Summary
Expose PERMITTED_CORS_ORIGINS as a first‑class KOTS/Replicated installer config option (wired into the openhands chart's env) so self‑hosted OHE operators can allow additional cross‑origin browser clients — e.g. OpenHands Agent Canvas — without a bespoke channel release or a manual KOTS kustomize patch.
Context: customer support case where Agent Canvas (origin http://localhost:8000 / a hosted Canvas origin) cannot connect to a self‑hosted OHE because the app server rejects the cross‑origin preflight. Internal tracking: CS‑8. Related client‑side bug: OpenHands/Agent-Canvas#1513.
Why this is needed
The enterprise app server already reads PERMITTED_CORS_ORIGINS from its environment:
# OpenHands repo: enterprise/server/constants.py
WEB_HOST = os.getenv('WEB_HOST', 'app.all-hands.dev').strip()
PERMITTED_CORS_ORIGINS = [
host.strip()
for host in (os.getenv('PERMITTED_CORS_ORIGINS') or f'https://{WEB_HOST}').split(',')
...
]
…and the chart already has a generic env override (.Values.env, user overrides win):
charts/openhands/values.yaml env: map —
charts/openhands/templates/_env.yaml openhands.env (defaults + .Values.env, overrides win) —
|
{{- define "openhands.env" }} |
But there is no way to set it from the installer. I enumerated every option in replicated/config.yaml — there is no CORS field and no free‑form "additional env" input. The Replicated values.env: block is vendor‑templated from fixed config options:
replicated/openhands.yaml env block —
So today the only ways to set PERMITTED_CORS_ORIGINS are: (a) a bespoke release that hard‑codes it into the env: block, or (b) a KOTS downstream kustomize patch on the openhands Deployment. Neither is self‑service.
Proposed change
-
Add a Config option (suggest placing under domain_configuration or advanced_options):
- name: permitted_cors_origins
title: Additional Permitted CORS Origins
type: text
default: ""
help_text: >
Comma-separated list of additional browser origins allowed to call this
deployment's API cross-origin, e.g.
https://canvas.example.com,http://localhost:8000
This deployment's own app URL is always permitted. Required for browser
clients hosted on a different origin, such as OpenHands Agent Canvas.
-
Wire it into the openhands HelmChart values.env: block in replicated/openhands.yaml (around L23), including the app's own origin so the default isn't clobbered:
{{repl if ConfigOption "permitted_cors_origins" }}
PERMITTED_CORS_ORIGINS: 'https://{{repl ConfigOption "app_hostname" }},{{repl ConfigOption "permitted_cors_origins" }}'
{{repl end }}
⚠️ Implementation note: constants.py uses os.getenv('PERMITTED_CORS_ORIGINS') or f'https://{WEB_HOST}' — setting the env var replaces the default rather than appending. The template must therefore always include the deployment's own app origin (app_hostname) plus the operator‑supplied extras, or the app's own UI could be locked out.
Acceptance criteria
Notes
- Works on all current app‑server versions, no image upgrade required.
constants.py has read PERMITTED_CORS_ORIGINS since the enterprise CORS code landed, so this unblocks even older deployments (e.g. the customer on cloud-1.29.1).
- This is the explicit allow‑list route and is independent of the API‑key permissive CORS path (OpenHands #14473 / #14835); operators get a deterministic fix without relying on that path.
- For non‑KOTS/raw‑Helm installs, the same value is settable today via
.Values.env.PERMITTED_CORS_ORIGINS; this issue is specifically about surfacing it in the KOTS installer.
This issue was filed by an AI agent (OpenHands) on behalf of the All Hands team while investigating a customer support case.
Summary
Expose
PERMITTED_CORS_ORIGINSas a first‑class KOTS/Replicated installer config option (wired into theopenhandschart's env) so self‑hosted OHE operators can allow additional cross‑origin browser clients — e.g. OpenHands Agent Canvas — without a bespoke channel release or a manual KOTS kustomize patch.Context: customer support case where Agent Canvas (origin
http://localhost:8000/ a hosted Canvas origin) cannot connect to a self‑hosted OHE because the app server rejects the cross‑origin preflight. Internal tracking: CS‑8. Related client‑side bug: OpenHands/Agent-Canvas#1513.Why this is needed
The enterprise app server already reads
PERMITTED_CORS_ORIGINSfrom its environment:…and the chart already has a generic env override (
.Values.env, user overrides win):charts/openhands/values.yamlenv:map —OpenHands-Cloud/charts/openhands/values.yaml
Line 77 in f04b923
charts/openhands/templates/_env.yamlopenhands.env(defaults +.Values.env, overrides win) —OpenHands-Cloud/charts/openhands/templates/_env.yaml
Line 609 in f04b923
But there is no way to set it from the installer. I enumerated every option in
replicated/config.yaml— there is no CORS field and no free‑form "additional env" input. The Replicatedvalues.env:block is vendor‑templated from fixed config options:replicated/openhands.yamlenv block —OpenHands-Cloud/replicated/openhands.yaml
Line 23 in f04b923
So today the only ways to set
PERMITTED_CORS_ORIGINSare: (a) a bespoke release that hard‑codes it into theenv:block, or (b) a KOTS downstream kustomize patch on theopenhandsDeployment. Neither is self‑service.Proposed change
Add a Config option (suggest placing under
domain_configurationoradvanced_options):Wire it into the
openhandsHelmChartvalues.env:block inreplicated/openhands.yaml(around L23), including the app's own origin so the default isn't clobbered:Acceptance criteria
PERMITTED_CORS_ORIGINSon theopenhandsapp deployment, containing the app's own origin plus the configured extras./server_infoand/api/v1/...(verifyAccess-Control-Allow-Originechoes the origin).https://{WEB_HOST}only).Notes
constants.pyhas readPERMITTED_CORS_ORIGINSsince the enterprise CORS code landed, so this unblocks even older deployments (e.g. the customer oncloud-1.29.1)..Values.env.PERMITTED_CORS_ORIGINS; this issue is specifically about surfacing it in the KOTS installer.This issue was filed by an AI agent (OpenHands) on behalf of the All Hands team while investigating a customer support case.