Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
596 commits
Select commit Hold shift + click to select a range
3f520dd
feat(server): declare gRPC auth (mode + scope + role) at the handler,…
mrunalp May 27, 2026
6c7950d
ci(snap): add snap release pipeline (#1600)
drew May 27, 2026
63e3a8f
docs: refresh landing terminal demo and apply NVIDIA fern theme (#1615)
aschilling-nv May 28, 2026
5bcc462
build(macos): remove unused import of tracing::warn (#1619)
Cali0707 May 29, 2026
9b95281
chore: align .python-version with mise.toml (#1618)
Cali0707 May 29, 2026
5007042
feat(helm): add optional PostgreSQL backing store (#1579)
sauagarwa May 29, 2026
188b355
docs(config): update gateway config reference (#1624)
TaylorMutch May 29, 2026
7873f61
feat(flake): add Nix development shell (#1592)
SDAChess May 29, 2026
d01d106
refactor(proto): move phase and current_policy_version into status (#…
derekwaynecarr May 29, 2026
fb03e38
feat(python-sdk): support OIDC Bearer auth on SandboxClient (#1621)
mrunalp May 29, 2026
7d32bf9
fix(helm): vendor chart dependencies before release packaging (#1627)
TaylorMutch May 29, 2026
f1ed347
fix(driver-podman): bind gateway to 0.0.0.0 in rootless mode (#1623)
jewzaam May 29, 2026
f6d0fd1
docs(providers): note that ANTHROPIC_API_KEY requires an API account,…
mesutoezdil May 29, 2026
0f73d11
fix(podman): avoid host-gateway on macOS machines (#1637)
TaylorMutch May 29, 2026
7036dcf
chore(vm): generalize crate for multi-device PCIe passthrough (#1573)
cheese-head May 29, 2026
f1fc87e
fix(sandbox): trust exact declared private endpoints (#1560)
mjamiv May 29, 2026
e98ea3e
feat(policy): add agentic approval loop (#1528)
zredlined May 30, 2026
28ee296
fix(e2e): clean up temp files in sandbox-runner on exit (#1647)
mesutoezdil Jun 1, 2026
269dbc6
ci(kubernetes): add HA e2e workflow (#1598)
TaylorMutch Jun 1, 2026
5045b9c
ci(release): use bundled Z3 for macOS gateway build (#1658)
pimlock Jun 1, 2026
7cea9d9
fix(gateway): align package TLS bootstrap path (#1601)
TaylorMutch Jun 1, 2026
eb97fb3
feat(tui): add PageUp/PageDown scrolling to all panes (#1656)
major Jun 1, 2026
c63ac76
feat(telemetry): add anonymous opt-out OpenShell usage telemetry (#1433)
kirit93 Jun 1, 2026
2d78503
ci(release): gate helm/oci artifact publishing on release (#1662)
krishicks Jun 1, 2026
99ca85a
ci(kubernetes): stabilize HA e2e setup (#1659)
TaylorMutch Jun 1, 2026
019a986
fix(gateway): place supervisor_image under podman driver TOML table (…
jhjaggars Jun 1, 2026
29e2539
refactor: deduplicate shared utilities across driver crates (#1660)
ericcurtin Jun 1, 2026
3d441e7
fix(config): reject unknown fields in nested gateway config tables (#…
pimlock Jun 2, 2026
d990822
feat(kubernetes): support sandbox image pull secrets (#1671)
TaylorMutch Jun 2, 2026
79aa355
refactor(driver): trim compute capability response (#1402)
elezar Jun 2, 2026
f061b1d
feat(providers): add Google Vertex AI inference provider (#1568)
maxamillion Jun 2, 2026
ae5127f
fix: correct example paths in local-inference README (#1676)
mesutoezdil Jun 2, 2026
1d2d8c3
ci(release): bring Fedora RPM canary to parity (#1688)
krishicks Jun 2, 2026
8bf667f
fix: update RFC link in agent-driven-policy-management README (#1677)
mesutoezdil Jun 2, 2026
62c421b
feat(providers): add profile-backed policy visibility (#1640)
johntmyers Jun 3, 2026
61b33ea
ci(release): fix Ubuntu Snap canary install and registration (#1699)
krishicks Jun 3, 2026
19be568
feat(snap): add openshell.term desktop app (#1693)
zyga Jun 3, 2026
5102cb9
fix(sandbox): restore GPU procfs baseline (#1522)
elezar Jun 3, 2026
1f07bf0
fix(gateway): try harder to detect Podman (#1536)
krishicks Jun 3, 2026
427dacb
chore(mise): refresh tool lockfile (#1712)
krishicks Jun 3, 2026
b7ce0be
ci(release): authenticate snap canary artifact download (#1711)
krishicks Jun 3, 2026
1c8417c
docs(container-gateway): fix Docker driver setup for containerized ga…
ericcurtin Jun 3, 2026
d5b79e5
refactor(server): deduplicate test helpers and grpc utilities (#1708)
ericcurtin Jun 3, 2026
e4bcfdf
fix(gateway): allow local sandbox jwt to not expire (#1721)
TaylorMutch Jun 3, 2026
5f58cb0
fix(helm): create sandbox JWT secret when cert-manager is enabled (#1…
TaylorMutch Jun 3, 2026
5e32403
feat(k8s-driver): add default_runtime_class_name config for sandbox p…
sjenning Jun 3, 2026
b41e0df
docs: add Hermes Agent to supported agents (#1735)
shannonsands Jun 4, 2026
76d7453
fix(cli): roll back gateway registration when auth fails during gatew…
zanetworker Jun 4, 2026
69764d8
refactor: deduplicate shared driver and TUI helpers (#1741)
ericcurtin Jun 4, 2026
eea9751
feat(cli): support multiple --upload flags on sandbox create (#1635) …
feloy Jun 4, 2026
c26d4e8
fix(grpc): allow credential rotation when legacy provider.type exceed…
latenighthackathon Jun 4, 2026
a4014f7
fix(cli): respect gateway name for mTLS lookup (#1626)
alexclewontin Jun 4, 2026
79b77ca
chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#1739)
dependabot[bot] Jun 4, 2026
586c385
chore(k8s): use upstream agent-sandbox manifest in CI/e2e (#1657)
rmalani-nv Jun 4, 2026
884d4ed
fix(bootstrap): set docker build platform args (#1761)
shiju-nv Jun 4, 2026
e26a1b1
fix(kubernetes): configure sandbox apparmor profile (#1767)
TaylorMutch Jun 5, 2026
97986d9
fix(server): resume unspecified sandbox phase (#1765)
shiju-nv Jun 5, 2026
35afcf8
refactor(tui): extract shared setting edit overlay (#1776)
ericcurtin Jun 5, 2026
c3964a6
feat(kubernetes): support driver config passthrough (#1744)
elezar Jun 5, 2026
13e8318
fix(sandbox): stop log push after auth failure (#1787)
johntmyers Jun 5, 2026
b392b2e
feat(providersv2): add path auth_style (#1622)
Cali0707 Jun 6, 2026
3558888
refactor(tui): extract shared draw_text_field and draw_confirm_popup …
ericcurtin Jun 7, 2026
25abc9e
feat(inference): allow local embeddings route (#1774)
shiju-nv Jun 7, 2026
88b5f3d
test(cli): avoid browser launch in auth rollback test (#1808)
elezar Jun 8, 2026
f236279
docs: document DCO commit sign-off requirement (#1811)
elezar Jun 8, 2026
1399f37
refactor: deduplicate OCSF builder setters and persistence helpers (#…
ericcurtin Jun 8, 2026
1f5e123
feat(vm): add vm life cycle extensions (#1583)
cheese-head Jun 8, 2026
4da07f6
feat(cli): add generic output formatter to eliminate --output flag du…
jeffmaury Jun 8, 2026
7274a6b
feat(cli): add --env flag to sandbox create/exec and fix env var pass…
russellb Jun 8, 2026
4025894
chore(snap): remove early snap packaging (#1648)
zyga Jun 9, 2026
3a4463e
fix(cli): fall back to regular upload when git filtering excludes all…
russellb Jun 9, 2026
3aba30c
feat(telemetry): add build-time option to compile out telemetry (#1845)
russellb Jun 9, 2026
70acbaf
refactor(driver-utils): centralize container mount path constants (#1…
ericcurtin Jun 9, 2026
c4ca283
refactor(helm): require external postgres for ha (#1844)
TaylorMutch Jun 9, 2026
d2a522d
feat(snap): switch to prebuilt binaries shared with other packages (#…
zyga Jun 10, 2026
713d46c
feat(snap): expand snap description with setup instructions (#1695)
zyga Jun 10, 2026
27fd31c
fix(cli)!: require explicit gpu sandbox flag (#1835)
elezar Jun 10, 2026
84c24a0
fix(ocsf): widen the shorthand [reason:] budget so denial endpoints s…
latenighthackathon Jun 10, 2026
c1d3b43
fix(policy): classify advisory private-IP notes with the canonical is…
latenighthackathon Jun 10, 2026
702cbc4
feat(providers): support SPIFFE-backed token grants (#1784)
TaylorMutch Jun 10, 2026
9e805dc
fix(build): use zigbuild for musl supervisor staging (#1850)
elezar Jun 10, 2026
530aaf1
feat(drivers): support docker and podman config mounts (#1785)
drew Jun 10, 2026
d8e0ef5
fix(ci): pin snap artifact downloads to valid action (#1855)
drew Jun 10, 2026
4a7f8e7
fix(ci): use existing snap gateway wrapper (#1859)
elezar Jun 10, 2026
c5ce3ed
AGENTS.md: Add more detailed signoff guidance (#1852)
russellb Jun 10, 2026
42e7b80
feat(podman): make container health check interval configurable (#1833)
sshnaidm Jun 10, 2026
4b44d62
fix(helm): use stable gateway container name (#1864)
TaylorMutch Jun 10, 2026
7dab612
feat(helm): support Deployment kind in HA gateway workloads (#1867)
TaylorMutch Jun 10, 2026
1dc5985
feat(gpu): move device selection to driver config (#1815)
elezar Jun 11, 2026
b6c87a7
feat(server): add grpc rate limiting gateway-wide (#1566)
alangou Jun 11, 2026
58a3777
fix(drivers): filter bind-backed named volumes (#1861)
elezar Jun 11, 2026
f33fd02
fix(server): use public tonic body type in gRPC rate limiter (#1872)
alangou Jun 11, 2026
e73745f
feat(gateway): add reconciler lease for HA multi-replica deployments …
derekwaynecarr Jun 11, 2026
fb83d1a
feat(gateway): add system registry support and source indicators (#1625)
alexclewontin Jun 11, 2026
21ff5db
ci(stale): add stale issue and PR workflow (#1890)
TaylorMutch Jun 12, 2026
ec197a4
fix(e2e): correct return type of _stub_with_token (#1897)
mesutoezdil Jun 13, 2026
6c8cf38
ci(docs): add docs website automation (#1788)
pimlock Jun 15, 2026
8c01534
test(e2e): add GPU workload image artifacts (#1484)
elezar Jun 15, 2026
62aa5e3
ci(branch-checks): align Python checks with pre-commit (#1908)
TaylorMutch Jun 15, 2026
ac3bb63
docs(rfc): improve template and add creation skill (#1889)
krishicks Jun 15, 2026
1ca23bc
refactor(openshell-sandbox): Split `sandbox` into `process` and `netw…
rrhubenov Jun 15, 2026
ed65bfd
feat(cli): add JSON/YAML output format to provider list command (#1830)
jeffmaury Jun 15, 2026
ec71b1a
fix(sandbox): apply initial OCSF JSON setting (#1921)
TaylorMutch Jun 16, 2026
f4a5005
chore(deps): bump astral-sh/setup-uv from 8.0.0 to 8.2.0 (#1926)
dependabot[bot] Jun 16, 2026
294c64e
fix(gpu): prefer single CDI devices for local runtimes (#1675)
elezar Jun 16, 2026
fd6cbf6
fix(server): retry sandbox delete phase conflicts (#1905)
TaylorMutch Jun 16, 2026
ff028ce
feat(server): support TLS certificate hot-reload (#1870)
lunarwhite Jun 16, 2026
36bb9e3
feat(providers): add DeepInfra as a built-in inference provider (#1902)
mmilutinovic371 Jun 16, 2026
5ca39b0
docs(rfc): require issues before RFCs (#1918)
drew Jun 16, 2026
f1245a3
test(e2e): retry transient forward proxy stale policy responses (#1929)
drew Jun 17, 2026
4c75b85
fix(server): share gateway shutdown channel (#1945)
elezar Jun 17, 2026
234e69d
fix(e2e): refresh latest sandbox image for docker runs (#1928)
krishicks Jun 17, 2026
f5e109a
feat: build CLI during pull request (#1491)
jeffmaury Jun 17, 2026
70fed04
fix(helm): build chart dependencies before lint (#1947)
elezar Jun 17, 2026
f23c2c8
test(e2e): remove python gpu smoke test (#1948)
elezar Jun 17, 2026
ed24031
chore(deps): bump softprops/action-gh-release from 3.0.0 to 3.0.1 (#1…
dependabot[bot] Jun 22, 2026
8d02733
docs(agents): document stale Helm subchart cleanup (#1957)
elezar Jun 22, 2026
ce788b5
chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#1960)
dependabot[bot] Jun 22, 2026
b6428cb
fix(build): align container engine selection (#1944)
elezar Jun 22, 2026
b689c82
fix(python): add encoding=utf-8 to file reads and writes in sandbox.p…
mesutoezdil Jun 22, 2026
f084eb3
fix(sbom): release lock before sleeping in _rate_limit (#1896)
mesutoezdil Jun 22, 2026
ffc102a
fix(cli): verify forward listener before success (#1880)
shiju-nv Jun 22, 2026
82d03f1
fix(linux): lower host glibc floor to 2.28 to support RHEL/Rocky 8 (#…
pimlock Jun 22, 2026
85c52bb
fix(sbom): handle SPDX expression licenses in extract_licenses (#1898)
mesutoezdil Jun 22, 2026
d64542f
fix(supervisor-network): block h2c L7 tunnel escape (#1967)
ddurst-nvidia Jun 22, 2026
48a7d09
feat(providers): support profile updates (#1914)
johntmyers Jun 23, 2026
48545cf
feat(sandbox): add GCE metadata emulator for Google Cloud (#1763)
p5 Jun 23, 2026
4ee27d9
feat(sandbox,providers): add aws-bedrock as a recognized inference pr…
st-gr Jun 23, 2026
8e831f3
fix(ci): fix linting issues (#1985)
TaylorMutch Jun 24, 2026
2c54589
feat(cli): add GPU count requests (#1812)
elezar Jun 24, 2026
62b03f0
fix(docs): add step for creating the GatewayClass (#1984)
zhaohuabing Jun 24, 2026
c7879a0
test(e2e): stop using custom e2e binary builds (#2000)
SDAChess Jun 25, 2026
c636e70
fix(e2e): make postgres fixture compatible with OpenShift (#2002)
sjenning Jun 25, 2026
d93293a
fix(e2e): stabilize local Docker smoke test (#1935)
elezar Jun 25, 2026
e4d7d41
fix(snap): use snap-owned XDG directories (#1972)
pimlock Jun 25, 2026
3ace968
chore(deps): bump azure/setup-helm from 5.0.0 to 5.0.1 (#1996)
dependabot[bot] Jun 25, 2026
f2ecadf
refactor(cli): replace sandbox_create positional args with SandboxCre…
lunarwhite Jun 26, 2026
75a317e
feat(server): support out-of-tree compute drivers via --compute-drive…
st-gr Jun 26, 2026
e3382cb
fix(server): update driver spec test argument (#2022)
elezar Jun 26, 2026
7ea471c
chore(deps): remove unused regorus yaml feature (#2021)
elezar Jun 26, 2026
a242f84
chore(gitignore): ignore nix result links (#2020)
elezar Jun 26, 2026
b855d8d
fix(policy): reserve provider rule namespace (#1991)
johntmyers Jun 26, 2026
4b78b44
fix(openshell-network-supervisor): gate proxy accept on symlink resol…
Cali0707 Jun 26, 2026
f569a0a
feat(sandbox): proxy-side AWS SigV4 credential signing for CONNECT tu…
jhjaggars Jun 26, 2026
ba21bb3
feat(kubernetes): support agent-sandbox v1beta1 (#2009)
TaylorMutch Jun 26, 2026
45e5a5d
fix(server): prevent exec relays from hanging on idle connections (#1…
Gal-Zaidman Jun 26, 2026
7e0cce4
fix(build): use zig archive tools for cross builds (#2014)
TaylorMutch Jun 26, 2026
8c78459
fix(python): include generated proto stubs in Linux wheels (#2029)
maxdubrinsky Jun 26, 2026
7bce122
feat(policy): add JSON-RPC and MCP L7 policies (#1865)
krishicks Jun 26, 2026
d1ef777
chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#2038)
dependabot[bot] Jun 29, 2026
c7202af
chore(deps): bump actions/attest from 4.1.0 to 4.1.1 (#2037)
dependabot[bot] Jun 29, 2026
8cb16de
chore(deploy): use OCI registry for cert-manager Helm chart (#2041)
lunarwhite Jun 29, 2026
afc06dd
fix(supervisor): drop sandbox child capability bounding set (#2001)
alangou Jun 29, 2026
a5161d0
refactor(server): normalize compute driver config acquisition (#1974)
elezar Jun 29, 2026
a226806
test(e2e): run gpu workloads from manifest (#1709)
elezar Jun 30, 2026
f27ff15
fix(providers): reserve credential placeholder revisions (#2049)
johntmyers Jun 30, 2026
474d2d4
fix(CONTRIBUTING): update label format for good first issues (#2056)
jgarciao Jun 30, 2026
ed0026a
fix(helm): generate namespace-aware SANs in certgen and cert-manager …
akram Jun 30, 2026
0a25fdf
refactor(core): remove unused extra bind addresses (#2059)
elezar Jun 30, 2026
5477e2f
docs(mcp): fix granular policy lifecycle examples (#2066)
shiju-nv Jun 30, 2026
914da33
feat(kubernetes): add combined topology config surface (#2074)
TaylorMutch Jun 30, 2026
450685c
fix(drivers): reject whitespace in mount fields (#2086)
elezar Jul 1, 2026
45614a3
refactor(api): remove SandboxTemplate.volume_claim_templates (#2088)
elezar Jul 1, 2026
abcd15d
feat(helm): add TLS termination for Envoy Gateway ingress (#2015)
zhaohuabing Jul 1, 2026
45060f4
feat(agents): add manifest-driven gator agent (#1826)
johntmyers Jul 1, 2026
43bb030
feat(docker,podman): add SELinux label support for bind mounts (#2092)
bergmannf Jul 2, 2026
5f9bf9c
test(e2e): run rootless podman on ubuntu host (#2119)
elezar Jul 2, 2026
6461677
feat(policy): accept numeric UIDs for sandbox process identity (#1973)
sjenning Jul 2, 2026
f852d07
docs: add Hermes Agent to supported agents table (#2131)
mesutoezdil Jul 3, 2026
6252aa1
rfc-0006: add driver config passthrough proposal (#1589)
elezar Jul 6, 2026
31807d6
chore(deps): bump docker/login-action from 4.2.0 to 4.4.0 (#2146)
dependabot[bot] Jul 6, 2026
5656240
docs: fix STYLEGUIDE heading to match filename (#2134)
mesutoezdil Jul 6, 2026
290297f
docs(kubernetes): bump cert-manager to v1.20.3 (#2129)
mesutoezdil Jul 6, 2026
9c14de7
docs: fix article before OpenShell in sync-files (#2133)
mesutoezdil Jul 6, 2026
eba5dd7
docs: warn to redact credentials from log output before sharing (#2124)
elezar Jul 6, 2026
abe42fb
fix(podman): deliver sandbox JWTs as secrets (#2156)
maxamillion Jul 6, 2026
a727116
chore: remove deprecated --keep flag from docs, scripts, and e2e test…
Ygnas Jul 7, 2026
f7aa3aa
chore(deps): bump astral-sh/setup-uv from 8.2.0 to 8.3.0 (#2160)
dependabot[bot] Jul 7, 2026
2e2b497
fix(driver-podman): gate Linux-only Path import (#2188)
krishicks Jul 8, 2026
ed8ce82
docs: fix Docker version format from 28.04 to 28.0 (#2136)
mesutoezdil Jul 8, 2026
5207f11
docs: update man page date to 2026 (#2135)
mesutoezdil Jul 8, 2026
ff9af8e
fix(sandbox): acknowledge initial policy revision; expose SDK labels/…
KyleZheng1284 Jul 9, 2026
709aa0f
chore(deps): bump astral-sh/setup-uv from 8.3.0 to 8.3.1 (#2191)
dependabot[bot] Jul 9, 2026
83131d7
feat(cli): add --secret-material-env to provider refresh configure (#…
hunglp6d Jul 9, 2026
8871022
docs(telemetry): Added first telemetry report for the community (#2190)
kirit93 Jul 9, 2026
4970108
change packit target to new correct copr project (#2185)
maxamillion Jul 9, 2026
420a855
test(supervisor-network): add proxy hostname parser regression tests …
shaneutt Jul 9, 2026
5f38b7c
fix(tui): route warning logs to status bar instead of stderr (#2210)
r3v5 Jul 10, 2026
ccdac9c
fix(mcp): include tool names in policy logs (#2189)
kirit93 Jul 10, 2026
caaa516
chore(deps): bump astral-sh/setup-uv from 8.3.1 to 8.3.2 (#2206)
dependabot[bot] Jul 10, 2026
8c0ecac
docs(openshift): simplify install steps and add Helm README entries f…
ChristianZaccaria Jul 10, 2026
233d207
docs(issues): require release and duplicate checks (#2214)
elezar Jul 10, 2026
1070213
fix(core): pin supervisor image tag to gateway version for all driver…
benoitf Jul 10, 2026
bebf440
fix(helm): propagate supervisor image overrides (#2216)
TaylorMutch Jul 10, 2026
8eacb47
feat(kubernetes): add sidecar supervisor topology (#2076)
TaylorMutch Jul 10, 2026
614c8c1
feat(kubernetes): support PVC subPath driver config (#2034)
mjamiv Jul 10, 2026
40194f9
fix(network): fail closed when credential placeholders cannot be rewr…
TonyLuo-NV Jul 11, 2026
bb72d01
fix(server): allow newlines in exec command arguments (#1965)
zanetworker Jul 13, 2026
94cdd69
chore(deps): bump actions/stale from 10.3.0 to 10.4.0 (#2234)
dependabot[bot] Jul 13, 2026
88f2656
fix(tui): redraw after sandbox shell exits (#2230)
johntmyers Jul 13, 2026
0fe24a4
fix(agents): add confirmation gate to triage-issue batch mode (#2239)
rhuss Jul 13, 2026
9ad53b3
fix(gator): retry review after draft blocker clears (#2200)
johntmyers Jul 13, 2026
4e1ffef
fix(certgen): stage temp dir inside output dir to fix cross-device re…
gracesmith6504 Jul 13, 2026
fcc9db3
refactor(jsonrpc): carry typed inspection errors (#2244)
shiju-nv Jul 13, 2026
ee9b455
docs(agents): add gator launch skill (#2203)
johntmyers Jul 13, 2026
df06286
chore(python): lower minimum supported Python to 3.11 (#2247)
maxdubrinsky Jul 13, 2026
e3d26dd
fix(policy): keep approved chunk when a mechanistic denial resubmits …
laitingsheng Jul 13, 2026
97e1051
fix(tasks): format all Rust workspaces (#2268)
krishicks Jul 14, 2026
a41cd12
docs: fix stray bracket in provider create command example (#2275)
mesutoezdil Jul 14, 2026
96fd31f
rfc-0010: gateway interceptors (#1927)
drew Jul 14, 2026
e8c16eb
fix(release-dev): update azure/setup-helm to v5.0.1 (#2274)
krishicks Jul 14, 2026
994750e
feat(snap): vendor ssh in openshell snap and remove ssh-keys interfac…
olivercalder Jul 15, 2026
83003e8
feat(interceptors): initial gateway interceptor implementation and re…
drew Jul 15, 2026
e6f319c
feat(sdk): add openshell-sdk crate (#1862)
maxdubrinsky Jul 15, 2026
8029321
fix(sdk): initialize sandbox annotations (#2296)
drew Jul 15, 2026
392ad63
fix(driver-vm): run sandbox supervisor as guest pid 1 (#2299)
drew Jul 15, 2026
b4be33e
feat(ci): introduce merge queue (#2024)
elezar Jul 15, 2026
21aaa89
feat(gateway): add elevated gateway info (#2202)
elezar Jul 15, 2026
3dee557
fix(ci): prune snap assets from dev release (#2302)
pimlock Jul 15, 2026
dd3f27c
feat!(openshell-cli): remove openshell policy prove command and z3 de…
SDAChess Jul 16, 2026
077adb7
fix(server): persist sandbox labels on create (#2306)
matthewgrossman Jul 16, 2026
008193a
fix: remove mentions of bundled-z3 in CI and wheel builds (#2322)
SDAChess Jul 16, 2026
cf4decc
fix(gateway): probe Docker socket during driver auto-detection (#2303)
krishicks Jul 16, 2026
1a0c101
chore(deps): bump actions/setup-node from 6.4.0 to 7.0.0 (#2289)
dependabot[bot] Jul 16, 2026
fe7135a
chore(deps): bump softprops/action-gh-release from 3.0.1 to 3.0.2 (#2…
dependabot[bot] Jul 16, 2026
d0961cd
feat(tui): navigate panels via Up/Down arrow overflow at list boundar…
varshaprasad96 Jul 16, 2026
aa483ec
feat(providers): AWS STS AssumeRole refresh strategy and aws-s3 profi…
russellb Jul 16, 2026
32f0524
rfc-0009: supervisor middleware (#1738)
pimlock Jul 16, 2026
5402551
test(e2e): run VM suite in CI (#2305)
drew Jul 16, 2026
d70adaf
fix(vm-driver): fixes BYOC sandbox creation failing with ext4-fs writ…
bornav Jul 17, 2026
d556748
feat(supervisor-middleware): add network egress middleware (#2027)
pimlock Jul 17, 2026
0606202
docs(gator): require inline review comments (#2346)
johntmyers Jul 17, 2026
98f253b
fix(cli): preserve symlinks in sandbox upload (#2319)
loveRhythm1990 Jul 17, 2026
1fd4d2b
fix(kubernetes): validate sandbox names against RFC 1123 requirements…
2000krysztof Jul 17, 2026
8cf2673
docs: bump stated Rust MSRV from 1.88 to 1.90 (#2276)
mesutoezdil Jul 17, 2026
9a4f8a8
ci: pin docker actions to commit SHA (#2328)
mesutoezdil Jul 20, 2026
339eae5
ci(e2e): reuse prebuilt CLI and gateway artifacts (#2311)
elezar Jul 20, 2026
80987e9
docs: fix broken links and small inconsistencies (#2329)
mesutoezdil Jul 20, 2026
a2cd5f8
fix(gateway): honor tty flag for interactive exec (#2315)
emonq Jul 20, 2026
a9f7131
fix(ci): grant E2E permissions to release workflows (#2376)
pimlock Jul 20, 2026
f32c46d
chore(ci): pin pr gate action (#2368)
elezar Jul 20, 2026
2575585
chore(deps): bump actions/attest from 4.1.1 to 4.2.0 (#2357)
dependabot[bot] Jul 20, 2026
9377e0d
fix(providers): allow git clone/fetch via default GitHub provider (#2…
russellb Jul 20, 2026
745512e
fix(build): raise open-file limit for host musl cross-compile on macO…
purp Jul 20, 2026
ad29ab9
fix(supervisor-network): warn on unsupported L7 access presets (#2177)
lunarwhite Jul 21, 2026
5952a5a
feat(workspace): add workspace resource model with scoping, membershi…
derekwaynecarr Jul 21, 2026
f169084
fix(supervisor): tailor Landlock rights by inode type (#2380)
drew Jul 21, 2026
8d9502d
perf(build): share sccache across worktrees (#2379)
matthewgrossman Jul 21, 2026
d44dde2
Merge remote-tracking branch 'upstream/main' into chore/force-sync-up…
ashsolei Jul 21, 2026
81bf111
chore: re-apply iAiFy overlay after upstream force-sync
ashsolei Jul 21, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
51 changes: 51 additions & 0 deletions .agents/skills/create-rfc/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
---
name: create-rfc
description: Create OpenShell RFC proposals in rfc/ from a design request. Use when the user asks to write, draft, start, create, or update an RFC, Request for Comments, architecture proposal, API proposal, process proposal, or cross-cutting design proposal that should follow the OpenShell RFC process and template.
---

# Create RFC

## Workflow

Create RFCs by following `rfc/README.md` and `rfc/0000-template/README.md`.
Keep the template as the source of truth for section guidance.

1. Read `rfc/README.md` to confirm when an RFC is appropriate, how to choose the
RFC number, and how the lifecycle works.
2. Read `rfc/0000-template/README.md` before drafting. Follow its section
guidance, including scope, expected detail, and suggested section length.
3. Choose the next available `NNNN` from the existing `rfc/NNNN-*` directories
unless the user provided a specific number.
4. Create `rfc/NNNN-short-title/README.md` by copying the template and replacing
placeholders. Use a short hyphenated folder title.
5. Fill in front matter with the RFC author, `state: draft`, and any related
links the user provided. If the author is unknown, use the requesting user's
GitHub handle when available or leave the template placeholder.
6. Draft each section from the user's design context. Keep Summary concise,
Motivation readable by anyone, Non-goals explicit, Proposal focused on what
is being proposed, and Alternatives focused on credible competing approaches.
7. Preserve uncertainty in Open questions instead of silently deciding unknowns.
If a missing decision blocks a coherent RFC, ask the user for that decision.
8. Check the completed RFC against the template once more before finishing.

## Writing Standards

- Prefer concrete design statements over placeholder language.
- Link to relevant issues, prior RFCs, and architecture docs when they provide
needed context.
- Keep rejected or left-out designs in Alternatives, not Proposal.
- Use Mermaid diagrams for architecture or data flow when a diagram would make
the proposal easier to review.
- Do not update `architecture/` or published docs just because an RFC was
drafted. Those updates belong with implementation or with an accepted RFC when
the user asks for them.

## Validation

Before handing the RFC back to the user:

- Verify the folder name and RFC number match the process in `rfc/README.md`.
- Verify every template section is present or intentionally marked as not
applicable.
- Run a Markdown formatting or lint check only if the repo already provides one
for Markdown-only changes.
4 changes: 4 additions & 0 deletions .agents/skills/create-rfc/agents/openai.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
interface:
display_name: "Create RFC"
short_description: "Create OpenShell RFC proposals"
default_prompt: "Use $create-rfc to draft an OpenShell RFC from this design."
568 changes: 258 additions & 310 deletions .agents/skills/debug-openshell-cluster/SKILL.md

Large diffs are not rendered by default.

282 changes: 282 additions & 0 deletions .agents/skills/helm-dev-environment/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,282 @@
---
name: helm-dev-environment
description: Start up, tear down, and configure the local Kubernetes development environment for OpenShell. Uses k3d (Docker-backed k3s) + Skaffold + Helm. Covers cluster lifecycle, optional add-ons (Keycloak OIDC, Envoy Gateway), HA testing, and port mappings. Trigger keywords - local k8s, local cluster, k3d, skaffold, helm dev, start cluster, stop cluster, tear down cluster, delete cluster, create cluster, helm:k3s, helm:skaffold, local dev environment, dev cluster, k8s dev, envoy gateway local, keycloak local, high availability, HA.
---

# Helm Dev Environment

Set up, run, and tear down the local Kubernetes development environment for OpenShell.
The stack is: **k3d** (Docker-backed k3s) for the cluster, **Skaffold** for image builds and Helm deploys, and the **OpenShell Helm chart** (`deploy/helm/openshell/`).

---

## Prerequisites

- Docker Desktop (macOS) or Docker Engine (Linux) running
- `mise install` completed (provides `k3d`, `kubectl`, `skaffold`, `helm`)

---

## Startup

### 1. Create the cluster

```bash
mise run helm:k3s:create
```

Creates a k3d cluster and merges its kubeconfig into the worktree-local `kubeconfig` file.
Also applies the upstream agent-sandbox CRDs/controller (pinned via `AGENT_SANDBOX_VERSION`
in `tasks/scripts/helm-k3s-local.sh`, fetched from `github.com/kubernetes-sigs/agent-sandbox`
releases) and preloads the default community sandbox image into k3d so the first sandbox
create does not wait on a large registry pull. Traefik is disabled at cluster creation time.

**Multi-worktree support:** the cluster name is derived from the last component of the
current git branch (e.g. branch `kube-support/local-dev/tmutch` → cluster
`openshell-dev-tmutch`). Each worktree therefore gets its own isolated cluster and its
own `kubeconfig` file. Override with `HELM_K3S_CLUSTER_NAME` to force a specific name
or share one cluster across worktrees.

Port mappings created at cluster time (cannot be changed without recreating):

| Host port | Target | Used by |
|-----------|--------|---------|
| `8080` | Port `80` via k3d load balancer | Envoy Gateway LoadBalancer service (`values-gateway.yaml`) |

Override with env vars before running `helm:k3s:create`:
- `HELM_K3S_LB_HOST_PORT` (default: `8080`)
- `HELM_K3S_PRELOAD_SANDBOX_IMAGE` (default:
`ghcr.io/nvidia/openshell-community/sandboxes/base:latest`; set to an empty value to skip)

### 2. Deploy OpenShell

**Iterative dev** (rebuilds on file changes, recommended during active development):
```bash
mise run helm:skaffold:dev
```

**One-shot deploy** (build once and leave running):
```bash
mise run helm:skaffold:run
```

**Supervisor sidecar topology** (build once and leave running):
```bash
mise run helm:skaffold:run:sidecar
```

**Supervisor sidecar topology with TLS/mTLS enabled** (build once and leave running):
```bash
mise run helm:skaffold:run:sidecar-mtls
```

Both commands build the `gateway` and `supervisor` images and deploy the OpenShell Helm
chart. The sidecar profile renders an `openshell-network-init` init container for
nftables setup and an `openshell-supervisor-network` runtime sidecar for proxying.
Binary-aware policy mode runs that sidecar as UID 0 with `SYS_PTRACE` and
`DAC_READ_SEARCH`; relaxed mode can run it as the configured proxy UID. The
sidecar-mTLS profile reuses `ci/values-sidecar.yaml` and restores
`server.disableTls=false` inline for Skaffold. The `pkiInitJob` hook (a pre-install
Job that runs `openshell-gateway generate-certs`) generates mTLS secrets on first
install. Envoy Gateway opt-in; see the Optional Add-ons section below.

The gateway Service uses ClusterIP. Access is via Envoy Gateway (port `8080`) or `kubectl port-forward`.

**HA test deploy** (two gateway replicas + external PostgreSQL Secret): uncomment
`#- ci/values-high-availability.yaml` in `deploy/helm/openshell/skaffold.yaml`,
create the Secret named `openshell-ha-pg` with a `uri` key, then run
`mise run helm:skaffold:run` or `mise run helm:skaffold:dev`.

### TLS behaviour

`ci/values-skaffold.yaml` sets `server.disableTls: true`, so Skaffold-based deploys run
plaintext by default. To test sidecar topology with TLS enabled, use
`mise run helm:skaffold:run:sidecar-mtls`.

| Mode | `server.disableTls` | Gateway scheme |
|------|---------------------|----------------|
| Skaffold dev (default) | `true` | `http://` |
| TLS enabled | `false` (or omitted) | `https://` |

### Connecting via port-forward

Port `8080` is already bound by the k3d load balancer when Envoy Gateway is active, so
the port-forward uses local port `8090` to avoid a collision:

```bash
KUBECONFIG=kubeconfig kubectl port-forward -n openshell svc/openshell 8090:8080
```

**Plaintext (default Skaffold deploy):**

```bash
openshell sandbox list --gateway-endpoint http://localhost:8090
```

**With mTLS enabled** — extract the client cert the PKI hook wrote to the cluster,
then place it where the CLI expects it. Run once after each fresh install:

```bash
mkdir -p ~/.config/openshell/gateways/openshell/mtls
KUBECONFIG=kubeconfig kubectl get secret openshell-client-tls -n openshell \
-o jsonpath='{.data.ca\.crt}' | base64 -d > ~/.config/openshell/gateways/openshell/mtls/ca.crt
KUBECONFIG=kubeconfig kubectl get secret openshell-client-tls -n openshell \
-o jsonpath='{.data.tls\.crt}' | base64 -d > ~/.config/openshell/gateways/openshell/mtls/tls.crt
KUBECONFIG=kubeconfig kubectl get secret openshell-client-tls -n openshell \
-o jsonpath='{.data.tls\.key}' | base64 -d > ~/.config/openshell/gateways/openshell/mtls/tls.key
```

The server cert SANs include `localhost` and `127.0.0.1`, so hostname verification
passes over a port-forward without any extra flags:

```bash
openshell sandbox list --gateway-endpoint https://localhost:8090
```

---

## Teardown

### Remove the Helm releases (keep cluster)

```bash
mise run helm:skaffold:delete
```

For a sidecar-profile deployment:

```bash
mise run helm:skaffold:delete:sidecar
```

### Delete the cluster entirely

```bash
mise run helm:k3s:delete
```

This removes the k3d cluster and all resources. Kubeconfig context is left behind
but will point to a deleted cluster — safe to ignore or clean up manually.

---

## Optional Add-ons

Each add-on requires uncommenting the corresponding `valuesFiles` entry in
`deploy/helm/openshell/skaffold.yaml` before running `helm:skaffold:dev` or `helm:skaffold:run`.

### Envoy Gateway (Gateway API / GRPCRoute)

Envoy Gateway is already installed by Skaffold (the `envoy-gateway` Helm release in
`skaffold.yaml`). To activate routing:

1. Uncomment `#- values-gateway.yaml` in `skaffold.yaml`
2. Redeploy: `mise run helm:skaffold:run`
3. Apply the GatewayClass: `mise run helm:gateway:apply`
4. Access: `http://127.0.0.1:8080`

`values-gateway.yaml` creates a `Gateway` (listener on port 80, class `eg`) and a
`GRPCRoute` in the `openshell` namespace. Envoy Gateway provisions a LoadBalancer
service for the proxy; klipper-lb binds it to hostPort 80, reachable via the
`8080:80` load balancer port mapping.

### Keycloak OIDC

One-time setup — only needed once per cluster lifetime:

```bash
mise run keycloak:k8s:setup
```

This deploys Keycloak (`quay.io/keycloak/keycloak:24.0`) into the `keycloak` namespace,
imports the openshell realm from `scripts/keycloak-realm.json`, and prints a port-forward
command for acquiring tokens from the CLI.

Then activate OIDC in the OpenShell Helm chart:
1. Uncomment `#- ci/values-keycloak.yaml` in `skaffold.yaml`
2. Redeploy: `mise run helm:skaffold:run`

To remove Keycloak:
```bash
mise run keycloak:k8s:teardown
```

### SPIRE / SPIFFE Provider Token Grants

Skaffold can install SPIRE with the SPIFFE hardened Helm charts. To activate
SPIFFE JWT-SVIDs for dynamic provider token grants:

1. Uncomment the `spire-crds` and `spire` releases in `deploy/helm/openshell/skaffold.yaml`
2. Uncomment `#- ci/values-spire.yaml` in the OpenShell release values files
3. Redeploy: `mise run helm:skaffold:run`

`ci/values-spire-stack.yaml` configures the local SPIRE trust domain as
`openshell.local` and adds a `ClusterSPIFFEID` that maps sandbox pod
annotations to `spiffe://openshell.local/openshell/sandbox/<sandbox-id>`.
OpenShell mounts the SPIFFE CSI Workload API socket at
`/spiffe-workload-api/spire-agent.sock` into sandbox pods for provider token
grants. Supervisor-to-gateway authentication remains on the Kubernetes
ServiceAccount bootstrap and gateway-minted sandbox JWT path.

---

## Cluster Lifecycle (suspend/resume)

Stop the cluster without losing state (faster than delete/recreate):
```bash
mise run helm:k3s:stop
mise run helm:k3s:start
```

Check cluster status:
```bash
mise run helm:k3s:status
```

---

## Helm Chart Checks

Run the chart lint task before changing Helm templates, values overlays, or
Skaffold inputs:

```bash
mise run helm:lint
```

If Helm reports missing chart dependencies, remove the specific stale subchart
archive or directory named by the error from `deploy/helm/openshell/charts/`,
then rerun the lint task.

For example, when lint reports `chart metadata is missing these dependencies:
postgresql`, remove stale PostgreSQL chart artifacts:

```bash
rm -f deploy/helm/openshell/charts/postgresql-*.tgz
rm -rf deploy/helm/openshell/charts/postgresql
mise run helm:lint
```

The `charts/` directory is ignored and regenerated by `helm dependency build`
for dependencies still declared in `Chart.yaml`.

---

## Key Files

| Path | Purpose |
|------|---------|
| `deploy/helm/openshell/skaffold.yaml` | Skaffold config — images, Helm releases, values overlays |
| `deploy/helm/openshell/values.yaml` | Default Helm values |
| `deploy/helm/openshell/ci/values-skaffold.yaml` | Dev overrides (image pull policy, TLS disabled for local Skaffold) |
| `deploy/helm/openshell/ci/values-cert-manager.yaml` | cert-manager PKI overlay (opt-in; disables pkiInitJob) |
| `deploy/helm/openshell/ci/values-gateway.yaml` | Envoy Gateway GRPCRoute + Gateway overlay |
| `deploy/helm/openshell/ci/values-high-availability.yaml` | HA test overlay (`replicaCount: 2` with external PostgreSQL Secret) |
| `deploy/helm/openshell/ci/values-keycloak.yaml` | Keycloak OIDC overlay |
| `deploy/helm/openshell/ci/values-sidecar.yaml` | Supervisor sidecar topology overlay for Kubernetes e2e/dev |
| `deploy/helm/openshell/ci/values-spire.yaml` | SPIFFE/SPIRE provider token grant overlay |
| `deploy/helm/openshell/ci/values-spire-stack.yaml` | SPIRE hardened chart values for local dev |
| `deploy/helm/openshell/ci/values-tls-disabled.yaml` | Lint-only: TLS + auth disabled (reverse-proxy edge termination) |
| `deploy/kube/manifests/envoy-gateway-openshell.yaml` | GatewayClass for Envoy Gateway (`mise run helm:gateway:apply`) |
| `tasks/scripts/helm-k3s-local.sh` | k3d cluster create/delete/start/stop/status |
| `tasks/scripts/keycloak-k8s-setup.sh` | Keycloak deploy + realm import |
Loading
Loading