You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 9708ba9
Browse filesBrowse the repository at this point in the historyBrowse files
* feat(providers): report applied sandbox provider changes
Record exact provider mutation targets in shared configuration operations.
Require authenticated evidence that credentials, effective policy, and the
workload launch environment have been installed before reporting readiness.
Add bounded CLI and Rust SDK status and wait support, preserving ordinary
revision-scoped references for existing processes. Verify new-client rotation
and acknowledged detach revocation without external-stable resolver changes.
Signed-off-by: Shiju <shiju@nvidia.com>
* fix(providers): align readiness times with protobuf contracts
Represent readiness receipts, status, and operation times with Timestamp
and report intervals with Duration. Reserve the scalar field tags, update
all consumers and generated bindings, and preserve timestamp presence
and nanosecond identity through storage and client validation.
Qualify both empty-map constructors in the Linux boundary test so its
module compiles while retaining the explicit default required by Clippy.
Signed-off-by: Shiju <shiju@nvidia.com>
* fix(cli): preserve provider mutation storage uncertainty
Recognize the gateway's exact structured storage-uncertainty reason for
provider attach, detach, and update. Explain that the change may already
be saved and must be reconciled before retrying, without exposing server
messages or metadata. Preserve uncertainty ahead of generic retry hints.
Exercise saved mutations through the CLI and verify single submission,
redaction, missing receipt handling, and untrusted error-detail rejection.
Document the recovery guidance for users and the public CLI skill.
Signed-off-by: Shiju <shiju@nvidia.com>
* fix(cli): explain denied provider profile lookups
Report exact and alias profile lookup denials with fixed permission and workspace guidance. Keep backend details redacted and stop before provider mutations.
Cover denied create and update calls through the CLI. Verify the complete provider list independently in the cross-workspace OIDC regression, extracting its JSON object from surrounding startup diagnostics.
Signed-off-by: Shiju <shiju@nvidia.com>
---------
Signed-off-by: Shiju <shiju@nvidia.com>
Copy file name to clipboardExpand all lines: architecture/gateway.md
+30-1Lines changed: 30 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -387,6 +387,8 @@ Public RPC contracts and durable protobuf formats have separate ownership. The `
387
387
388
388
`ReportEndpointStatus` is a sandbox-authenticated public gateway RPC. Its request, response, and `EndpointObservation` messages belong only to the public closure. `EndpointStatus` and `EndpointResult` also belong to the durable closure because `Sandbox.status.endpoint_statuses` persists them. The repeated status field uses a new wire tag; stored sandboxes without it decode with an empty endpoint list and retain their lifecycle fields. A fixed payload encoded with the earlier sandbox schema verifies that no database rewrite is required.
389
389
390
+
`GetSandboxProviderStatus` and `ReportProviderReadiness` are unary public gateway RPCs. The first lets authorized users inspect a provider change; the second accepts installation reports only from the sandbox's current authenticated supervisor session.
391
+
390
392
The removed `NetworkBinary.harness` field remains reserved by number and name,
391
393
so protobuf implementations cannot reuse its wire slot or source identifier.
392
394
The durable-policy compatibility decoder reads the former boolean before Prost
@@ -408,8 +410,10 @@ than extending the frozen message.
408
410
| SQL materializations |`StoredPolicyRevision`, `StoredDraftChunk`| Server-only typed results assembled from indexed columns and decoded payloads; not public RPC messages. |
409
411
| Public messages used directly as encoded storage roots |`Sandbox`, `SandboxWorkloadTemplate`, `Provider`, `Workspace`, `WorkspaceMember`, `SshSession`, `ServiceEndpoint`| The generated public type is also the persisted payload. `SshSession` is not in the current public RPC message closure. |
410
412
| Embedded encoded root |`SandboxPolicy`| Stored in policy rows and inside the JSON settings envelope. |
413
+
| Configuration operation storage root |`StoredConfigUpdateOperation`| One common operation resource stores the exact provider target, receipt projection, snapshot failure reason, and historical outcome. |
414
+
| Public dependencies of an operation |`ConfigUpdateOperation`, `ProviderMutationReceipt`, `ProviderReadinessReason`| Their complete message and enum closures are durable contracts. |
411
415
412
-
The descriptor-derived test inventories the complete message and enum closure of the encoded durable roots and its intersection with the public RPC closure. The tables here record the reviewed roots and classifications.
416
+
The descriptor-derived test owns the complete public, durable, and intersecting inventories and their reviewed fingerprints. The tables here record their roots and classifications. A synthetic sandbox-spec byte fixture verifies that an absent server-owned attachment epoch decodes to the valid empty initial identity; direct and template creation tests separately require the gateway to replace any caller-supplied epoch.
413
417
414
418
Public delete, membership-removal, and SSH-revocation responses use
415
419
`DeletionOutcome`, not a transport-success boolean. `COMPLETED` establishes
@@ -439,6 +443,9 @@ require a request UUID for the admission contract.
439
443
|`SshSession`| Defer a storage twin; govern its complete dependency closure as durable. |
440
444
|`ServiceEndpoint`| Defer a storage twin; govern its complete dependency closure as durable. |
441
445
|`SandboxPolicy`| Defer a storage twin; govern its complete dependency closure as durable. |
446
+
|`ConfigUpdateOperation`| Persist the common historical outcome within `StoredConfigUpdateOperation`; govern its complete dependency closure as durable. |
447
+
|`ProviderMutationReceipt`| Persist the immutable provider projection within `StoredConfigUpdateOperation`; govern its complete dependency closure as durable. |
448
+
|`ProviderReadinessReason`| Persist only the closed snapshot failure category within the operation; govern its enum values as durable. |
442
449
443
450
The public/storage overlap is deliberate for the current format. Storage twins
444
451
for the public roots are deferred: introducing them would require a broad
@@ -739,6 +746,28 @@ configuration, valid endpoint-bound static credentials from other attached
739
746
providers, and the dynamic credential snapshot. Provider environment revisions
740
747
include profile endpoint and binding changes.
741
748
749
+
The supervisor owns provider fetching, support negotiation, and credential resolution outside the workload. The authenticated sandbox boundary receives a revision and its prepared child environment from one snapshot; it preserves the issued placeholders without receiving the secret resolver or turning those placeholders into new references.
750
+
751
+
Provider mutations return immutable per-sandbox receipts that separate saved desired state from observed runtime installation. A receipt pins sandbox and provider identity, the attachment epoch, and the exact provider/configuration/policy fingerprints. Attachment-set changes replace the epoch in the same sandbox CAS write; credential updates stage distinct backend objects before publishing their handles and provider revision. This prevents a published revision from referring to an unfinished in-place credential write. Update receipts retain the sandbox target set selected before publication.
752
+
753
+
Each receipt projects a common configuration operation in the `config_update_operation` store; its receipt ID is the operation ID. The provider status path evaluates current installation evidence and records historical terminal outcomes through resource-version CAS. A previously applied operation does not bypass current session, freshness, or authority checks. The live provider projection can be pending after disconnection or superseded after another change even when historical operation state remains applied. Pending operations are evaluated through provider status queries; this path adds no background delivery engine or mutation replay contract.
754
+
755
+
When a provider mutation opts into admission with `request_id`, its replay record retains references to the original configuration operations and the original mutation ID. Replay returns those immutable receipts even if sandbox attachments have since changed; it does not select new targets or create replacement receipts. Missing operation evidence makes replay unavailable without executing the mutation again. Provider resources still require their original recorded version, and sandbox resources retain the replay contract's current-state projection.
756
+
757
+
Provider mutation and operation-result writes are separate. A result-storage failure can follow a saved mutation and returns structured uncertainty without a rollback or safe-retry claim. A failed initial snapshot remains failed rather than acquiring a different target during a later lookup. Operations contain only identities, revisions, timestamps, and closed reason categories.
758
+
759
+
The CLI recognizes the gateway's `CONFIG_OPERATION_STORAGE_UNCERTAIN` error reason and domain for attach, detach, and update. It reports fixed guidance to inspect and reconcile the saved change before retrying, while withholding arbitrary server messages and error metadata. An uncertain mutation never starts a readiness wait or automatic replay.
760
+
761
+
Provider receipts, installation status, and common operations represent absolute times with protobuf `Timestamp`; report intervals and evidence lifetimes use protobuf `Duration`. Receipt identity compares the full canonical timestamp without truncating nanoseconds. An absent observation or completion time represents missing evidence or an unfinished operation, independently of the Unix epoch.
762
+
763
+
Provider installation reports belong to the existing `ConnectSupervisor` session. Each report names that session, has an increasing sequence, and expires unless the supervisor reports again. Reconnection or disconnect invalidates prior observations; stored change records survive a gateway restart, but runtime evidence does not. Replaying an identical report cannot extend its lifetime.
764
+
765
+
Reports and status also compare the supervisor instance with the sandbox's persisted current instance. A different supervisor becoming current invalidates an older connection, including one retained by another gateway replica. Observations stay local to the gateway holding the supervisor session; a status request reaching a replica without that session returns pending. Multi-replica deployments therefore retain the existing supervisor-session routing requirement.
766
+
767
+
The supervisor reports success only after it installs the matching credentials, activates the effective policy, and receives an acknowledgment from the authenticated workload boundary that it installed the environment for future processes. Environment synchronization shares the process-launch lock, and its acknowledgment identifies the exact publication, including retries at the same provider revision. Failed policy installation cannot reuse evidence for a different installed policy. Ready and revoked statuses also recheck the requested sandbox, provider, attachment and configuration identities; revision fingerprints are compared only for equality. Revocation applies to future credential resolution and future processes. Requests already forwarded upstream can still finish.
768
+
769
+
Ordinary static credentials retain revision-scoped references. After update readiness, a newly launched process receives the updated reference; an existing process keeps its original revision. Installation completion does not retarget that reference or establish that an old upstream key can be retired.
770
+
742
771
## Provider Environment Resolution
743
772
744
773
The gateway resolves only the providers attached to a sandbox. It combines each
0 commit comments