Conversation
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
drew
requested review from
a team,
derekwaynecarr,
mrunalp and
sjenning
as code owners
October 6, 2026 06:19
|
🌿 Preview your docs: https://nvidia-preview-pr-4230.docs.buildwithfern.com/openshell |
drew
marked this pull request as draft
October 6, 2026 06:21
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Exposed sandbox HTTP services now report continuously observed health. Services check listener responsiveness by default; configuring a readiness path requires a 2xx response, and the Codex app-server example uses
/readyz.Related Issue
Closes #4229
Changes
Service contract
A service remains an exposed loopback HTTP port identified by workspace, sandbox, and service name (empty name selects the unnamed endpoint). Readiness uses that same target port and relay; it does not require another listener or route.
Configuration and response
ExposeServiceRequestand create-timeSandboxServiceExposureaccept an optionalreadiness_check. The persistedServiceEndpointreturns the effective configuration. Existing expose/get/list RPCs return health alongside the endpoint and URL:GET /readiness_check: { path: "/readyz" }GET /readyzAn empty configured path resolves to
/. Paths must begin with/, be at most 1,024 bytes, and contain no query, fragment, whitespace, or alternate host. Omitting the check when updating an existing service preserves its configuration. Removing the check requires deleting and recreating the endpoint in this version.Continuous observation
last_checked_time,message, and optionalhttp_status_codedescribe the latest attempt. The code is present only when response headers arrived. Clients should branch onstate, because thresholds can leave the state healthy while the latest attempt failed.The CLI adds
service expose --readiness-path PATHandsandbox create --expose-readiness-path PATH(requires--expose). Service output showsReady/Not readyfor configured readiness andResponsive/Unresponsiveotherwise. The Codex example sets--expose-readiness-path /readyz.Testing
mise run pre-commit, schema inventory, scoped Rust checks, TypeScript SDK CI, focused Go SDK tests and lint, and docs checks.OPENSHELL_E2E_DOCKER_TEST=service_bearer_passthrough mise run e2e:dockerpasses, including readiness transitions, closed targets, stopped sandboxes, unchanged routing, and authorization passthrough./readyzreturns HTTP 200 without credentials.Full
mise run go:cireaches unrelated gateway tests that assume no system gateway configuration; this machine has/etc/openshell/gateways/default. Focused service/client/converter tests and Go lint pass.Checklist