User Story
As an operator configuring a local gateway, I want missing launch-signing configuration reported before OpenShell downloads or prepares sandbox images, so that I can fix the setup without waiting through a failed provisioning attempt.
Problem Statement
A v0.1.2 gateway had working listener TLS but no sandbox launch-token signer. Its VM driver prepared the bootstrap and workload images before returning VM sandbox launch authentication is required. Listener TLS configuration and sandbox launch signing are separate; the current setup did not explain that distinction before provisioning.
Impact / Why This Matters
A configuration error that can be detected before provisioning consumes image-download and preparation time. Users see an eventual launch error after expensive work and must investigate which credentials the gateway was actually missing.
Proposed Design
Before accepting a sandbox create, validate the launch requirements declared by the selected driver. A missing or invalid signing setup should identify the required configuration and supported discovery location without printing keys or tokens. The VM driver should also reject missing or malformed launch material before image work. Verify the documented setup with both explicit signing configuration and supported local bundle discovery.
Acceptance Criteria
Alternatives Considered
Documenting the missing configuration helps users but still permits the late failure. Checking only inside the VM driver can avoid image work but cannot provide the earliest gateway diagnostic. Requiring a signer for every external driver would assume a launch mechanism that its contract may not use.
Agent Investigation
The recorded setup used custom TLS paths, omitted [openshell.gateway.gateway_jwt], and did not expose a complete signing bundle through local discovery. In current provision_sandbox_inner, prepare_runtime_images precedes launch-authentication validation. Resolved report #3900 describes a related Docker configuration error and requests earlier diagnostics. The proposed change preserves launch authentication; it changes validation timing and the setup documentation.
Recorded failure:
ProvisioningFailed: VM sandbox launch authentication is required
Checklist
User Story
As an operator configuring a local gateway, I want missing launch-signing configuration reported before OpenShell downloads or prepares sandbox images, so that I can fix the setup without waiting through a failed provisioning attempt.
Problem Statement
A v0.1.2 gateway had working listener TLS but no sandbox launch-token signer. Its VM driver prepared the bootstrap and workload images before returning
VM sandbox launch authentication is required. Listener TLS configuration and sandbox launch signing are separate; the current setup did not explain that distinction before provisioning.Impact / Why This Matters
A configuration error that can be detected before provisioning consumes image-download and preparation time. Users see an eventual launch error after expensive work and must investigate which credentials the gateway was actually missing.
Proposed Design
Before accepting a sandbox create, validate the launch requirements declared by the selected driver. A missing or invalid signing setup should identify the required configuration and supported discovery location without printing keys or tokens. The VM driver should also reject missing or malformed launch material before image work. Verify the documented setup with both explicit signing configuration and supported local bundle discovery.
Acceptance Criteria
gateway_jwtconfiguration and supported local discovery both pass a fresh-install smoke test.Alternatives Considered
Documenting the missing configuration helps users but still permits the late failure. Checking only inside the VM driver can avoid image work but cannot provide the earliest gateway diagnostic. Requiring a signer for every external driver would assume a launch mechanism that its contract may not use.
Agent Investigation
The recorded setup used custom TLS paths, omitted
[openshell.gateway.gateway_jwt], and did not expose a complete signing bundle through local discovery. In currentprovision_sandbox_inner,prepare_runtime_imagesprecedes launch-authentication validation. Resolved report #3900 describes a related Docker configuration error and requests earlier diagnostics. The proposed change preserves launch authentication; it changes validation timing and the setup documentation.Recorded failure:
Checklist