User Story
I run OpenShell on Kubernetes from the Helm chart and need to register an operator-run supervisor middleware service and a gateway interceptor with the gateway, and to select provider-profile sources. The chart exposes no values for any of these, so I had to patch the rendered ConfigMap.
Problem Statement
The Helm chart renders gateway.toml from a fixed template. It has no values for [[openshell.supervisor.middleware]], [[openshell.gateway.interceptors]], or provider_profile_sources. The gateway rejects unknown config fields and the chart passes a single config file, so a Kubernetes operator has no supported way to register an extension. The gateway reads these tables only at startup.
Impact / Why This Matters
Today an operator must patch the rendered ConfigMap with a Helm post-renderer or kustomize overlay and keep that patch in step with chart changes. This affects every external extension on Kubernetes. Registration is the only way to attach middleware or an interceptor, and a patch that silently stops matching the template can leave the gateway refusing to start or an extension unregistered. It also pushes operators to hand-edit security-relevant settings (binding_policy, failure_policy, tls_ca_cert_path) with no chart validation.
Proposed Design
Add three values under server, rendered into the existing tables with no new gateway behavior:
server:
middleware:
- name: content-guard
grpcEndpoint: https://content-guard.openshell.svc:50051
tlsCaCertPath: /etc/openshell-extensions/ca.crt
maxPayloadBytes: 262144
timeout: 500ms
interceptors:
- name: governance
grpcEndpoint: https://governance.openshell.svc:50052
tlsCaCertPath: /etc/openshell-extensions/ca.crt
failurePolicy: fail_closed
bindingPolicy: allowlist
bindings:
- rpc: openshell.v1.OpenShell/CreateSandbox
phases: [modify_operation, validate]
providerProfileSources:
- { type: user }
- { type: interceptor, name: governance }
- Empty defaults render nothing, so existing releases are unchanged.
- The chart fails at render time on a missing
name, grpcEndpoint, or maxPayloadBytes, and on a type: interceptor source without a name.
- Private CAs use the existing
server.extraVolumes and server.extraVolumeMounts.
Acceptance Criteria
Alternatives Considered
- Helm post-renderer or kustomize patch: works today, but is unvalidated and sensitive to template changes.
- Raw TOML passthrough value: a smaller change, but it bypasses chart validation and the CA mounting convention.
- Running another service in front of the gateway: does not help, because registration is static gateway-side configuration.
- Existing extension points: middleware and interceptors are what is being registered. This only closes the deployment gap.
Agent Investigation
Checked against current main: field names and defaults match crates/openshell-core/src/config.rs, crates/openshell-server/src/config_file.rs, and crates/openshell-gateway-interceptors/src/plan.rs. A chart render with these values loads through the gateway's own config parser.
Checklist
User Story
I run OpenShell on Kubernetes from the Helm chart and need to register an operator-run supervisor middleware service and a gateway interceptor with the gateway, and to select provider-profile sources. The chart exposes no values for any of these, so I had to patch the rendered ConfigMap.
Problem Statement
The Helm chart renders
gateway.tomlfrom a fixed template. It has no values for[[openshell.supervisor.middleware]],[[openshell.gateway.interceptors]], orprovider_profile_sources. The gateway rejects unknown config fields and the chart passes a single config file, so a Kubernetes operator has no supported way to register an extension. The gateway reads these tables only at startup.Impact / Why This Matters
Today an operator must patch the rendered ConfigMap with a Helm post-renderer or kustomize overlay and keep that patch in step with chart changes. This affects every external extension on Kubernetes. Registration is the only way to attach middleware or an interceptor, and a patch that silently stops matching the template can leave the gateway refusing to start or an extension unregistered. It also pushes operators to hand-edit security-relevant settings (
binding_policy,failure_policy,tls_ca_cert_path) with no chart validation.Proposed Design
Add three values under
server, rendered into the existing tables with no new gateway behavior:name,grpcEndpoint, ormaxPayloadBytes, and on atype: interceptorsource without aname.server.extraVolumesandserver.extraVolumeMounts.Acceptance Criteria
gateway.tomlas before.[[openshell.supervisor.middleware]],[[openshell.gateway.interceptors]](with bindings), andprovider_profile_sourcesthat the gateway's config loader accepts.helm templatewith a message naming the value.Alternatives Considered
Agent Investigation
Checked against current
main: field names and defaults matchcrates/openshell-core/src/config.rs,crates/openshell-server/src/config_file.rs, andcrates/openshell-gateway-interceptors/src/plan.rs. A chart render with these values loads through the gateway's own config parser.Checklist