Conversation
Signed-off-by: Mrunal Patel <mrunalp@gmail.com>
|
Label |
|
🌿 Preview your docs: https://nvidia-preview-pr-4213.docs.buildwithfern.com/openshell |
Signed-off-by: Mrunal Patel <mrunalp@gmail.com>
|
agent review that I sent mrunalp via slack earlier, just for the record: Reviewed [#4213](#4213) at I found two compatibility gaps:
The rollout needs coordination:
I ran 266 gateway Helm tests—all passed—and reproduced the URL rewriting behavior. I did not rerun the Rust suite or live Kubernetes isolation tests; required CI checks remain pending. Our local implementation is untouched. |
|
/ok to test 914000a |
Summary
Allow operators to expose sandbox applications on a separate gateway listener while restricting privileged control-plane access to the primary listener. Shared-port routing remains the default.
Related Issue
Closes #4210
Changes
service_bind_address,--service-port/OPENSHELL_SERVICE_PORT, and Helmservice.ingressPort, with port-conflict validation at startup and preflight.service_public_port, Helmservice.ingressNodePort, andservice.ingressPublicPort. A fixed ingress NodePort is advertised automatically; automatically allocated NodePorts must be queried and configured explicitly.CreateSandboxandExposeServicereplays from current configuration for all API clients, preserving the original resource identities and service names. Advertise the reachable service port in gRPC metadata so updated CLI output does not substitute the control-plane port.Testing
e2e/rust/e2e-kubernetes.sh; the wrapper stopped before deployment because Docker is not running and no cluster context is configured. Live E2E verification remains pending.For OCE rollout, enable
service.ingressPort, updatenetwork.providerHarness, and restrict Agent Gateway access to the ingress port. Upgrade older CLIs before enabling the split because they still rewrite service URLs to the control-plane port.Checklist