Skip to content

feat(providers): support stable credential placeholders - #3339

Open
shiju-nv wants to merge 3 commits into
NVIDIA:mainfrom
shiju-nv:feat/stable-placeholders
Open

shiju-nv wants to merge 3 commits into
NVIDIA:mainfrom
shiju-nv:feat/stable-placeholders

Conversation

@shiju-nv

@shiju-nv shiju-nv commented Sep 15, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

An external issuer can install credential B in OpenShell while a running client keeps using A through its original reference. This PR adds credentials[].stable_placeholder: true so the client's next authorized request uses B after the supervisor applies the update, without restarting the client or reloading its reference. OpenShell already provides this continuity for gateway-managed token refresh; this extends it to externally supplied static credentials.

Related Issue

Closes #3336

Changes

Our motivating workload is a long-running agent that calls MCP tools through an MCP gateway and authenticates to it with a short-lived signed assertion in a request header. A host service rotates that assertion, then updates its OpenShell provider. The agent holds an OpenShell reference in the header. Once the old assertion is revoked, the next tool call needs to use the new one without interrupting the agent session. The issuer keeps responsibility for signing and rotation, and the real assertion stays outside the agent.

  • Reuse the stable-handle resolver for explicitly opted-in external credentials. Value-only updates keep the reference usable; expiry, detach, provider replacement, or changes to its identity or endpoint binding revoke access to the replacement credential.
  • Preserve revision-scoped references by default and retain existing endpoint and binary restrictions. Hand-written aliases cannot grant access.
  • Check gateway support before CLI or Go SDK profile writes, and require gateway and supervisor support before delivering opted-in credentials. Preserve that requirement across failed refreshes and supervisor reconstruction.
  • Reject incompatible profiles, including credentials owned by managed refresh or token grants. Carry the opt-in through protobuf and Go SDK types, and keep legacy stored profiles disabled by default.
  • Add a persistent-client HTTPS regression based on the caller-assertion workload. It makes a synthetic MCP tools/call, verifies the backend's observed credential generation, and checks endpoint restrictions, TLS verification, and detach with independent reachability controls.

Enabling the opt-in requires a supporting profile client, gateway, and supervisor. Raw API clients must check the lint support acknowledgment before writing the field, because an older gateway can discard unknown fields. Remove and apply the opt-in before downgrading. Existing profiles keep their current behavior.

Testing

  • Checks appropriate to the affected code and behavior pass
  • Unit tests added/updated
  • E2E tests added/updated

Checklist

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

This pull request has had no activity for 14 days and is now marked stale. It may be closed in 7 days if there is no further activity.

@github-actions github-actions Bot added the state:stale Inactive item at risk of automatic closure. label Oct 1, 2026
Add credentials[].stable_placeholder so a running client keeps using an externally rotated static credential through the reference it already holds. Squashed replay of the earlier four commits onto upstream main 71c3cd9; re-derives the frozen schema fingerprints and adapts the provider environment revision test to the added capability argument.

Signed-off-by: Shiju <shiju@nvidia.com>
@shiju-nv
shiju-nv force-pushed the feat/stable-placeholders branch from cf79135 to 208706f Compare October 4, 2026 15:29
@github-actions github-actions Bot removed the state:stale Inactive item at risk of automatic closure. label Oct 5, 2026
Comment thread docs/about/architecture.mdx Outdated
path. The outer fence denies everything else, so the agent can't reach a
service, the gateway, DNS, or another private address directly.

### Keep Credential References Current

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Would prefer to keep this page pretty lean, this is too much detail for this page. Suggest removal and rely on other pages to explain this functionality.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated the page.

@johntmyers johntmyers added the test:e2e Requires end-to-end coverage label Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Label test:e2e applied for 208706f. Open the existing run and click Re-run all jobs to execute with the label set. The run will execute the standard E2E suite after building the required gateway, sandbox, and supervisor images once. The matching required CI gate status on this PR will flip green automatically once the run finishes.

@johntmyers johntmyers left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

PR Review Status

The independent review found no blocking code defects in the current patch. This implements the external-rotation use case in #3336 while preserving revision-scoped credentials by default.

John (@johntmyers), I checked your question about #2780: that change handles gateway-managed refresh, while this opt-in covers credentials rotated by an external issuer. I also checked your request to keep the architecture page lean; the provider-profile page already explains the feature, so the author can remove the added architecture section as you suggested.

Blocking findings: None.

Carried findings: None.

Non-blocking suggestions: Address John's architecture-page suggestion before maintainer handoff.

Gator metadata
  • Validation: Implements the concrete external credential rotation scenario and acceptance criteria in #3336; explicitly requested for review by the operator.
  • Docs: Provider-profile Fern documentation and CLI skill updated; architecture-page placement remains a maintainer editorial follow-up.
  • Checks: Current-head Branch Checks, Helm Lint, Trivy Changes, and DCO passed. Runtime E2E previously skipped without its label.
  • E2E: test:e2e applied; Branch E2E Checks run 37213177413 attempt 2 confirmed queued on the current head after the bot-requested rerun.
  • Head SHA: 208706ffea3c1b868379e39482d1a93cd54636e1
  • Base SHA: 71c3cd957abef062eb7f37010056717cd49f2ed3
  • Merge base SHA: 71c3cd957abef062eb7f37010056717cd49f2ed3
  • Patch ID: efa28d6234a44906b8da437b9a2c03c83d501529
  • Gator payload: 10
  • Review mode: initial
  • Previous reviewed SHA: none
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Next state: gator:watch-pipeline

@johntmyers johntmyers added gator:watch-pipeline Gator is monitoring PR CI/CD status gator:approval-needed Gator completed review; maintainer approval needed gator:blocked Gator is blocked by process or repository gates and removed gator:watch-pipeline Gator is monitoring PR CI/CD status gator:approval-needed Gator completed review; maintainer approval needed labels Oct 5, 2026
Preserve provider fetch tracing alongside stable-placeholder compatibility checks.
Remove the detailed architecture subsection and keep rotation guidance in the provider-profile docs.

Signed-off-by: Shiju <shiju@nvidia.com>

@johntmyers johntmyers left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

PR Review Status

The independent follow-up review found no blocking findings in the author’s changes since the previous review. The merge reconciliation preserves provider-fetch tracing alongside stable-placeholder compatibility checks.

Shiju (@shiju-nv), I checked your “Updated the page” reply: the architecture subsection John (@johntmyers) asked to remove is gone, and the provider-profile page retains the rotation guidance.

Blocking findings: None.

Carried findings: None.

Gator metadata
  • Validation: Continues the external credential rotation use case in #3336.
  • Docs: Provider-profile Fern guidance retained; architecture-page editorial request addressed.
  • Checks: Current-head Branch Checks, Helm Lint, Trivy Changes, and DCO passed. E2E remains pending.
  • E2E: test:e2e is present; current-head Branch E2E Checks run 37413151392 is in progress, with runtime suites executing. No additional dispatch is needed.
  • Head SHA: 90916b9f91213110d8f1e483dad90a223e11982b
  • Base SHA: fb8f6c0885127fe4ca29993739131a3bdbaed477
  • Merge base SHA: fb8f6c0885127fe4ca29993739131a3bdbaed477
  • Patch ID: 418ffad787bad0be086458c02da9c38d92c0e6f1
  • Gator payload: 10
  • Review mode: follow_up
  • Previous reviewed SHA: 208706ffea3c1b868379e39482d1a93cd54636e1
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Review telemetry: 1 prior round; 0 unique findings; 0 duplicate IDs; 0 unchanged-code proposals in this follow-up.
  • Next state: gator:watch-pipeline

@johntmyers johntmyers added gator:watch-pipeline Gator is monitoring PR CI/CD status gator:blocked Gator is blocked by process or repository gates and removed gator:blocked Gator is blocked by process or repository gates gator:watch-pipeline Gator is monitoring PR CI/CD status labels Oct 6, 2026
@johntmyers johntmyers added gator:in-review Gator is reviewing or awaiting PR review feedback and removed gator:watch-pipeline Gator is monitoring PR CI/CD status labels Oct 6, 2026
Use ManagedGateway's per-process supervisor image override so the fixture
CA reaches the supervisor when runtime image environment variables take
precedence over gateway TOML. Restore the wrapper's original image after
each test, following the provider-readiness fixture.

Signed-off-by: Shiju <shiju@nvidia.com>

@johntmyers johntmyers left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

PR Review Status

The independent follow-up review found no blocking findings in the latest E2E fixture changes. Shiju (@shiju-nv), I checked your supervisor-image fix: the fixture now uses the harness's per-process image override and restores the wrapper's original image after each case.

Blocking findings: None.

Carried findings: None.

Gator metadata
  • Validation: Continues the external credential rotation use case in #3336.
  • Docs: Provider-profile Fern guidance remains in place; this test-only delta needs no additional user documentation.
  • Checks: Current-head Branch Checks, Helm Lint, Trivy Changes, and DCO passed. Required E2E is still pending.
  • E2E: test:e2e is present; current-head Branch E2E Checks run 37422887776 attempt 1 is in progress. No additional dispatch is needed.
  • Head SHA: 9b069aabe4e15da1f37373e13d7e4424e596af05
  • Base SHA: fb8f6c0885127fe4ca29993739131a3bdbaed477
  • Merge base SHA: fb8f6c0885127fe4ca29993739131a3bdbaed477
  • Patch ID: 6dba816a478fd0daf3ea2a98ae017907d981621d
  • Gator payload: 10
  • Review mode: follow_up
  • Previous reviewed SHA: 90916b9f91213110d8f1e483dad90a223e11982b
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Review telemetry: 2 prior rounds; 0 unique findings; 0 duplicate IDs; 0 proposed findings, unchanged-code proposals, or missing-reproducer downgrades in this follow-up.
  • Next state: gator:watch-pipeline

@johntmyers johntmyers added gator:watch-pipeline Gator is monitoring PR CI/CD status gator:approval-needed Gator completed review; maintainer approval needed and removed gator:in-review Gator is reviewing or awaiting PR review feedback gator:watch-pipeline Gator is monitoring PR CI/CD status labels Oct 6, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gator:approval-needed Gator completed review; maintainer approval needed test:e2e Requires end-to-end coverage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Keep credential references current after external rotation

2 participants