Initial tick fires immediately on start so first policy evaluation doesn't wait for the full interval on boot. The PolicyEvaluator subscribes to SchedulerTick events and invokes evaluate_all -> overdue discovery -> RotationScheduled fan-out. 3 specs verify boot-tick, periodic cadence, and clean stop(). |
||
|---|---|---|
| .. | ||
| api-security-scanner | ||
| binary-analysis-tool | ||
| credential-enumeration | ||
| credential-rotation-enforcer | ||
| dlp-scanner | ||
| docker-security-audit | ||
| sbom-generator-vulnerability-matcher | ||
| secrets-scanner | ||
| siem-dashboard | ||