Skip to content

Docker driver: pick the container runtime (e.g. Kata) and show which one a sandbox got #3868

Description

@carrollco

User Story

I run untrusted, AI-written code through my project, plimsoll, which uses OpenShell on one machine with the Docker driver. I'd like those sandboxes on something stronger than runc, like Kata, and a way to check which runtime a sandbox actually got.

Problem Statement

Setting runtime_class_name on the Docker driver gets refused, and nothing in the API says which runtime a sandbox is on (it's Docker's default, runc here).

Impact / Why This Matters

plimsoll tells whoever sent the code what isolation it ran under. On the Docker driver the best it can say is "a container". I could change Docker's default runtime in daemon.json, but that changes every container on the machine, and OpenShell still can't tell anyone.

Proposed Design

  • Whoever sets up the gateway picks which runtimes the Docker driver may use.
  • GetGatewayInfo lists them.
  • runtime_class_name (or whatever you'd prefer) picks one at create. Anything not on the list gets refused, like today.
  • GetSandbox says which runtime the sandbox is actually on.

Even just the last one would help.

Acceptance Criteria

  • GetGatewayInfo lists the allowed runtimes
  • A sandbox created with an allowed runtime runs on it
  • Anything else is refused before a container starts
  • GetSandbox shows the runtime, default included

Alternatives Considered

  • Change the default in daemon.json: hits everything on the machine, and OpenShell can't report it.
  • Kubernetes RuntimeClass: works, but I'm on one machine, no cluster.
  • VM driver: marked experimental, haven't tried it.

Agent Investigation

I had Claude Code dig into this. Here's what it found, which I checked.

On v0.1.2 (Docker driver, local gateway, Docker's default runtime runc, runsc also installed):

  • No runtime_class_name: the sandbox comes up fine, docker inspect shows both containers on runc, and GetSandbox reads back an empty runtime_class_name. GetGatewayInfo only reports CPU, memory and GPU capabilities.
  • runtime_class_name set to runsc, or to a made-up name: refused with FAILED_PRECONDITION: docker compute driver does not support template.platform_config, before any container is created.

In the source (main at cfcc373):

Why Kata and not gVisor: #3361 says gVisor doesn't do Landlock or seccomp user notification, which the supervisor needs. I haven't tried Kata either, so no promises the supervisor is happy there. Related: #1616, #3361, #3366.

Checklist

  • I've reviewed existing issues and the architecture docs
  • This is a design proposal, not a "please build this" request
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    state:triage-neededOpened without agent diagnostics and needs triage

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions