Skip to content

config preflight should name the offending key and flag unusable launch-signing setups #3959

Description

@Trustalix

User Story

As an operator (and integrator) configuring an OpenShell gateway with the Docker driver,
I want openshell-gateway config preflight to tell me exactly which section or key is wrong
and whether sandbox launches can succeed,
so that I can fix a configuration before starting the gateway instead of discovering it
when the first CreateSandbox call fails.

Context: we build Trustalix, a governance layer for AI agents (policy decisions and enforcement,
Permit-to-Operate approvals, a risk-based kill switch, multi-tenant audit). We are evaluating
OpenShell as an optional enforcement runtime behind a separate bridge service. We have no
partnership with NVIDIA.

Problem Statement

config preflight (gateway 0.1.2) does not give an actionable result in several cases:

  1. An invalid schema-2 file exits 1 with category=malformed detected_version=2. It names no
    section or key. It also says "migrate it before restarting", although the detected version
    is already 2, so the remediation does not apply.
  2. A [openshell.gateway.gateway_jwt] table that lacks the required signing paths, and an
    unknown key in [openshell.gateway], both produce that identical message.
  3. With compute_driver = "docker" and no gateway_jwt, preflight exits 0 with no output,
    but every CreateSandbox then fails with FAILED_PRECONDITION
    "docker sandboxes require launch-scoped gateway authentication" (related to Validate sandbox launch-signing configuration before image preparation #3949, Docker driver requires launch-scoped session JWT that local gateway does not mint (0.1.2) #3900).
  4. signing_key_path, public_key_path and kid_path pointing at files that do not exist
    also pass with exit 0.

Impact / Why This Matters

config preflight (gateway 0.1.2) does not give an actionable result in several cases:

  1. An invalid schema-2 file exits 1 with category=malformed detected_version=2. It names no
    section or key. It also says "migrate it before restarting", although the detected version
    is already 2, so the remediation does not apply.
  2. A [openshell.gateway.gateway_jwt] table that lacks the required signing paths, and an
    unknown key in [openshell.gateway], both produce that identical message.
  3. With compute_driver = "docker" and no gateway_jwt, preflight exits 0 with no output,
    but every CreateSandbox then fails with FAILED_PRECONDITION
    "docker sandboxes require launch-scoped gateway authentication" (related to Validate sandbox launch-signing configuration before image preparation #3949, Docker driver requires launch-scoped session JWT that local gateway does not mint (0.1.2) #3900).
  4. signing_key_path, public_key_path and kid_path pointing at files that do not exist
    also pass with exit 0.

Proposed Design

Running preflight on a file should either succeed, meaning a sandbox launch is expected to be
possible with the selected driver, or report each problem with its section and key. The
"migrate to schema 2" advice should appear only for files that are actually an older schema.

Acceptance Criteria

  • A schema-2 file with an unknown key or an incomplete table is rejected with a message that
    names that section and key.
  • A Docker-driver configuration with no usable launch signer is reported by preflight
    (overlaps Validate sandbox launch-signing configuration before image preparation #3949; happy to fold into it).
  • Referenced signing-key files that cannot be read are reported.
  • The migration hint is not shown when detected_version is already 2.

Alternatives Considered

Image: ghcr.io/nvidia/openshell/gateway@sha256:2fe4dad9118e14ab80a8258b545ea6e6cd74c3469e24ad4e6610f964d98913a2
(version 0.1.2, linux/amd64), Docker Desktop on Windows.

Minimal file (case 2), saved as t.toml:
[openshell]
version = 2
[openshell.gateway]
disable_tls = true
compute_driver = "docker"
bogus_key = 1

Run: docker run --rm -v

:/cfg:ro

--config /cfg/t.toml config preflight
Result: exit 1, "category=malformed detected_version=2 ... migrate it ...".
Removing bogus_key exits 0 (case 3, no gateway_jwt).

Agent Investigation

No response

Checklist

  • I've reviewed existing issues and the published docs
  • This is a design proposal, not a "please build this" request

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    state:triage-neededOpened without agent diagnostics and needs triage

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions