Skip to content

feat(gateway): support runtime image env overrides - #3504

Open
elezar wants to merge 1 commit into
mainfrom
feat/3502-runtime-image-env-overrides/elezar
Open

elezar wants to merge 1 commit into
mainfrom
feat/3502-runtime-image-env-overrides/elezar

Conversation

@elezar

@elezar elezar commented Sep 21, 2026 •

Copy link
Copy Markdown
Member

🏗️ build-from-issue-agent

Summary

Add gateway-process overrides for the trusted sandbox-runtime and supervisor images used by the built-in Docker, Podman, and Kubernetes drivers. They follow the gateway's established CLI > environment > TOML > built-in default contract; because the gateway has no image CLI flags, its effective order is process environment > driver TOML > compiled default.

Related Issue

Closes #3502

Changes

  • Make OPENSHELL_SANDBOX_RUNTIME_IMAGE and OPENSHELL_SUPERVISOR_IMAGE process-level overrides of the existing shared runtime-image defaults.
  • Apply the gateway environment after driver TOML deserialization, matching existing gateway configuration precedence.
  • Add equivalent CLI/environment image options to the standalone Docker driver, matching standalone Podman and Kubernetes behavior.
  • Keep environment values on the same pass-through path as equivalent TOML fields; add no separate OCI parser or image-value logging.
  • Keep trusted image fields outside sandbox request schemas.
  • Convert the shared Debian/RPM package qualification role to inject exact candidate images through packaged gateway.env without generating operator TOML.
  • Move tmachine Docker/Podman trusted-image selection from gateway TOML into the gateway service environment, including the Nix development Podman service.
  • Document precedence, pass-through behavior, supported drivers, package delivery, and trust implications.

Testing

  • mise run pre-commit
  • Focused Rust formatting and compilation
  • Default-resolution unit test
  • Environment-over-TOML precedence test
  • Docker, Podman, and Kubernetes trusted-image request-boundary tests
  • Packaging and tmachine template asset validation
  • Installed-package E2E completes in CI

Commands run:

  • cargo fmt --all --check
  • cargo check -p openshell-core -p openshell-gateway -p openshell-driver-docker -p openshell-driver-kubernetes -p openshell-driver-podman --all-targets
  • cargo test -p openshell-core runtime_image_environment_value_replaces_compiled_default
  • cargo test -p openshell-driver-docker sandbox_driver_config_rejects_trusted_runtime_image_overrides
  • cargo test -p openshell-driver-kubernetes sandbox_driver_config_rejects_trusted_runtime_image_overrides
  • cargo test -p openshell-driver-podman sandbox_driver_config_rejects_trusted_runtime_image_overrides
  • bash tasks/scripts/test-packaging-assets.sh
  • mise run pre-commit

Checklist

  • Follows Conventional Commits
  • Commit is signed off (DCO)
  • Documentation updated
  • Related public debugging skill reviewed; no workflow update is required

@github-actions

Copy link
Copy Markdown

@elezar
elezar force-pushed the feat/3502-runtime-image-env-overrides/elezar branch from d6b0148 to b6b552e Compare September 21, 2026 12:05
@elezar
elezar force-pushed the feat/3502-runtime-image-env-overrides/elezar branch 3 times, most recently from 424296b to 20aead4 Compare October 2, 2026 15:14
Closes #3502

Resolve trusted OCI runtime images with driver TOML, process environment, and compiled-default precedence across Docker, Podman, and Kubernetes.

Signed-off-by: Evan Lezar <elezar@nvidia.com>
@elezar
elezar force-pushed the feat/3502-runtime-image-env-overrides/elezar branch from 20aead4 to 360f46a Compare October 2, 2026 15:30

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(gateway): support process-level runtime image overrides

1 participant