Skip to content

feat(api): add cron-based scan schedule data layer - #10094

Closed
vicferpoy wants to merge 4 commits into
PROWLER-1098-cron-based-scan-schedulingfrom
PROWLER-1099-api-scan-schedule-model-provider-fk-migration
Closed

vicferpoy wants to merge 4 commits into
PROWLER-1098-cron-based-scan-schedulingfrom
PROWLER-1099-api-scan-schedule-model-provider-fk-migration

Conversation

@vicferpoy

Copy link
Copy Markdown
Contributor

Context

This PR starts the scheduling redesign by introducing the data layer for cron-based scan scheduling in a multi-tenant setup.

Current scheduling was implemented quickly for product needs and is hard to evolve.
This change lays the foundation for custom cron schedules while keeping current behavior intact for now (no API/runtime behavior changes yet).

Description

This PR implements phase 1 (models + migration + validation) for cron scheduling:

  • Adds new ScanSchedule model (RLS, tenant-scoped)
  • Adds strict 5-field cron validator (UTC-oriented)
  • Adds Provider.scan_schedule as nullable FK to enforce real 1:N scheduling assignment.
  • Adds Scan.scan_schedule as nullable FK for traceability.
  • Adds migration 0079_scan_schedule.py that:
    • creates ScanSchedule,
    • adds new FKs on Provider and Scan,
    • backfills valid active legacy daily tasks (scan-perform-scheduled) into ScanSchedule,
    • links provider + related scheduled scans,
    • keeps reverse migration as noop (forward-oriented migration),
    • runs with atomic = False.
  • Adds validator tests.

Notes:

  • ScanSchedule intentionally has no name field in this PR.
  • No functional changes yet to /schedules/daily, tasks/beat.py, tasks/tasks.py, UI, or MCP.

Checklist

Community Checklist
  • This feature/issue is listed in here or roadmap.prowler.com
  • Is it assigned to me, if not, request it via the issue/feature in here or Prowler Community Slack

SDK/CLI

  • Are there new checks included in this PR? Yes / No
    • If so, do we need to update permissions for the provider? Please review this carefully.

UI

  • All issue/task requirements work as expected on the UI
  • Screenshots/Video of the functionality flow (if applicable) - Mobile (X < 640px)
  • Screenshots/Video of the functionality flow (if applicable) - Table (640px > X < 1024px)
  • Screenshots/Video of the functionality flow (if applicable) - Desktop (X > 1024px)
  • Ensure new entries are added to CHANGELOG.md, if applicable.

API

  • All issue/task requirements work as expected on the API
  • Endpoint response output (if applicable)
  • EXPLAIN ANALYZE output for new/modified queries or indexes (if applicable)
  • Performance test results (if applicable)
  • Any other relevant evidence of the implementation (if applicable)
  • Verify if API specs need to be regenerated.
  • Check if version updates are required (e.g., specs, Poetry, etc.).
  • Ensure new entries are added to CHANGELOG.md, if applicable.

License

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@vicferpoy
vicferpoy requested a review from a team February 17, 2026 10:22
@vicferpoy vicferpoy added the no-changelog Skip including change in changelog/release notes label Feb 17, 2026
@vicferpoy vicferpoy closed this Apr 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-changelog Skip including change in changelog/release notes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant