Skip to content

feat(helm): register supervisor middleware and gateway interceptors from chart values #4068

Description

@dvavili

User Story

I run OpenShell on Kubernetes from the Helm chart and need to register an operator-run supervisor middleware service and a gateway interceptor with the gateway, and to select provider-profile sources. The chart exposes no values for any of these, so I had to patch the rendered ConfigMap.

Problem Statement

The Helm chart renders gateway.toml from a fixed template. It has no values for [[openshell.supervisor.middleware]], [[openshell.gateway.interceptors]], or provider_profile_sources. The gateway rejects unknown config fields and the chart passes a single config file, so a Kubernetes operator has no supported way to register an extension. The gateway reads these tables only at startup.

Impact / Why This Matters

Today an operator must patch the rendered ConfigMap with a Helm post-renderer or kustomize overlay and keep that patch in step with chart changes. This affects every external extension on Kubernetes. Registration is the only way to attach middleware or an interceptor, and a patch that silently stops matching the template can leave the gateway refusing to start or an extension unregistered. It also pushes operators to hand-edit security-relevant settings (binding_policy, failure_policy, tls_ca_cert_path) with no chart validation.

Proposed Design

Add three values under server, rendered into the existing tables with no new gateway behavior:

server:
  middleware:
    - name: content-guard
      grpcEndpoint: https://content-guard.openshell.svc:50051
      tlsCaCertPath: /etc/openshell-extensions/ca.crt
      maxPayloadBytes: 262144
      timeout: 500ms
  interceptors:
    - name: governance
      grpcEndpoint: https://governance.openshell.svc:50052
      tlsCaCertPath: /etc/openshell-extensions/ca.crt
      failurePolicy: fail_closed
      bindingPolicy: allowlist
      bindings:
        - rpc: openshell.v1.OpenShell/CreateSandbox
          phases: [modify_operation, validate]
  providerProfileSources:
    - { type: user }
    - { type: interceptor, name: governance }
  • Empty defaults render nothing, so existing releases are unchanged.
  • The chart fails at render time on a missing name, grpcEndpoint, or maxPayloadBytes, and on a type: interceptor source without a name.
  • Private CAs use the existing server.extraVolumes and server.extraVolumeMounts.

Acceptance Criteria

  • A release with no new values renders the same gateway.toml as before.
  • Setting the values renders valid [[openshell.supervisor.middleware]], [[openshell.gateway.interceptors]] (with bindings), and provider_profile_sources that the gateway's config loader accepts.
  • A missing required field fails helm template with a message naming the value.
  • Chart unit tests, the chart README, and the gateway configuration docs cover the new values.

Alternatives Considered

  • Helm post-renderer or kustomize patch: works today, but is unvalidated and sensitive to template changes.
  • Raw TOML passthrough value: a smaller change, but it bypasses chart validation and the CA mounting convention.
  • Running another service in front of the gateway: does not help, because registration is static gateway-side configuration.
  • Existing extension points: middleware and interceptors are what is being registered. This only closes the deployment gap.

Agent Investigation

Checked against current main: field names and defaults match crates/openshell-core/src/config.rs, crates/openshell-server/src/config_file.rs, and crates/openshell-gateway-interceptors/src/plan.rs. A chart render with these values loads through the gateway's own config parser.

Checklist

  • I've reviewed existing issues and the published docs
  • This is a design proposal, not a "please build this" request

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    state:triage-neededOpened without agent diagnostics and needs triage

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions