Skip to content

Validate sandbox launch-signing configuration before image preparation #3949

Description

@shiju-nv

User Story

As an operator configuring a local gateway, I want missing launch-signing configuration reported before OpenShell downloads or prepares sandbox images, so that I can fix the setup without waiting through a failed provisioning attempt.

Problem Statement

A v0.1.2 gateway had working listener TLS but no sandbox launch-token signer. Its VM driver prepared the bootstrap and workload images before returning VM sandbox launch authentication is required. Listener TLS configuration and sandbox launch signing are separate; the current setup did not explain that distinction before provisioning.

Impact / Why This Matters

A configuration error that can be detected before provisioning consumes image-download and preparation time. Users see an eventual launch error after expensive work and must investigate which credentials the gateway was actually missing.

Proposed Design

Before accepting a sandbox create, validate the launch requirements declared by the selected driver. A missing or invalid signing setup should identify the required configuration and supported discovery location without printing keys or tokens. The VM driver should also reject missing or malformed launch material before image work. Verify the documented setup with both explicit signing configuration and supported local bundle discovery.

Acceptance Criteria

  • A VM gateway without a usable launch signer rejects creation before any registry request or image preparation.
  • The error distinguishes listener TLS from sandbox launch signing and identifies a supported corrective action.
  • Missing, partial and malformed signing bundles produce specific errors without exposing credential material.
  • Explicit gateway_jwt configuration and supported local discovery both pass a fresh-install smoke test.
  • Driver requirements are checked through the shared contract; unrelated external drivers are not required to adopt a JWT mechanism.

Alternatives Considered

Documenting the missing configuration helps users but still permits the late failure. Checking only inside the VM driver can avoid image work but cannot provide the earliest gateway diagnostic. Requiring a signer for every external driver would assume a launch mechanism that its contract may not use.

Agent Investigation

The recorded setup used custom TLS paths, omitted [openshell.gateway.gateway_jwt], and did not expose a complete signing bundle through local discovery. In current provision_sandbox_inner, prepare_runtime_images precedes launch-authentication validation. Resolved report #3900 describes a related Docker configuration error and requests earlier diagnostics. The proposed change preserves launch authentication; it changes validation timing and the setup documentation.

Recorded failure:

ProvisioningFailed: VM sandbox launch authentication is required

Checklist

  • I've reviewed existing issues and the published docs
  • This is a design proposal, not a "please build this" request

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:computearea:gatewayGateway server and control-plane workstate:acceptedA maintainer decided OpenShell should pursue this issue

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions