Commit a7aa90d
committed
feat(sandbox): write agent output to the container log
Since #2726 the canonical main process's stdout and stderr are captured
in pipes that feed only the in-memory replay buffer used by sandbox
connect. Agent output therefore never reaches the container's own stdout
and stderr, so it is missing from kubectl logs, docker logs, and podman
logs and from anything that collects container logs. Before #2726 the
entrypoint inherited the container's descriptors and its output appeared
there.
Copy the main process's output to the launcher's stdout and stderr in
addition to the replay buffer, restoring the earlier behavior:
- Output is copied byte for byte to the matching stream from a
forwarder thread per stream, after it is published to the replay
buffer. When the container runtime falls behind on a stream, that
stream's reader waits instead of dropping output, so backpressure
reaches the agent as it did with inherited descriptors, while the
other stream and attachments keep receiving output.
- Before the main process's exit is published, the output readers
finish and queued output is drained to the container log, so an
agent's final lines are not lost at shutdown. A 30 second deadline
covers both; when it expires, readers waiting on the container log
are released and drain the pipes into the replay buffer only, so a
stalled container log cannot block exit reporting.
- PTY-mode processes are not copied. The terminal stream carries escape
sequences and echoed input, and terminal commands never reached the
container log before #2726.
- Exec, SSH, and SFTP sessions are not copied.
Launcher log lines keep their existing format and remain in the
container's stderr. They are written as whole lines, and a newline is
inserted first when the agent left stderr mid-line, so launcher and
agent lines do not merge.
The Docker driver appended the tail of the workload container's log to
failure messages, which land in the sandbox's Ready condition and in
platform events that the gateway republishes to the sandbox event
stream. With agent output in that log, those messages would carry
arbitrary agent output, including anything sensitive the agent prints,
into gateway status and events. The supervisor starts its health
endpoint only after the agent starts, so every failure path could
include agent output. Forward only the supervisor container's log
tail, matching the Podman driver, which reads the workload log solely
to match fixed launcher markers and never forwards raw workload output.
The workload container's log remains available through docker logs.
Document where main process output appears in the logging docs and the
cluster debugging skill.
Closes #3928
Signed-off-by: Kris Hicks <khicks@nvidia.com>1 parent 7caff12 commit a7aa90d
8 files changed
Lines changed: 681 additions & 32 deletions
File tree
- crates
- openshell-driver-docker/src
- openshell-sandbox/src
- docs/observability
- skills/debug-openshell-cluster
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5302 | 5302 | | |
5303 | 5303 | | |
5304 | 5304 | | |
5305 | | - | |
5306 | | - | |
5307 | | - | |
5308 | | - | |
5309 | | - | |
5310 | | - | |
5311 | 5305 | | |
5312 | 5306 | | |
5313 | 5307 | | |
| |||
5358 | 5352 | | |
5359 | 5353 | | |
5360 | 5354 | | |
5361 | | - | |
5362 | | - | |
5363 | | - | |
5364 | | - | |
5365 | | - | |
| 5355 | + | |
| 5356 | + | |
| 5357 | + | |
5366 | 5358 | | |
5367 | 5359 | | |
5368 | 5360 | | |
| |||
5375 | 5367 | | |
5376 | 5368 | | |
5377 | 5369 | | |
5378 | | - | |
5379 | 5370 | | |
5380 | | - | |
5381 | | - | |
5382 | | - | |
| 5371 | + | |
| 5372 | + | |
5383 | 5373 | | |
5384 | 5374 | | |
5385 | 5375 | | |
| |||
5388 | 5378 | | |
5389 | 5379 | | |
5390 | 5380 | | |
5391 | | - | |
5392 | | - | |
5393 | | - | |
5394 | | - | |
5395 | 5381 | | |
5396 | 5382 | | |
5397 | 5383 | | |
5398 | | - | |
| 5384 | + | |
5399 | 5385 | | |
5400 | 5386 | | |
5401 | 5387 | | |
| |||
0 commit comments