You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
As an operator (and integrator) configuring an OpenShell gateway with the Docker driver,
I want openshell-gateway config preflight to tell me exactly which section or key is wrong
and whether sandbox launches can succeed,
so that I can fix a configuration before starting the gateway instead of discovering it
when the first CreateSandbox call fails.
Context: we build Trustalix, a governance layer for AI agents (policy decisions and enforcement,
Permit-to-Operate approvals, a risk-based kill switch, multi-tenant audit). We are evaluating
OpenShell as an optional enforcement runtime behind a separate bridge service. We have no
partnership with NVIDIA.
Problem Statement
config preflight (gateway 0.1.2) does not give an actionable result in several cases:
An invalid schema-2 file exits 1 with category=malformed detected_version=2. It names no
section or key. It also says "migrate it before restarting", although the detected version
is already 2, so the remediation does not apply.
A [openshell.gateway.gateway_jwt] table that lacks the required signing paths, and an
unknown key in [openshell.gateway], both produce that identical message.
signing_key_path, public_key_path and kid_path pointing at files that do not exist
also pass with exit 0.
Impact / Why This Matters
config preflight (gateway 0.1.2) does not give an actionable result in several cases:
An invalid schema-2 file exits 1 with category=malformed detected_version=2. It names no
section or key. It also says "migrate it before restarting", although the detected version
is already 2, so the remediation does not apply.
A [openshell.gateway.gateway_jwt] table that lacks the required signing paths, and an
unknown key in [openshell.gateway], both produce that identical message.
signing_key_path, public_key_path and kid_path pointing at files that do not exist
also pass with exit 0.
Proposed Design
Running preflight on a file should either succeed, meaning a sandbox launch is expected to be
possible with the selected driver, or report each problem with its section and key. The
"migrate to schema 2" advice should appear only for files that are actually an older schema.
Acceptance Criteria
A schema-2 file with an unknown key or an incomplete table is rejected with a message that
names that section and key.
User Story
As an operator (and integrator) configuring an OpenShell gateway with the Docker driver,
I want
openshell-gateway config preflightto tell me exactly which section or key is wrongand whether sandbox launches can succeed,
so that I can fix a configuration before starting the gateway instead of discovering it
when the first CreateSandbox call fails.
Context: we build Trustalix, a governance layer for AI agents (policy decisions and enforcement,
Permit-to-Operate approvals, a risk-based kill switch, multi-tenant audit). We are evaluating
OpenShell as an optional enforcement runtime behind a separate bridge service. We have no
partnership with NVIDIA.
Problem Statement
config preflight(gateway 0.1.2) does not give an actionable result in several cases:category=malformed detected_version=2. It names nosection or key. It also says "migrate it before restarting", although the detected version
is already 2, so the remediation does not apply.
[openshell.gateway.gateway_jwt]table that lacks the required signing paths, and anunknown key in
[openshell.gateway], both produce that identical message.compute_driver = "docker"and nogateway_jwt, preflight exits 0 with no output,but every CreateSandbox then fails with FAILED_PRECONDITION
"docker sandboxes require launch-scoped gateway authentication" (related to Validate sandbox launch-signing configuration before image preparation #3949, Docker driver requires launch-scoped session JWT that local gateway does not mint (0.1.2) #3900).
signing_key_path,public_key_pathandkid_pathpointing at files that do not existalso pass with exit 0.
Impact / Why This Matters
config preflight(gateway 0.1.2) does not give an actionable result in several cases:category=malformed detected_version=2. It names nosection or key. It also says "migrate it before restarting", although the detected version
is already 2, so the remediation does not apply.
[openshell.gateway.gateway_jwt]table that lacks the required signing paths, and anunknown key in
[openshell.gateway], both produce that identical message.compute_driver = "docker"and nogateway_jwt, preflight exits 0 with no output,but every CreateSandbox then fails with FAILED_PRECONDITION
"docker sandboxes require launch-scoped gateway authentication" (related to Validate sandbox launch-signing configuration before image preparation #3949, Docker driver requires launch-scoped session JWT that local gateway does not mint (0.1.2) #3900).
signing_key_path,public_key_pathandkid_pathpointing at files that do not existalso pass with exit 0.
Proposed Design
Running preflight on a file should either succeed, meaning a sandbox launch is expected to be
possible with the selected driver, or report each problem with its section and key. The
"migrate to schema 2" advice should appear only for files that are actually an older schema.
Acceptance Criteria
names that section and key.
(overlaps Validate sandbox launch-signing configuration before image preparation #3949; happy to fold into it).
Alternatives Considered
Image: ghcr.io/nvidia/openshell/gateway@sha256:2fe4dad9118e14ab80a8258b545ea6e6cd74c3469e24ad4e6610f964d98913a2
(version 0.1.2, linux/amd64), Docker Desktop on Windows.
Minimal file (case 2), saved as t.toml:
[openshell]
version = 2
[openshell.gateway]
disable_tls = true
compute_driver = "docker"
bogus_key = 1
Run: docker run --rm -v
:/cfg:ro![]()
--config /cfg/t.toml config preflightResult: exit 1, "category=malformed detected_version=2 ... migrate it ...".
Removing bogus_key exits 0 (case 3, no gateway_jwt).
Agent Investigation
No response
Checklist