feat(compute): negotiate gateway callback listeners - #2492
Conversation
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
|
Label |
|
/ok-to-test 7e8b6d2 |
7e8b6d2 to
ec3d9eb
Compare
|
/ok-to-test ec3d9eb |
e0ba998 to
c2543d9
Compare
Signed-off-by: Evan Lezar <elezar@nvidia.com>
Signed-off-by: Evan Lezar <elezar@nvidia.com>
Signed-off-by: Evan Lezar <elezar@nvidia.com>
Signed-off-by: Evan Lezar <elezar@nvidia.com>
Signed-off-by: Evan Lezar <elezar@nvidia.com>
Signed-off-by: Evan Lezar <elezar@nvidia.com>
Signed-off-by: Evan Lezar <elezar@nvidia.com>
c2543d9 to
e817863
Compare
|
🌿 Preview your docs: https://nvidia-preview-pr-2492.docs.buildwithfern.com/openshell |
|
/ok-to-test e817863 |
|
/ok to test |
Signed-off-by: Evan Lezar <elezar@nvidia.com>
Signed-off-by: Evan Lezar <elezar@nvidia.com>
|
/ok-to-test c768219 |
Signed-off-by: Evan Lezar <elezar@nvidia.com>
|
/ok-to-test a5cef7d |
Signed-off-by: Evan Lezar <elezar@nvidia.com>
|
/ok-to-test ee88761 |
elezar
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
Validation: This maintainer-authored PR is project-valid and directly advances the listener-discovery work related to #2215.
Head SHA: ee8876193e2191b948b470abf592ce9d3b32357e
Review findings:
- Three warning-level findings were left inline: one docs accuracy issue, one gateway config reference-doc gap, and one operational logging gap.
Docs: Updated in part, but the published Podman and gateway configuration docs still need the inline corrections before gator can move this to pipeline watch.
Next state: gator:in-review
| For proxy-required networks, the Podman driver also accepts the corporate egress proxy keys `https_proxy`, `no_proxy`, `proxy_auth_file`, `proxy_auth_allow_insecure`, and `proxy_connect_by_hostname`. The supervisor chains policy-approved TLS tunnels through the proxy with HTTP CONNECT instead of dialing destinations directly. See the [Gateway Configuration File](./gateway-config) reference for the full contract, including the cleartext-credential acknowledgement and the validated-IP CONNECT behavior. | ||
|
|
||
| On macOS with `podman machine`, the driver uses gvproxy's host-loopback IP, `192.168.127.254`, for sandbox host aliases by default. Set `host_gateway_ip` only when your Podman machine uses a non-standard host-loopback address. On Linux, an empty `host_gateway_ip` keeps Podman's `host-gateway` resolver behavior. | ||
| On macOS with `podman machine`, the driver uses gvproxy's host-loopback IP, `192.168.127.254`, for sandbox host aliases by default. Set `host_gateway_ip` only when your Podman machine uses a non-standard host-loopback address. On Linux, an empty `host_gateway_ip` keeps Podman's `host-gateway` resolver behavior. Automatic local callback listener discovery for rootless Podman requires the default pasta network helper. When Podman reports another helper, set `host_gateway_ip` or configure an explicitly remote `grpc_endpoint`; otherwise the gateway fails startup rather than leaving sandbox callbacks unreachable. |
There was a problem hiding this comment.
gator-agent
Warning: This published Podman docs paragraph still says rootless callback discovery requires the default pasta helper, but the implementation now accepts pasta, slirp4netns, and the empty legacy Podman helper. Please update this paragraph so supported users are not incorrectly told to configure host_gateway_ip or a remote grpc_endpoint.
| # you don't use Podman or want loopback-only access (e.g. behind a reverse | ||
| # proxy). mTLS is enabled by default and protects all connections. | ||
| bind_address = "0.0.0.0:17670" | ||
| # Keep the primary listener on the built-in 127.0.0.1:17670 default. The |
There was a problem hiding this comment.
gator-agent
Warning: This changes the RPM config default by removing the bind_address = "0.0.0.0:17670" override, but docs/reference/gateway-config.mdx was not updated. Please add a short note that RPM/Podman leaves bind_address unset, uses the built-in 127.0.0.1:17670 primary listener, and relies on restricted driver-negotiated callback listeners.
| let local_addr = listener.local_addr().unwrap_or(address); | ||
| .map_err(|e| Error::transport(format!("failed to bind to {}: {e}", spec.address)))?; | ||
| let local_addr = listener.local_addr().unwrap_or(spec.address); | ||
| info!(address = %local_addr, "Server listening"); |
There was a problem hiding this comment.
gator-agent
Warning: The troubleshooting skill now tells operators to inspect the listener-purpose startup log, but this startup log still emits only address. Please include purpose = ?spec.purpose here so unexpected callback binds show the driver and reason in gateway logs.
Summary
Add a shared, gateway-owned contract for built-in compute drivers to report the
additional listeners required by their sandbox callback topology. Migrate
Docker and Podman to that contract so the primary gateway listener can remain
on its loopback default.
This PR is the production-scoped listener-discovery portion of #2215. It keeps
the initial authorization ceiling limited to the built-in Docker and Podman
topologies. Negotiated listeners expose only the generated sandbox-callable
gRPC surface; the operator-configured primary listener retains the full
multiplexed API.
Per-sandbox callback URI delivery, portable credential delivery, and
operator-configurable or interceptor-extensible listener capabilities remain
follow-up work.
Related Issue
Related to #2215
Changes
ComputeDriver.GetGatewayListenerRequirementswith exact-address andsemantic default-route/IPv4-loopback selectors.
UNIMPLEMENTEDfrom older external drivers as no additional listenerrequirements for protocol compatibility.
the gateway before persisted sandboxes resume.
request extensions.
before normal authentication and routing.
HTTP routes on callback listeners while leaving primary routing unchanged.
interfaces, rootless slirp4netns and legacy Podman 4 compatibility, Podman
Machine IPv4 loopback, and explicit Linux
host_gateway_ip.and fail startup when a required local callback listener cannot be safely
discovered.
wildcard socket IPv6-only when necessary.
configurations, and the local rootless-Podman development launcher.
cluster diagnostics.
Testing
cargo test -p openshell-driver-podman(136 tests)cargo test -p openshell-server --lib(1,127 tests)failures, remote callbacks, IPv4 loopback selection, split-dual-stack
binding, callback-only routing, and unchanged primary-listener behavior
Podman 4 and 5, Kubernetes, VM, and MCP E2E
The full workspace pre-commit gate reaches an unrelated macOS-only unused
Orderingimport already present on the branch base; #2513 contains thatindependent fix. All other pre-commit tasks completed successfully. Docker and
live Podman E2E were not run locally.
Checklist