You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit e9271cb
Browse filesBrowse the repository at this point in the historyBrowse files
feat(gateway): support runtime image env overrides (#3504)
Closes#3502
Resolve trusted OCI runtime images with driver TOML, process environment, and compiled-default precedence across Docker, Podman, and Kubernetes.
Signed-off-by: Evan Lezar <elezar@nvidia.com>
`OPENSHELL_SANDBOX_RUNTIME_IMAGE` and `OPENSHELL_SUPERVISOR_IMAGE` take
63
+
precedence over explicit image fields in the selected driver's TOML table; the
64
+
driver TOML takes precedence over the compiled release default. Preflight and
65
+
startup use the same resolution. These values are trusted operator inputs, not
66
+
sandbox request fields. Keep registry credentials in Podman's credential store
67
+
rather than embedding them in image references.
68
+
54
69
To override the path to the TOML config file entirely:
55
70
56
71
```shell
@@ -216,8 +231,8 @@ overrides that persist across package upgrades.
216
231
|`bind_address`|`127.0.0.1:17670` (gateway default) | Address for the primary gRPC/HTTP API listener. |
217
232
|`compute_driver`|`"podman"` (RPM default) | When unset, the gateway auto-detects Kubernetes, then Podman, then Docker. The RPM default pins to Podman; legacy `compute_drivers` lists are rejected. |
|`[openshell.drivers.podman].sandbox_runtime_image`|`ghcr.io/nvidia/openshell/sandbox:latest`|Static musl sandbox runtime image mounted into Podman workloads. |
220
-
|`[openshell.drivers.podman].supervisor_image`|`ghcr.io/nvidia/openshell/supervisor:latest`|Dynamic glibc supervisor image used outside the workload. |
234
+
|`[openshell.drivers.podman].sandbox_runtime_image`|`ghcr.io/nvidia/openshell/sandbox:latest`|Trusted sandbox runtime image. `OPENSHELL_SANDBOX_RUNTIME_IMAGE` overrides this field. |
235
+
|`[openshell.drivers.podman].supervisor_image`|`ghcr.io/nvidia/openshell/supervisor:latest`|Trusted supervisor image. `OPENSHELL_SUPERVISOR_IMAGE` overrides this field. |
221
236
|`[openshell.gateway].guest_tls_ca`| auto-generated path | Gateway CA injected into the selected local driver for supervisor-to-gateway TLS. Sandbox identity uses a bearer token. |
222
237
|`[openshell.gateway.tls]` paths | auto-generated paths | Server TLS certificate, key, and client CA. |
223
238
|`disable_tls`| unset | Set to `true` to disable TLS. |
0 commit comments