Conversation
BlockedGator is blocked because the current branch conflicts with Next action: @feloy, rebase or merge the latest Gator metadata
|
Closes NVIDIA#3545 Validate and stage operator-owned proxy CA bundles for Docker supervisors, add corporate proxy E2E coverage, and document the trust contract. Signed-off-by: Philippe Martin <phmartin@redhat.com>
e324162 to
9b05d9f
Compare
|
/ok to test 9b05d9f |
|
Label |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
The merge conflict is resolved and the full current patch has been reviewed. One startup-path consistency issue still needs an author update before Gator can hand the PR to pipeline monitoring.
Action required: @feloy, make the standalone Docker driver reject incoherent proxy CA configuration during startup and add regression coverage for that entry point.
Blocking findings:
GATOR-9b05d9f4-01: the standalone Docker driver bypasses the new proxy CA configuration validation.
Carried findings:
- None
Gator metadata
- Validation: Project-valid implementation of linked issue #3545; scope matches the Docker corporate-proxy trust contract.
- Docs: Fern documentation and operator diagnostics are updated for the new Docker configuration.
- Checks: Current-head branch checks and E2E are queued or running.
- E2E:
test:e2eapplied;/ok to testaccepted; Branch E2E Checks run 36192072961 is queued as attempt 2. - Head SHA:
9b05d9f4c89ff1596d3cc9ac7b68ac3398756931 - Base SHA:
496ebba293f5cc2bb2753444dddd534f0b4aeb6a - Merge base SHA:
496ebba293f5cc2bb2753444dddd534f0b4aeb6a - Patch ID:
b2506fc4796c4bbd5ef3862c347c25da077c14bc - Gator payload:
9 - Review mode:
initial - Previous reviewed SHA: none
- Review budget exhausted: no
- Maintainer decision required: no
- Next state:
gator:in-review
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
|
/ok to test 30f1c90 |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
The follow-up review confirms that the standalone Docker constructor now validates the full proxy configuration before Docker I/O, with targeted regression coverage. The prior startup-validation finding is resolved and no code-review blockers remain, but the required current-head Docker E2E job failed before Gator could complete pipeline monitoring.
Action required: @NVIDIA/openshell-maintainers, inspect the docker-e2e / E2E (rust-docker) failure in run 36197865788 and either rerun it if the failure is flaky or infrastructure-related, or request the corresponding author fix.
Blocking findings:
- No blocking code-review findings remain.
Carried findings:
GATOR-9b05d9f4-01: resolved by routingDockerComputeDriver::newthroughvalidate_configurationand adding constructor regression coverage.
Gator metadata
- Validation: Project-valid implementation of linked issue #3545; scope matches the Docker corporate-proxy trust contract.
- Docs: Fern documentation and operator diagnostics are updated for the Docker configuration.
- Checks: Branch Checks, Helm Lint, and DCO are green; required
OpenShell / E2Eis failing becausedocker-e2e / E2E (rust-docker)exited with code 101. - E2E:
test:e2eis applied and the current-head workflow completed; detailed job logs are unavailable to this sandbox, and no current-head E2E Label Help instruction requested a rerun. - Head SHA:
30f1c906207c0bbaef3bdc2d18c418bef6ad03f3 - Base SHA:
496ebba293f5cc2bb2753444dddd534f0b4aeb6a - Merge base SHA:
496ebba293f5cc2bb2753444dddd534f0b4aeb6a - Patch ID:
131c7faac70146a6e2080862943e78b7f31dc958 - Gator payload:
9 - Review mode:
follow_up - Previous reviewed SHA:
9b05d9f4c89ff1596d3cc9ac7b68ac3398756931 - Review budget exhausted: no
- Maintainer decision required: no
- Next state:
gator:blocked - Blocked reason:
e2e_failure_diagnosis_required
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
|
/ok to test d9b608b |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
Thanks @johntmyers. I checked your current-head update that replaces the explicit --from base arguments with the harness-managed E2E workload image in all three Docker corporate-proxy scenarios. It addresses the prior rust-docker environment mismatch without reopening the resolved startup-validation finding, and no code-review blockers remain.
Action required: @NVIDIA/openshell-maintainers, approve the current-head Trivy Changes workflow run 36205578960 so the required security check can execute. Gator will also continue watching the active Branch E2E run 36205590139.
Blocking findings:
- No blocking code-review findings remain.
Carried findings:
GATOR-9b05d9f4-01: remains resolved; this E2E-only delta does not alter Docker configuration validation.
Gator metadata
- Validation: Project-valid implementation of linked issue #3545; scope remains within the Docker corporate-proxy trust contract.
- Docs: Fern documentation and operator diagnostics are updated for the Docker configuration.
- Checks: Branch Checks, Helm Lint, and DCO are green; Branch E2E is active; the required Trivy workflow is awaiting maintainer approval.
- E2E:
test:e2eis applied,/ok to test d9b608b0987764f84da13cb7a7878dba92a617f8refreshed the mirror, and current-head Branch E2E run 36205590139 is in progress. - Head SHA:
d9b608b0987764f84da13cb7a7878dba92a617f8 - Base SHA:
496ebba293f5cc2bb2753444dddd534f0b4aeb6a - Merge base SHA:
496ebba293f5cc2bb2753444dddd534f0b4aeb6a - Patch ID:
5814d4d9c02c0e874e4d87753f05d9a88caf159d - Gator payload:
9 - Review mode:
follow_up - Previous reviewed SHA:
30f1c906207c0bbaef3bdc2d18c418bef6ad03f3 - Review budget exhausted: no
- Maintainer decision required: no
- Next state:
gator:blocked - Blocked reason:
trivy_workflow_approval_required
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
|
/ok to test 9283d28 |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
I checked @johntmyers's current-head update that surfaces TLS-interception fixture errors in proxy logs and assertion output. The critical-only delta review found no new Critical defect, the earlier startup-validation finding remains resolved, and no maintainer convergence decision is needed.
Action required: @NVIDIA/openshell-maintainers, approve the current-head Trivy Changes workflow run 36230881275 so the required security check can execute. Branch Checks and the required E2E workflow are already running.
Blocking findings:
- No blocking code-review findings remain.
Carried findings:
GATOR-9b05d9f4-01: remains resolved; this E2E diagnostic-only delta does not alter Docker configuration validation.
Gator metadata
- Validation: Project-valid implementation of linked issue #3545; scope remains within the Docker corporate-proxy trust contract.
- Docs: Fern documentation and operator diagnostics are updated for the Docker configuration.
- Checks: Branch Checks and E2E are active; Helm Lint and DCO are green; required Trivy Changes awaits maintainer workflow approval.
- E2E:
test:e2eis applied,/ok to test 9283d28aa56447dae20c93b13558ae57b1af53b6refreshed the mirror, and current-head Branch E2E run 36230890328 is in progress. - Head SHA:
9283d28aa56447dae20c93b13558ae57b1af53b6 - Base SHA:
496ebba293f5cc2bb2753444dddd534f0b4aeb6a - Merge base SHA:
496ebba293f5cc2bb2753444dddd534f0b4aeb6a - Patch ID:
c42872a1f59746e40c071c331c2397dea86d3e94 - Gator payload:
9 - Review mode:
critical_only - Previous reviewed SHA:
a70b6973d2d3ed012e8348d799b484c31b222fd5 - Review budget exhausted: yes
- Maintainer decision required: no
- Next state:
gator:blocked - Blocked reason:
trivy_workflow_approval_required
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
|
/ok to test 9ea5b0c |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
Thanks @johntmyers. I checked your current-head update that drains already-decrypted TLS bytes before the proxy fixture waits on the underlying sockets. The critical-only delta review found no new Critical defect, the earlier startup-validation finding remains resolved, and no maintainer convergence decision is needed.
Action required: @NVIDIA/openshell-maintainers, approve the current-head Trivy Changes workflow run 36233996817 so the required security check can execute. Branch Checks and Helm Lint are green, and the required E2E workflow is active.
Blocking findings:
- No blocking code-review findings remain.
Carried findings:
GATOR-9b05d9f4-01: remains resolved; this E2E fixture delta does not alter Docker configuration validation.
Gator metadata
- Validation: Project-valid implementation of linked issue #3545; scope remains within the Docker corporate-proxy trust contract.
- Docs: Fern documentation and operator diagnostics are updated for the Docker configuration.
- Checks: Branch Checks and Helm Lint are green; E2E is active; required Trivy Changes awaits maintainer workflow approval.
- E2E:
test:e2eis applied,/ok to test 9ea5b0cfd20a86593e0e65157e93542c228e609crefreshed the mirror, and current-head Branch E2E run 36234007284 is in progress. - Head SHA:
9ea5b0cfd20a86593e0e65157e93542c228e609c - Base SHA:
496ebba293f5cc2bb2753444dddd534f0b4aeb6a - Merge base SHA:
496ebba293f5cc2bb2753444dddd534f0b4aeb6a - Patch ID:
0c86f54b7f6fc899bd7ec95130db46ecd2152cff - Gator payload:
9 - Review mode:
critical_only - Previous reviewed SHA:
9283d28aa56447dae20c93b13558ae57b1af53b6 - Review budget exhausted: yes
- Maintainer decision required: no
- Next state:
gator:blocked - Blocked reason:
trivy_workflow_approval_required
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
|
/ok to test 6b9f004 |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
I checked the current-head update that replaces the bidirectional intercepted-TLS relay with a deterministic one-request HTTP relay. The critical-only delta review found no new Critical defect, the earlier startup-validation finding remains resolved, and no maintainer convergence decision is needed.
Action required: @NVIDIA/openshell-maintainers, approve the current-head Trivy Changes workflow run 36236954334 so the required security check can execute. Branch Checks and the required E2E workflow are already running.
Blocking findings:
- No blocking code-review findings remain.
Carried findings:
GATOR-9b05d9f4-01: remains resolved; this E2E fixture delta does not alter Docker configuration validation.
Gator metadata
- Validation: Project-valid implementation of linked issue #3545; scope remains within the Docker corporate-proxy trust contract.
- Docs: Fern documentation and operator diagnostics are updated for the Docker configuration.
- Checks: Branch Checks and E2E are active; Helm Lint and DCO are green; required Trivy Changes awaits maintainer workflow approval.
- E2E:
test:e2eis applied,/ok to test 6b9f004eb553e86de474dbe4dc60c982a5029a09refreshed the mirror, and current-head E2E is in progress. - Head SHA:
6b9f004eb553e86de474dbe4dc60c982a5029a09 - Base SHA:
496ebba293f5cc2bb2753444dddd534f0b4aeb6a - Merge base SHA:
496ebba293f5cc2bb2753444dddd534f0b4aeb6a - Patch ID:
2d81b60abc3dc93ad18badedd98f62de7ffc2862 - Gator payload:
9 - Review mode:
critical_only - Previous reviewed SHA:
9ea5b0cfd20a86593e0e65157e93542c228e609c - Review budget exhausted: yes
- Maintainer decision required: no
- Next state:
gator:blocked - Blocked reason:
trivy_workflow_approval_required
Summary
Add explicit custom CA bundle support for Docker compute-driver corporate forward proxies. The gateway validates and stages the operator-owned bundle into the supervisor archive at a fixed internal path without exposing the host path to sandbox workloads.
Related Issue
Closes #3545
Changes
proxy_ca_bundleconfiguration.OPENSHELL_SANDBOX_PROXY_CA_BUNDLEin the Docker gateway task.Testing
mise run pre-commitpassescargo test -p openshell-driver-docker— 125 passedcargo test --manifest-path e2e/rust/Cargo.toml --features e2e-docker --test docker_corporate_proxy --no-runbash -n tasks/scripts/gateway-docker.shOPENSHELL_E2E_DOCKER_TEST=docker_corporate_proxy mise run e2e:docker— not run locally because the Docker CLI/daemon is unavailable. Podman is installed, but aliasing it as Docker would not validate the Docker runtime/socket semantics exercised by this path.Checklist