Skip to content

Commit 3bdd6e7

Browse files
committed
chore(policy): merge main and preserve policy boundaries
Signed-off-by: Johnny Greco <jogreco@nvidia.com>
2 parents 649c4a1 + c1f2e71 commit 3bdd6e7

399 files changed

Lines changed: 60992 additions & 33731 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.agents/skills/build-openshell-mxc-windows/SKILL.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -213,6 +213,10 @@ compatibility under emulation is not part of these tasks. The aggregate
213213
commands above on an ARM64 host.
214214

215215
The repository-wide `mise run pre-commit` task is also supported on Windows.
216+
Run `rust:lockfiles:check`, `sdk:ts:ci`, `go:ci`, and `test:e2e-parity` through
217+
the Windows-aware tasks when validating those surfaces. Do not count the Go
218+
Windows ARM64 race-detector exclusion or POSIX permission-bit skips as security
219+
coverage. SDK test dependencies must remain at their lockfile versions.
216220
Its Rust check, Clippy, and test dependencies enter the same MSVC environment
217221
for the native host target and use an inherited compiler wrapper when it is
218222
available. Linux glibc

‎.agents/skills/helm-dev-environment/SKILL.md‎

Lines changed: 42 additions & 39 deletions
Original file line numberDiff line numberDiff line change
@@ -69,28 +69,15 @@ mise run helm:skaffold:dev
6969
mise run helm:skaffold:run
7070
```
7171

72-
**Supervisor sidecar topology** (build once and leave running):
73-
```bash
74-
mise run helm:skaffold:run:sidecar
75-
```
76-
77-
**Supervisor sidecar topology with TLS/mTLS enabled** (build once and leave running):
78-
```bash
79-
mise run helm:skaffold:run:sidecar-mtls
80-
```
81-
82-
Both commands build the `gateway` and `supervisor` images and deploy the OpenShell Helm
83-
chart. The sidecar profile renders an `openshell-network-init` init container for
84-
nftables setup and an `openshell-supervisor-network` runtime sidecar for proxying.
85-
Binary-aware policy mode runs that sidecar as UID 0 with `SYS_PTRACE` and
86-
`DAC_READ_SEARCH`; relaxed mode can run it as the configured proxy UID, which
87-
must be at least `1000` and distinct from the workload UID. The
88-
sidecar-mTLS profile reuses `ci/values-sidecar.yaml` and restores
89-
`server.disableTls=false` inline for Skaffold. The `pkiInitJob` hook (a pre-install
90-
Job that runs `openshell-gateway generate-certs`) generates mTLS secrets on first
91-
install. The default Skaffold values export gateway and Kubernetes-driver traces to
92-
the collector service installed by `helm:k3s:create`. Envoy Gateway opt-in; see the
93-
Optional Add-ons section below.
72+
The Skaffold flow builds distinct `gateway`, `sandbox`, and `supervisor` images
73+
and deploys the OpenShell Helm chart. The Kubernetes driver creates a
74+
capability-free workload Pod and a directly managed capability-free supervisor
75+
Pod. One namespace-wide NetworkPolicy denies direct egress from every OpenShell
76+
workload Pod. The
77+
`pkiInitJob` hook (a pre-install Job that runs `openshell-gateway generate-certs`)
78+
generates mTLS secrets on first install. The default Skaffold values export
79+
gateway and Kubernetes-driver traces to the collector service installed by
80+
`helm:k3s:create`. Envoy Gateway is opt-in; see the Optional Add-ons section.
9481

9582
The gateway Service uses ClusterIP. Access is via Envoy Gateway (port `8080`) or
9683
the unified local forwarding task:
@@ -102,9 +89,9 @@ mise run helm:k3s:forward
10289
The task forwards OTLP/gRPC to `http://127.0.0.1:4317` and the trace UI to
10390
`http://127.0.0.1:18888`. When Skaffold has deployed a Kubernetes gateway, it
10491
also forwards the gateway to `http://127.0.0.1:8090`; otherwise it continues
105-
with the collector ports only. A successful plaintext `helm:skaffold:run` or
106-
`helm:skaffold:run:sidecar` registers the gateway under the worktree-specific
107-
k3d cluster name and selects it as the active gateway. Keep the forwarding
92+
with the collector ports only. A successful plaintext `helm:skaffold:run`
93+
registers the gateway under the worktree-specific k3d
94+
cluster name and selects it as the active gateway. Keep the forwarding
10895
task running while using those endpoints.
10996

11097
### Viewing local traces
@@ -134,8 +121,7 @@ create the Secret named `openshell-ha-pg` with a `uri` key, then run
134121
### TLS behaviour
135122

136123
`ci/values-skaffold.yaml` sets `server.disableTls: true`, so Skaffold-based deploys run
137-
plaintext by default. To test sidecar topology with TLS enabled, use
138-
`mise run helm:skaffold:run:sidecar-mtls`.
124+
plaintext by default. Override `server.disableTls=false` to exercise TLS/mTLS.
139125

140126
| Mode | `server.disableTls` | Gateway scheme |
141127
|------|---------------------|----------------|
@@ -188,12 +174,6 @@ openshell sandbox list --gateway-endpoint https://localhost:8090
188174
mise run helm:skaffold:delete
189175
```
190176

191-
For a sidecar-profile deployment:
192-
193-
```bash
194-
mise run helm:skaffold:delete:sidecar
195-
```
196-
197177
### Delete the cluster entirely
198178

199179
```bash
@@ -256,15 +236,19 @@ Key Helm values:
256236

257237
### Keycloak OIDC
258238

259-
One-time setup — only needed once per cluster lifetime:
239+
Initial setup — rerun it whenever you want to rotate the development CA:
260240

261241
```bash
262242
mise run keycloak:k8s:setup
263243
```
264244

265245
This deploys Keycloak (`quay.io/keycloak/keycloak:24.0`) into the `keycloak` namespace,
266-
imports the openshell realm from `scripts/keycloak-realm.json`, and prints a port-forward
267-
command for acquiring tokens from the CLI.
246+
imports the openshell realm from `scripts/keycloak-realm.json`, generates a short-lived
247+
development TLS certificate, and publishes its trust anchor as the
248+
`openshell-keycloak-ca` ConfigMap in the OpenShell namespace. The command prints a
249+
port-forward command for acquiring tokens from the CLI. Rerunning setup rotates the
250+
development certificate and trust anchor; redeploy the gateway afterward so it reloads
251+
the mounted CA bundle.
268252

269253
Then activate OIDC in the OpenShell Helm chart:
270254
1. Uncomment `#- ci/values-keycloak.yaml` in `skaffold.yaml`
@@ -288,12 +272,31 @@ SPIFFE JWT-SVIDs for dynamic provider token grants:
288272
`openshell.local` and adds a `ClusterSPIFFEID` that maps sandbox pod
289273
annotations to `spiffe://openshell.local/openshell/sandbox/<sandbox-id>`.
290274
OpenShell mounts the SPIFFE CSI Workload API socket at
291-
`/spiffe-workload-api/spire-agent.sock` into sandbox pods for provider token
275+
`/spiffe-workload-api/spire-agent.sock` only into supervisor Pods for provider token
292276
grants. Supervisor-to-gateway authentication remains on the Kubernetes
293277
ServiceAccount bootstrap and gateway-minted sandbox JWT path; the selected
294278
Kubernetes compute driver validates the projected token before the gateway
295279
mints its JWT.
296280

281+
### Vault Credential Driver
282+
283+
The `credential-driver-vault` Skaffold profile applies
284+
`ci/values-credential-driver-vault.yaml`. Its external OpenBao/Vault backend
285+
must expose HTTPS at the configured service DNS name and publish the issuing CA
286+
certificate as the `ca.crt` key in the `openbao-ca` ConfigMap. Local e2e uses
287+
OpenBao dev TLS and an `openbao-0` DNS alias matching its generated certificate.
288+
The Helm value
289+
`server.credentialDrivers.vault.caConfigMapName` mounts that key into the
290+
gateway and renders the driver's `ca_bundle` setting. Non-loopback HTTP
291+
addresses fail gateway startup, and hostname verification requires the service
292+
DNS name in the server certificate SANs.
293+
294+
```bash
295+
cd deploy/helm/openshell
296+
skaffold run -p credential-driver-vault
297+
kubectl -n openshell logs statefulset/openshell -c openshell-gateway --tail=200
298+
```
299+
297300
---
298301

299302
## Cluster Lifecycle (stop/start)
@@ -349,10 +352,10 @@ for dependencies still declared in `Chart.yaml`.
349352
| `deploy/helm/openshell/ci/values-gateway.yaml` | Envoy Gateway GRPCRoute + Gateway overlay |
350353
| `deploy/helm/openshell/ci/values-high-availability.yaml` | HA test overlay (`replicaCount: 2` with external PostgreSQL Secret) |
351354
| `deploy/helm/openshell/ci/values-keycloak.yaml` | Keycloak OIDC overlay |
352-
| `deploy/helm/openshell/ci/values-sidecar.yaml` | Supervisor sidecar topology overlay for Kubernetes e2e/dev |
353355
| `deploy/helm/openshell/ci/values-spire.yaml` | SPIFFE/SPIRE provider token grant overlay |
354356
| `deploy/helm/openshell/ci/values-spire-stack.yaml` | SPIRE hardened chart values for local dev |
355357
| `deploy/helm/openshell/ci/values-tls-disabled.yaml` | Lint-only: TLS + auth disabled (reverse-proxy edge termination) |
358+
| `deploy/helm/openshell/ci/values-credential-driver-vault.yaml` | Vault credential-driver validation overlay with HTTPS and private-CA trust |
356359
| `deploy/kube/manifests/envoy-gateway-openshell.yaml` | GatewayClass for Envoy Gateway (`mise run helm:gateway:apply`) |
357360
| `tasks/scripts/helm-k3s-local.sh` | k3d cluster create/delete/start/stop/status |
358-
| `tasks/scripts/keycloak-k8s-setup.sh` | Keycloak deploy + realm import |
361+
| `tasks/scripts/keycloak-k8s-setup.sh` | Keycloak deploy, realm import, and development TLS trust anchor |

‎.agents/skills/launch-openshell-gator/SKILL.md‎

Lines changed: 12 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ For gator's PR/issue validation policy, load `gator-gate` inside the launched sa
1313

1414
## Non-Negotiable Rules
1515

16-
- Keep normal gator launches supervised: use `--watch --background` and let the in-sandbox supervisor own sleeping and relaunching bounded cycles.
16+
- Keep normal gator launches supervised: use `--watch` and let the in-sandbox supervisor own sleeping and relaunching bounded cycles.
1717
- Do not add passive `sleep` loops in the operator session to watch gator. Check logs or status once, then report the current state or launch a proper watcher outside the model session only when explicitly asked.
1818
- Do not change the default gator model in `scripts/agents/gator/agent.yaml` for experiments. Use `CODEX_MODEL=...` and, if needed, a temporary `--from` Docker context or `--codex-bin` override.
1919
- Do not push to contributor branches, approve, merge, post `/ok to test`, or broaden gator scope unless the operator explicitly authorized that action.
@@ -34,7 +34,6 @@ For gator's PR/issue validation policy, load `gator-gate` inside the launched sa
3434
| `scripts/agents/gator/bin/validate-review-findings` | Enforces the blocker evidence schema and downgrades unsupported hypotheses. |
3535
| `scripts/agents/gator/prompts/gator.md` | Rendered top-level prompt template baked into the payload. |
3636
| `scripts/agents/gator/skills/gator-gate/SKILL.md` | In-sandbox gator state-machine skill. |
37-
| `scripts/agents/gator/logs/` | Background launch and supervisor logs. |
3837

3938
## Preflight
4039

@@ -156,11 +155,12 @@ sandbox_name="gator-pr-${pr_number}-supervised"
156155
--gateway "$gateway_name" \
157156
--name "$sandbox_name" \
158157
--watch \
159-
--background \
160158
"Review and monitor PR #${pr_number} through the gator-gate workflow. Scope this invocation only to PR #${pr_number}."
161159
```
162160

163-
The launcher queries gateway's selected compute driver, builds gator image in matching Docker or Podman image store, stages immutable payload, imports provider profiles, configures provider credentials and refresh, creates and uploads sandbox payload, then starts agent supervisor with `sandbox exec`. It writes a background log under `scripts/agents/gator/logs/`. `CONTAINER_ENGINE`, when set, must match gateway driver.
161+
The launcher queries the gateway's selected compute driver, builds the gator image in the matching Docker or Podman image store, stages the immutable payload, imports provider profiles, configures provider credentials and refresh, and starts the agent supervisor as the sandbox's canonical main process. The detached main process survives loss of the host CLI connection and reconnects to a restarted gateway. Unless `--keep` is set, the sandbox is marked ephemeral so the gateway deletes it after the supervisor exits. `CONTAINER_ENGINE`, when set, must match the gateway driver.
162+
163+
The launcher streams image-build and provisioning output until the detached workload is ready, then exits. Use `openshell logs <sandbox-name>` or the TUI for runtime output.
164164

165165
### Launch An Issue Or Issue/PR Pair
166166

@@ -177,7 +177,6 @@ sandbox_name="gator-issue-${issue_number}-supervised"
177177
--gateway "$gateway_name" \
178178
--name "$sandbox_name" \
179179
--watch \
180-
--background \
181180
"Run gator on issue #${issue_number}. Scope this invocation only to issue #${issue_number}."
182181
```
183182

@@ -198,7 +197,6 @@ sandbox_name="gator-pr-${pr_number}-supervised"
198197
--gateway "$gateway_name" \
199198
--name "$sandbox_name" \
200199
--watch \
201-
--background \
202200
"Review and monitor PR #${pr_number} with linked issue #${issue_number} through the gator-gate workflow. Scope this invocation only to PR #${pr_number} and issue #${issue_number}."
203201
```
204202

@@ -219,7 +217,6 @@ sandbox_name="gator-pr-${pr_number}-supervised"
219217
--gateway "$gateway_name" \
220218
--name "$sandbox_name" \
221219
--watch \
222-
--background \
223220
"Review and monitor PR #${pr_number} through the gator-gate workflow. Scope this invocation only to PR #${pr_number}. The operator explicitly authorizes applying the test:e2e label, posting /ok to test for the current head SHA, and rerunning the relevant current-head workflow when the E2E Label Help bot says that is required."
224221
```
225222

@@ -241,7 +238,6 @@ CODEX_MODEL=gpt-5.6-sol \
241238
--gateway "$gateway_name" \
242239
--name "$sandbox_name" \
243240
--watch \
244-
--background \
245241
"Review and monitor PR #${pr_number} through the gator-gate workflow. Scope this invocation only to PR #${pr_number}. This launch is intentionally testing Codex model gpt-5.6-sol via the CLI launcher."
246242
```
247243

@@ -266,27 +262,22 @@ CODEX_MODEL=gpt-5.6-sol \
266262
--name "$sandbox_name" \
267263
--from "$tmp_context" \
268264
--watch \
269-
--background \
270265
"Review and monitor PR #${pr_number} through the gator-gate workflow. Scope this invocation only to PR #${pr_number}."
271266
```
272267

273268
## Monitoring
274269

275270
### Read The Launch Result
276271

277-
The launcher prints the log path when `--background` is used:
278-
279-
```text
280-
Started in background. Log: scripts/agents/gator/logs/<sandbox-name>.log
281-
```
282-
283-
Read that file directly. Important markers:
272+
The launcher streams image-build and provisioning output to the terminal. Important markers:
284273

285274
- `Built image ...` means the local image build completed.
286275
- `Created sandbox: <name>` means OpenShell accepted the sandbox.
287276
- `openshell-agent: starting watch cycle` means the in-sandbox supervisor began a bounded cycle.
288277
- `OpenAI Codex v...` plus `model: ...` confirms the Codex CLI and model actually used.
289278
- `OPENSHELL_AGENT_RESULT {...}` is the bounded-cycle sentinel. In watch mode, the supervisor sleeps and relaunches after this line.
279+
- `/sandbox/.openshell-agent/status.json` is the atomic current state snapshot. Its `result.notes` field is Gator's plain-language diagnosis and next action for that cycle.
280+
- `/sandbox/.openshell-agent/history.jsonl` contains the latest 100 supervisor transitions, including active-cycle starts and completed cycle results.
290281
- `openshell-agent: still running watch cycle ...` is a heartbeat during long active model cycles.
291282
- `review_feedback_lookup_failed` means Gator could not build the required cross-SHA feedback ledger and deliberately skipped a context-free review.
292283

@@ -314,6 +305,11 @@ If `sandbox get` is not supported by the local CLI shape, use `openshell sandbox
314305
| `status=terminal_failure` | Unrecoverable or stale immutable payload. | Inspect the reason; rebuild/relaunch for `stale_gator_payload`. |
315306
| `status=complete` | Target closed, merged, or one-shot complete. | Delete sandbox if no longer needed. |
316307

308+
Prefer the state snapshot over scraping transient `/tmp` cycle output. Use the
309+
history file to tell whether a failure is repeating or whether the supervisor
310+
has begun a fresh cycle. Runtime logs remain useful for full command output and
311+
transport diagnostics.
312+
317313
## Restarting A Gator
318314

319315
Restart when the payload must change, the sandbox is wedged without a sentinel, the model/tooling version changed, or a transient failure repeats past the useful retry point.
@@ -339,7 +335,6 @@ openshell --gateway "$gateway_name" sandbox delete "$sandbox_name"
339335
--gateway "$gateway_name" \
340336
--name "$sandbox_name" \
341337
--watch \
342-
--background \
343338
"<same scoped operator prompt, updated only with the reason for relaunch>"
344339
```
345340

@@ -401,7 +396,6 @@ When you launch or inspect gator, report:
401396

402397
- Sandbox name.
403398
- Gateway name.
404-
- Log path.
405399
- Target issue/PR scope.
406400
- Harness and model when relevant.
407401
- Whether image build and sandbox creation succeeded.

‎.agents/skills/sbom/SKILL.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ The OpenShell SBOM tooling produces source-tree CycloneDX JSON SBOMs using Syft,
1515

1616
SBOMs are **release artifacts only** -- they are generated on demand and not committed to the repository. Output lands in `deploy/sbom/output/` (gitignored).
1717

18-
Pushed gateway and supervisor images carry an SPDX SBOM and minimal SLSA provenance as OCI attestations. Branch E2E, Release Dev, and Release Tag image binaries embed cargo-auditable metadata, so their image SBOMs include linked Rust crates.
18+
Pushed gateway, sandbox, and supervisor images carry an SPDX SBOM and minimal SLSA provenance as OCI attestations. Branch E2E, Release Dev, and Release Tag image binaries embed cargo-auditable metadata, so their image SBOMs include linked Rust crates.
1919

2020
## Prerequisites
2121

0 commit comments

Comments
 (0)