capable of inspecting or configuring registry management. Production multi-party approval remains organization-specific.","source_ids":["S1","S3","S5"]},"distinct_testable_incremental_claim":{"status":"YES","reason":"The remaining claim compares an integrated dependency/hold/quarantine/restore workflow with age/tag cleanup using measurable safety, byte-yield, discoverability, operator-effort, and restoration outcomes. It is distinct as a test configuration even though its components are established.","source_ids":["S2","S4","S5","S6","S7"]},"bounded_next_evidence_step":{"status":"YES","reason":"A 30-day, one-namespace, 500-artifact, no-hard-delete experiment with an age-only comparator, planted references, bounded archive and quarantine samples, and preset falsifiers is feasible.","source_ids":["S4","S5","S6","S7"]},"no_unresolved_safety_or_authority_stop":{"status":"YES","reason":"For the proposed first step only, hard deletion is prohibited, holds are vetoes, the namespace is nonproduction, and an authorized registry Owner or Maintainer can halt and restore. This gate does not authorize production deletion.","source_ids":["S2","S3","S4","S6"]},"credible_cost_scope_and_range":{"status":"YES","reason":"Broad resource-equivalent bands are credible because native preview, policy, dependency-scan, audit, archive, and restore primitives bound the custom work. Exact labor rates, storage volume, and integration complexity remain assumptions disclosed in each band.","source_ids":["S3","S4","S5","S6","S7"]}},"next_evidence_step":"With a registry Owner/Maintainer and release/security observer, run a 30-day pilot in one nonproduction namespace containing at most 500 superseded artifacts. Randomly split or replay the same inventory through comparator A, the current age/tag rule, and comparator B, the dependency/hold-gated workflow. Keep both in dry-run mode initially; plant 10 known references spanning Kubernetes objects, CI rollback metadata, and digest-only consumers. Manually adjudicate every proposed candidate. Archive and restore up to 50 dependency-clear artifacts, requiring digest and manifest fidelity and restoration within 30 minutes; quarantine up to 50 but hard-delete none. Measure confirmed-safe stale bytes per operator-hour, obsolete artifacts returned in a fixed search task, false-safe and false-blocked classifications, hold violations, restore success and latency, and attempted use of quarantined artifacts. Falsify the problem if fewer than 50 artifacts or 10% of bytes are superseded and no obsolete artifact appears in the fixed search task. Falsify the intervention if it misses any planted or confirmed live reference, quarantines any held artifact, fails any sampled digest restore, does not beat age-only confirmed-safe byte yield per operator-hour by 20%, does not reduce obsolete search exposure by 25%, or exceeds age-only operator time by more than 25% without a compensating safety gain.","blocking_evidence":["No registry inventory establishes the candidate adopter's superseded-artifact count, byte share, access pattern, or search exposure.","Live deployments, rollback records, CI metadata, legal or investigation holds, and external digest consumers require proprietary organization data.","No named registry operator has committed personnel or authority to the pilot.","No direct evidence shows one deployed system combining heterogeneous dependency discovery, formal holds, quarantine, tombstones, and recurring archive-restore tests.","The completeness of external reference discovery cannot be established by registry metadata alone.","Organization-specific retention law, erasure duties, incident holds, recovery objectives, labor rates, and storage/retrieval costs remain unverified."],"research_disposition":"KNOWN_PRACTICE_DIFFUSION","world_novelty_boundary":"The bounded search establishes that registry lifecycle cleanup, previews, keep exceptions, dependency-aware Kubernetes cleanup, manifest reference checking, archival, restoration, and audit logging are established practices. It did not find a single source demonstrating the entire proposed cross-system composition or its claimed comparative performance. Absence from these eight sources is not evidence of world novelty. Patentability, freedom to operate, market size, realized impact, and exhaustive product or research coverage remain unmeasured.","arm":"SENTINEL","candidate_version":0,"controller_recommendation":{"action":"STOP_EMPIRICAL_RESEARCH_NEEDED","repairable":true,"material_progress_observed":true,"progress_targets":["Secure a named registry Owner/Maintainer and release/security observer for one nonproduction namespace.","Export an inventory of at most 500 artifacts with size, age, tags, manifests, deployment references, rollback references, and hold status.","Establish adjudicated ground truth including 10 planted live or digest-only references.","Demonstrate zero live-reference and zero hold violations during quarantine selection.","Restore every sampled archived artifact with identical digest and manifest within 30 minutes.","Show at least 20% higher confirmed-safe stale-byte yield per operator-hour than age-only cleanup.","Show at least 25% lower obsolete-artifact exposure in a fixed search task without more than 25% uncompensated operator-time growth."],"reason":"Web evidence verifies the problem and shows substantial established prior art, but the remaining incremental advantage depends on proprietary dependency and hold data plus live archive, restore, quarantine, and workflow measurements. Under the evaluation rule, that evidence requires fieldwork and therefore cannot be resolved by further bounded web search."}}