Skip to content

fix(kubernetes): move agent-sandbox to v0.5.4 #2764

Description

@sjenning

https://github.com/kubernetes-sigs/agent-sandbox/releases/tag/v0.5.4

v0.5.4 contains a breaking change to the Suspended condition that we now use after the stop/start functionality in #2653

Also, the release manifest changed from manifest.yaml to sandbox.yaml. We need up update any scripts/docs that refer to this manifest. The manifest name switched in v0.5.2.

v0.5.1 and earlier manifest path (current): https://github.com/kubernetes-sigs/agent-sandbox/releases/download/v0.5.0/manifest.yaml

v0.5.2 and later manifest path (new): https://github.com/kubernetes-sigs/agent-sandbox/releases/download/v0.5.4/sandbox.yaml

Activity

  1. changed the title [-]bump(agent-sandbox): move to v0.5.4[/-] [+]fix(kubernetes): move agent-sandbox to v0.5.4[/+] on Aug 16, 2026
  2. sjenning commented on Aug 25, 2026

    @sjenning
    CollaboratorAuthor

    🏗️ build-plan

    Implementation Plan

    Issue type: fix
    Complexity: Medium
    Confidence: High — current compatibility behavior and upstream release artifacts are verified

    Summary

    Move OpenShell’s default Agent Sandbox dependency from v0.5.0 to v0.5.4 across local Kubernetes setup, E2E, branch CI, and release-canary coverage. Select the release manifest name by version so v0.5.2+ uses sandbox.yaml while the supported v0.4.6 compatibility lane continues using manifest.yaml; retain the already-compatible lifecycle logic and add focused regression assertions for v0.5.4’s persistent Suspended condition.

    Scope

    • tasks/scripts/helm-k3s-local.sh: default to v0.5.4 and select manifest.yaml for legacy releases versus sandbox.yaml for v0.5.2+.
    • e2e/support/install-agent-sandbox.sh: apply the same version-aware asset selection and v0.5.4 default.
    • e2e/with-kube-gateway.sh: update the default v1beta1 controller version to v0.5.4.
    • .github/workflows/e2e-kubernetes-test.yml: update the reusable workflow’s default Agent Sandbox version.
    • .github/workflows/branch-e2e.yml: run combined and sidecar v1beta1 jobs against v0.5.4 while retaining v0.4.6.
    • .github/workflows/release-canary.yml: pin the Kubernetes canary to v0.5.4.
    • crates/openshell-driver-kubernetes/src/driver.rs: extend lifecycle-condition tests to prove Suspended=False/NotSuspended is not interpreted as stopped.
    • crates/openshell-server/src/compute/mod.rs: cover the exact v0.5.4 running condition set and clarify that stale Suspended=True compatibility applies to older v1beta1 releases.
    • docs/kubernetes/setup.mdx: replace the obsolete latest-release manifest.yaml installation URL with sandbox.yaml.
    • deploy/helm/openshell/README.md.gotmpl: update the prerequisite installation URL.
    • deploy/helm/openshell/README.md: regenerate the Helm README from its template.
    • docs/reference/sandbox-compute-drivers.mdx: clarify that stop completion requires Suspended=True, not merely condition presence.

    No architecture document or agent skill changes are needed; the existing subsystem boundaries and skill instructions remain accurate.

    Implementation Steps

    1. Add focused driver and gateway unit assertions for v0.5.4’s persistent Suspended=False running condition, while retaining legacy stale-condition compatibility.
    2. Update both installer paths to default to v0.5.4 and resolve the release asset at the v0.5.2 rename boundary, then validate both v0.5.4 and v0.4.6 URLs.
    3. Update reusable workflow defaults, branch E2E matrix entries, and the release-canary pin to v0.5.4 without changing the v0.4.6 compatibility lane.
    4. Update published Kubernetes setup instructions and the Helm README template to use sandbox.yaml, regenerate the Helm README, and clarify condition-status semantics in the compute-driver reference.
    5. Run targeted unit checks, pre-commit/Helm documentation checks, and Kubernetes E2E against both supported release shapes.

    Test Plan

    • Unit tests: Extend tests in openshell-driver-kubernetes and openshell-server for Suspended=False/NotSuspended, False/PodTerminating, and True/PodTerminated; run the targeted crate test suites.
    • Integration tests: Run mise run helm:docs:check and mise run pre-commit; verify both selected release asset URLs resolve successfully.
    • E2E tests: Run mise run e2e:kubernetes:agent-sandbox-versions, exercising v0.5.4 stop/start behavior and the retained v0.4.6 fallback. Branch CI additionally covers v0.5.4 in sidecar topology.

    Risks & Open Questions

    • Asset selection must use the v0.5.2 boundary; changing every path unconditionally to sandbox.yaml would break v0.4.6.
    • v0.5.4 contains controller changes beyond condition persistence, so the live Kubernetes lifecycle suite is required.
    • Use core-only sandbox.yaml, not sandbox-with-extensions.yaml; OpenShell requires only the controller and Sandbox CRD, matching the prior manifest.yaml installation.
    • No stakeholder decisions are required.

    Documentation Impact

    Update the Kubernetes setup page, Helm chart prerequisites, generated Helm README, and compute-driver condition wording. No navigation changes are needed.

    Gateway Config Documentation Impact

    None. This does not add, remove, rename, or change defaults for gateway TOML or driver configuration fields.

    LSM Compatibility

    No impact. The change does not alter process identity, binary execution, /proc access, or inter-process visibility, so SELinux and AppArmor behavior is unchanged.


    Revision 1 — initial plan

  3. sjenning commented on Aug 25, 2026

    @sjenning
    CollaboratorAuthor

    🏗️ build-from-issue-agent

    Implementation Complete

    PR: #2937

    What was built

    Updated Agent Sandbox defaults and CI coverage to v0.5.4, added version-aware release manifest selection that preserves v0.4.6 compatibility, and documented and tested the new lifecycle condition behavior.

    Tests

    • Unit: 2 regression tests added/extended; targeted current and legacy lifecycle tests pass
    • Integration: pre-commit, Helm docs, shell syntax, and release asset URL checks pass
    • E2E: attempted, but the local k3d node hit ephemeral-storage disk pressure and evicted the sandbox and gateway pods; details are recorded in the PR

    Docs updated

    • Kubernetes setup
    • Helm chart prerequisite template and generated README
    • Kubernetes compute-driver lifecycle reference

    The issue will auto-close when the PR is merged.

  4. github-actions commented on Sep 9, 2026

    @github-actions

    This issue has had no activity for 14 days and is now marked stale. It may be closed in 7 days if there is no further activity. Comment or remove the state:stale label to keep it open.

  5. PicoNVIDIA commented on Sep 16, 2026

    @PicoNVIDIA

    I rechecked the setup instructions on September 16. The command still uses latest/download/manifest.yaml, which redirects to v1.0.2/manifest.yaml and returns 404. The versioned sandbox.yaml returns 200.

    That manifest brought the controller to Ready in our K3s lab, though this doesn't establish full OpenShell compatibility.

    #2937 already includes the URL correction, and I saw the request to update its controller version. Could the documentation correction ship separately if that version update needs more testing? The published prerequisite is still broken.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions