Skip to content

Expose PERMITTED_CORS_ORIGINS as a Replicated/KOTS installer config option #760

Description

@jpshackelford

Summary

Expose PERMITTED_CORS_ORIGINS as a first‑class KOTS/Replicated installer config option (wired into the openhands chart's env) so self‑hosted OHE operators can allow additional cross‑origin browser clients — e.g. OpenHands Agent Canvas — without a bespoke channel release or a manual KOTS kustomize patch.

Context: customer support case where Agent Canvas (origin http://localhost:8000 / a hosted Canvas origin) cannot connect to a self‑hosted OHE because the app server rejects the cross‑origin preflight. Internal tracking: CS‑8. Related client‑side bug: OpenHands/Agent-Canvas#1513.

Why this is needed

The enterprise app server already reads PERMITTED_CORS_ORIGINS from its environment:

# OpenHands repo: enterprise/server/constants.py
WEB_HOST = os.getenv('WEB_HOST', 'app.all-hands.dev').strip()
PERMITTED_CORS_ORIGINS = [
    host.strip()
    for host in (os.getenv('PERMITTED_CORS_ORIGINS') or f'https://{WEB_HOST}').split(',')
    ...
]

…and the chart already has a generic env override (.Values.env, user overrides win):

But there is no way to set it from the installer. I enumerated every option in replicated/config.yaml — there is no CORS field and no free‑form "additional env" input. The Replicated values.env: block is vendor‑templated from fixed config options:

So today the only ways to set PERMITTED_CORS_ORIGINS are: (a) a bespoke release that hard‑codes it into the env: block, or (b) a KOTS downstream kustomize patch on the openhands Deployment. Neither is self‑service.

Proposed change

  1. Add a Config option (suggest placing under domain_configuration or advanced_options):

    - name: permitted_cors_origins
      title: Additional Permitted CORS Origins
      type: text
      default: ""
      help_text: >
        Comma-separated list of additional browser origins allowed to call this
        deployment's API cross-origin, e.g.
        https://canvas.example.com,http://localhost:8000
        This deployment's own app URL is always permitted. Required for browser
        clients hosted on a different origin, such as OpenHands Agent Canvas.
  2. Wire it into the openhands HelmChart values.env: block in replicated/openhands.yaml (around L23), including the app's own origin so the default isn't clobbered:

    {{repl if ConfigOption "permitted_cors_origins" }}
    PERMITTED_CORS_ORIGINS: 'https://{{repl ConfigOption "app_hostname" }},{{repl ConfigOption "permitted_cors_origins" }}'
    {{repl end }}

    ⚠️ Implementation note: constants.py uses os.getenv('PERMITTED_CORS_ORIGINS') or f'https://{WEB_HOST}' — setting the env var replaces the default rather than appending. The template must therefore always include the deployment's own app origin (app_hostname) plus the operator‑supplied extras, or the app's own UI could be locked out.

Acceptance criteria

  • A new installer Config field lets an admin enter additional CORS origins.
  • It sets PERMITTED_CORS_ORIGINS on the openhands app deployment, containing the app's own origin plus the configured extras.
  • A browser client on a listed origin completes a CORS preflight against /server_info and /api/v1/... (verify Access-Control-Allow-Origin echoes the origin).
  • Empty/unset value preserves current behavior (default https://{WEB_HOST} only).
  • Brief docs note for operators connecting Agent Canvas / external browser UIs.

Notes

  • Works on all current app‑server versions, no image upgrade required. constants.py has read PERMITTED_CORS_ORIGINS since the enterprise CORS code landed, so this unblocks even older deployments (e.g. the customer on cloud-1.29.1).
  • This is the explicit allow‑list route and is independent of the API‑key permissive CORS path (OpenHands #14473 / #14835); operators get a deterministic fix without relying on that path.
  • For non‑KOTS/raw‑Helm installs, the same value is settable today via .Values.env.PERMITTED_CORS_ORIGINS; this issue is specifically about surfacing it in the KOTS installer.

This issue was filed by an AI agent (OpenHands) on behalf of the All Hands team while investigating a customer support case.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    customer-supportIssues and PRs related to customer support requestsenhancementNew feature or requestopenhands-enterpriseRelated to OpenHands EnterprisereplicatedRelated to the replicated installer

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions