Conversation
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
4ee9a55 to
9083078
Compare
e5d257d to
db1070b
Compare
|
🌿 Preview your docs: https://nvidia-preview-pr-3144.docs.buildwithfern.com/openshell |
db1070b to
f17a633
Compare
|
Label |
f17a633 to
2fc442b
Compare
28f965f to
d39252f
Compare
d39252f to
f0fade9
Compare
Re-check After Author UpdateThanks @drew. I checked head Gator cannot complete the required critical-only follow-up because this PR now conflicts with its current stacked base, #2965 ( Action required: @drew, rebase PR #3144 onto the current #2965 head, resolve the merge conflicts, and address or obtain a maintainer waiver for Gator metadata
|
Maintainer Convergence DecisionThanks @drew. I checked the rebased head and the Trivy Helm-profile inventory update. The stacked-base conflict is resolved, and the required critical-only review found no newly introduced Critical defect. The autonomous Warning budget is exhausted, and one concrete maintainer decision is required before review can proceed. Root-cause findings:
Scope growth:
Reviewer-quality signals:
Maintainer action: @NVIDIA/openshell-maintainers, decide whether #3144 must add and test an allow-egress policy selecting only supervisor-role Pods, or explicitly waive Gator metadata
|
Maintainer Convergence DecisionI checked Drew's new head after the stacked base advanced. The prior nine-commit Kubernetes patch is range-diff equivalent, and the only author-only addition updates the Trivy scan test's expected profile counts. The required critical-only review found no newly introduced Critical defect. The autonomous Warning budget is exhausted, and one concrete maintainer decision is still required before review can proceed. Root-cause findings:
Scope growth:
Reviewer-quality signals:
Maintainer action: @NVIDIA/openshell-maintainers, decide whether #3144 must add and test an allow-egress policy selecting only supervisor-role Pods, or explicitly waive Gator metadata
|
Maintainer Convergence DecisionI checked Drew's new head after #2965 advanced again. All ten commits are range-diff equivalent to the previously reviewed patch, and the base-only change is Trivy metadata, so no new critical-only review is needed and the existing supervisor-egress obligation is unchanged. The autonomous Warning budget is exhausted, and one concrete maintainer decision is still required before review can proceed. Root-cause findings:
Scope growth:
Reviewer-quality signals:
Maintainer action: @NVIDIA/openshell-maintainers, decide whether #3144 must add and test an allow-egress policy selecting only supervisor-role Pods, or explicitly waive Gator metadata
|
Maintainer Convergence DecisionI checked Drew's new head after #2965 advanced again. All ten commits are range-diff equivalent to the previously reviewed Kubernetes patch, with the same patch ID, so the effective change and its full-stack architectural context are unchanged. Another critical-only reviewer run would duplicate the prior review. The autonomous Warning budget is exhausted, and one concrete maintainer decision is still required before review can proceed. Root-cause findings:
Scope growth:
Reviewer-quality signals:
Maintainer action: @NVIDIA/openshell-maintainers, decide whether #3144 must add and test an allow-egress policy selecting only supervisor-role Pods, or explicitly waive Gator metadata
|
Maintainer Convergence DecisionThanks @drew. I checked the current head’s E2E image-reuse update against the current #2965 stacked base and the downstream RFC 0012 layers. The bounded critical-only review found no newly introduced Critical defect: the external Kubernetes driver path now reuses both preloaded runtime images and avoids reloading them into kind, while the non-external path still builds and loads its own images. The autonomous Warning budget is exhausted, and one concrete maintainer decision is still required before review can proceed. Root-cause findings:
Scope growth:
Reviewer-quality signals:
Maintainer action: @NVIDIA/openshell-maintainers, decide whether #3144 must add and test an allow-egress policy selecting only supervisor-role Pods, or explicitly waive Gator metadata
|
Maintainer Convergence DecisionI checked Drew's new head after #2965 advanced again. All eleven Kubernetes commits are range-diff equivalent to the previously reviewed patch, with the same patch ID; the only underlying stacked-base change is in the Docker driver layer. The effective Kubernetes change and its relationship to downstream #3230 and #3229 are unchanged, so another critical-only reviewer run would duplicate the prior review. The autonomous Warning budget is exhausted, and one concrete maintainer decision is still required before review can proceed. Root-cause findings:
Scope growth:
Reviewer-quality signals:
Maintainer action: @NVIDIA/openshell-maintainers, decide whether #3144 must add and test an allow-egress policy selecting only supervisor-role Pods, or explicitly waive Gator metadata
|
Maintainer Convergence DecisionThanks @drew. I reviewed the current head’s incremental E2E image-reuse update against the current #2965 stacked base and kept downstream #3230 and #3229 in scope. The bounded critical-only review found no newly introduced Critical defect: the external Kubernetes driver image now receives the preloaded sandbox runtime image reference alongside the supervisor image, while the established build/load paths remain intact. The autonomous Warning budget is exhausted, and one concrete maintainer decision is still required before review can proceed. Root-cause findings:
Scope growth:
Reviewer-quality signals:
Maintainer action: @NVIDIA/openshell-maintainers, decide whether #3144 must add and test an allow-egress policy selecting only supervisor-role Pods, or explicitly waive Gator metadata
|
Maintainer Convergence DecisionThanks @drew. I reviewed the current head’s two new Kubernetes commits against the current #2965 stacked base and kept downstream #3230 and #3229 in scope. The prior eleven-commit Kubernetes patch is range-diff equivalent, and the bounded critical-only review found no newly introduced Critical defect in the typed-resource cleanup or restart-recovery delta. The autonomous Warning budget is exhausted, and one concrete maintainer decision is still required before review can proceed. Root-cause findings:
Scope growth:
Reviewer-quality signals:
Maintainer action: @NVIDIA/openshell-maintainers, decide whether #3144 must add and test an allow-egress policy selecting only supervisor-role Pods, or explicitly waive Gator metadata
|
Maintainer Convergence DecisionThanks @drew. I reviewed the current head’s restored-session rotation against the current #2965 stacked base and kept downstream #3230 and #3229 in scope. The bounded critical-only review found no newly introduced Critical defect: when gateway recovery supplies fresh launch authentication for an existing workload Pod, this layer now tears down the old Kubernetes runtime pair and recreates it with the new session material. The autonomous Warning budget is exhausted, and one concrete maintainer decision is still required before review can proceed. Root-cause findings:
Scope growth:
Reviewer-quality signals:
Maintainer action: @NVIDIA/openshell-maintainers, decide whether #3144 must add and test an allow-egress policy selecting only supervisor-role Pods, or explicitly waive Gator metadata
|
Re-check After Author UpdateThanks @drew. I checked head The required bounded critical-only review found no newly introduced Critical defect in the current author-only delta. No blocking or carried findings remain, and no maintainer convergence decision is needed. Current-head Branch Checks and E2E are running; Helm Lint and Trivy Changes are green. Gator is moving to pipeline watch. Gator metadata
|
Maintainer Approval NeededGator validation and PR monitoring are complete. The current head is a rebase-equivalent copy of the reviewed Kubernetes patch, all four durable findings remain resolved, and the full required current-head pipeline is green. Human maintainer approval is now required. Gator metadata
|
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
Thanks @drew. I reviewed the current head’s Kubernetes session-lineage delta against the current #2965 stacked base while keeping the RFC 0012 core and downstream #3230/#3229 layers in scope. The prior 15 Kubernetes commits are range-diff identical to the reviewed patch, and the bounded critical-only review found no newly introduced Critical defect: the Kubernetes boundary now receives the signed runtime generation and session rotation used by the shared sandbox protocol.
Blocking findings:
- No blocking findings remain
Carried findings:
- None; all four durable findings remain resolved
Current-head Branch Checks and E2E are running; Helm Lint and Trivy Changes are green. Gator is returning to pipeline watch.
Gator metadata
- Validation: Project-valid as PR 4 of the RFC 0012 isolation stack, implementing the Kubernetes proxy-pod driver layer on #2965 while preserving downstream #3230 and #3229 architecture.
- Docs: No direct user-facing UX contract changed in this lineage propagation delta; existing Kubernetes documentation remains sufficient.
- Checks:
OpenShell / Branch ChecksandOpenShell / E2Eare pending;OpenShell / Helm LintandOpenShell / Trivy Changesare green. - E2E:
test:e2eis applied and current-head Branch E2E run34869062407is queued/running. No/ok to testor workflow rerun is currently required. - Head SHA:
dc47f155324e6ae42b02392b13bd12aa62ea7b2b - Base SHA:
a3ff2e7024cb028a153894ea66921025ca1176c2 - Merge base SHA:
a3ff2e7024cb028a153894ea66921025ca1176c2 - Patch ID:
8eed2c4d9598c9aa04d9fc52d4c3fa810702fc22 - Gator payload:
8 - Review mode:
critical_only - Previous reviewed SHA:
eb215c1bbd97631a1e204ad4694ffd5af09c5e23 - Review budget exhausted: yes
- Maintainer decision required: no
- Next state:
gator:watch-pipeline
Monitoring CompleteMonitoring is complete because this PR has merged. Final status: The RFC 0012 Kubernetes proxy-pod driver layer merged after all durable review findings were resolved and the required Branch Checks, Helm Lint, Trivy Changes, and E2E gates passed for the final reviewed patch. I removed the active Gator metadata
|
Summary
Add the Kubernetes implementation of RFC 0012. The workload Pod runs
openshell-sandbox; a directly managed supervisor Pod runsopenshell-supervisor.The driver denies direct workload egress and preserves supervisor egress with two shared namespace NetworkPolicies. TLS, JWT claims, session generation, and recorded Pod UIDs authorize the exact supervisor-to-sandbox pairing.
Related Issue
Part of #1737.
Changes
Testing
mise run pre-commitcargo test -p openshell-driver-kubernetes --lib(221 passed)Checklist
Stack