Repository navigation
Conversation
pimlock
requested review from
a team,
derekwaynecarr,
mrunalp and
sjenning
as code owners
September 9, 2026 19:39
6 tasks
|
🌿 Preview your docs: https://nvidia-preview-pr-3244.docs.buildwithfern.com/openshell |
This comment was marked as outdated.
This comment was marked as outdated.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment was marked as outdated.
This comment was marked as outdated.
5 of 6 tasks
pimlock
added this pull request to stack #3266
September 10, 2026 23:38
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
The startup repair that creates version-one policy history for legacy sandboxes propagated validation failures, so a single stored policy that no longer passes current validation rules prevented the gateway from starting. Skip such sandboxes with a warning and a completion summary so they keep the pre-repair behavior where only their own configuration reads report the failure. Store errors remain fatal. Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Fleet-wide configuration changes spawned one snapshot build per connected sandbox and component with no concurrency limit, so a global setting or provider change issued every store query and credential-driver call at once. Gate builds behind a semaphore sized from the database pool and start the build deadline only once a permit is held. Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Sandboxes keep their supervisor binary until they are recreated, so a gateway upgrade meets supervisors that predate the handshake and report revision zero. Rejecting them severs every running sandbox with no automatic recovery. Accept revision zero for one release, log a warning per session, and count them in openshell_supervisor_protocol_legacy_sessions_total. The supervisor mirrors the allowance for gateways that predate the handshake. Add a shared ConnectSupervisor test harness and handler-level tests for legacy acceptance and unknown-revision rejection. Move the skill troubleshooting paragraph out of the numbered deployment list so the list renders. Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
pimlock
force-pushed
the
1731-config-update-stage-1/pimlock
branch
from
September 11, 2026 02:08
e7729ec to
70773d3
Compare
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
This comment was marked as outdated.
This comment was marked as outdated.
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
pimlock
commented
Sep 19, 2026
pimlock
left a comment
Collaborator
Author
There was a problem hiding this comment.
gator-agent
PR Review Status
I reconciled the current head against the full Gator feedback ledger and reviewed the author-only delta since bd9f91e5 in critical-only mode. The range-diff shows all ten PR-authored commits are patch-identical after the merge from main, the earlier fanout-bounding obligation remains resolved, and no new Critical defect was found. Current-head Branch Checks and E2E workflows are running.
Blocking findings:
- No blocking findings remain
Carried findings:
- None
Gator metadata
- Validation: Project-valid Stage 1 of accepted issue #1731; the effective PR patch remains within the reviewed gateway/supervisor configuration-delivery scope.
- Docs: Architecture and Fern gateway-reference documentation remain included for the current behavior.
- Checks: OpenShell Helm Lint and Trivy Changes are green; Branch Checks and E2E are pending on the current head.
- E2E:
test:e2eandtest:e2e-kubernetesare applied; the current-head Branch E2E Checks workflow is running. - Head SHA:
8dfe13b575a931586a5bb26238230227bdc40d82 - Base SHA:
fa0bfa490e42c87a74a70be6ebb40faee7fb8faa - Merge base SHA:
fa0bfa490e42c87a74a70be6ebb40faee7fb8faa - Patch ID:
ca184a2ffbb6b7e1d73cbd0fc2a97533eca331e3 - Gator payload:
9 - Review mode:
critical_only - Previous reviewed SHA:
bd9f91e593c2096542599aebaad43a2c179426e9 - Review budget exhausted: yes
- Maintainer decision required: no
- Next state:
gator:watch-pipeline
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Replace the bounded delivery queue with a synchronous scheduler that never rejects admission. Every publication takes a sequence number and a key is rebuilt only while its last build predates the publication, so repeated publications coalesce. Fanouts are cursors over sorted recipients; direct and fanout builds share build slots with a direct reserve and a fanout floor, and a separate route lane handles owner lookups and peer hints. Provider instance changes and credential refreshes publish a targeted provider scope that fans out only to sandboxes attached to that provider, filtered by a monotonic attachment cache. Add the PeerConfigProviderTarget hint scope and remove the unreleased queue_full field. Push-mode sessions get one latest-wins slot per component, drained by an outbound stream that sends control frames first. Sessions register with the scheduler only after setup succeeds and only while still current, and recipient epochs fence stale tickets. Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Resolve the failed-create cleanup against the version-guarded delete from main: remove the initial policy revision only after the sandbox row is deleted. Regenerate Go bindings, update the public schema fingerprint, and add PeerNotifyConfigUpdate to the new CLI exec streaming mock gateway. Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Replace the exact-match protocol_revision handshake with a SupervisorHello.supports_config_snapshots capability, matching the existing supports_provider_readiness pattern. Peers no longer reject unknown revisions, so gateway rollback and mixed-version HA replicas keep supervisor sessions alive. SessionAccepted no longer carries a revision. Document SandboxConfigSnapshot and ProviderEnvironmentSnapshot as the canonical configuration shapes, with the GetSandboxConfig and GetSandboxProviderEnvironment responses as polling projections. State ProviderEnvironmentValue invariants and number its expiration_time field 3 instead of reserving a field that never shipped. Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Replace the shared 45-second build deadline with one per component. Sandbox configuration builds only read the store, so 5 seconds is ample. Provider environment builds also resolve credentials; 20 seconds covers a cold Vault Kubernetes-auth login plus a read at the default request timeout. A stalled build no longer holds a build slot for 45 seconds. Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Take main's failed-create path, which compensates through the normal delete and already removes policy revisions. Compensate the same way when initial policy history fails, so a prepared SSH identity is cleaned up. Update the public schema fingerprint. Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
TL;DR Supervisors currently poll the gateway for configuration every 10 seconds. This PR adds an opt-in push path. Polling remains authoritative in 0.1.x.
Stage 1 sends full snapshots when the gateway setting is
pushand the supervisor advertises snapshot support. Each update reaches the gateway that owns the affected supervisor session. The supervisor ignores the snapshot. Its existing polling path still applies configuration.The setting defaults to
pollin 0.1.x. The plan makes push the default in 0.2.0, deprecates polling there, and removes polling APIs in 0.3.0. Helm users can set this field throughgatewayConfigafter #3384 lands.Tip
Overview of changes.
Related Issue
Part of #1731. Stage 2 (#3265) will apply and acknowledge snapshots. Stage 3 (#3273) will track completion of global updates.
Changes
SupervisorHello.supports_config_snapshotsso older supervisors keep polling.Testing
mise run pre-commit; Rust workspace and server tests;mise run go:ci;mise run sdk:ts:ciconfig_delivery_mode = "push"fromgatewayConfigsandbox_file_sync_survives_gateway_pod_rollsfailed in 2 of 3 push runs and 1 of 3 poll runs with the same "sandbox is not ready" retry error, so it is an existing flake, not a push regression.Checklist