Skip to content

feat(supervisor): stage gateway configuration snapshot delivery - #3244

Open
pimlock wants to merge 10 commits into
mainfrom
1731-config-update-stage-1/pimlock
Open

feat(supervisor): stage gateway configuration snapshot delivery#3244
pimlock wants to merge 10 commits into
mainfrom
1731-config-update-stage-1/pimlock

Conversation

@pimlock

@pimlock pimlock commented Sep 9, 2026

Copy link
Copy Markdown
Collaborator

Summary

Add Stage 1 of gateway-pushed configuration over ConnectSupervisor. The gateway sends complete sandbox configuration and provider-environment snapshots; supervisors receive them while polling remains authoritative.

Related Issue

Part of #1731. Replaces #2967. Stage 2 will apply snapshots and acknowledge revisions; Stage 3 will add durable completion semantics and remove polling.

Changes

  • Add bootstrap, snapshot, and acknowledgement contracts with gateway/supervisor protocol revision checks.
  • Share read-only snapshot builders between polling and push delivery.
  • Route committed updates through an async interface with ordered, coalesced delivery, bounded fanout, and payload limits. Remote-owner routing follows in feat(kubernetes): support HA gateway rebalancing #1868.
  • Initialize policy history atomically without overwriting existing apply results.
  • Update architecture, compatibility documentation, and generated bindings.

Testing

  • Pre-commit and full local CI
  • Go and TypeScript SDK CI
  • Docker conformance and all four live-policy-update E2E tests

Postgres-specific concurrency coverage requires OPENSHELL_TEST_POSTGRES_URL and was not run.

Checklist

  • Conventional Commits and DCO sign-off
  • Architecture docs updated

@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown

@copy-pr-bot

copy-pr-bot Bot commented Sep 9, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@pimlock

pimlock commented Sep 9, 2026

Copy link
Copy Markdown
Collaborator Author

/ok to test a9387c7

@pimlock pimlock left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

PR Review Status

This Stage 1 implementation is project-valid under #1731 and the initial code review found one blocking fanout-bounding defect. Polling remains authoritative, but the new delivery path can still create fleet-sized queued work in one mutation.

Action required: bound waiting per-sandbox delivery work and add the constrained fleet-fanout regression test described inline.

Blocking findings:

  • GATOR-d33c96a8-01: Configuration fanout eagerly creates unbounded per-sandbox/component worker tasks.

Carried findings:

  • None
Gator metadata
  • Validation: Project-valid Stage 1 of the review-ready #1731 plan; author has repository admin authority.
  • Docs: Architecture, gateway reference, and troubleshooting guidance updated.
  • Checks: Current-head Branch Checks and Helm Lint are pending; Trivy and DCO are green.
  • E2E: Gateway/supervisor delivery changes require test:e2e; dispatch follows after blocking review feedback is resolved.
  • Head SHA: d33c96a87392b28484b7ee64cb8fa10ca63c016e
  • Base SHA: 25021ee31d917074dbfbba971235d85966886a91
  • Merge base SHA: 25021ee31d917074dbfbba971235d85966886a91
  • Patch ID: 279bc7ec2dd36e79708ea1167ab91ba4b6891e5a
  • Gator payload: 8
  • Review mode: initial
  • Previous reviewed SHA: none
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Next state: gator:in-review

Comment thread crates/openshell-server/src/config_delivery.rs Outdated
@pimlock pimlock added gator:in-review Gator is reviewing or awaiting PR review feedback gator:blocked Gator is blocked by process or repository gates and removed gator:in-review Gator is reviewing or awaiting PR review feedback labels Sep 10, 2026
@pimlock

pimlock commented Sep 10, 2026

Copy link
Copy Markdown
Collaborator Author

/ok to test e7729ec

@pimlock pimlock added the test:e2e Requires end-to-end coverage label Sep 10, 2026
@github-actions

Copy link
Copy Markdown

Label test:e2e applied for e7729ec. Open the existing run and click Re-run all jobs to execute with the label set. The run will execute the standard E2E suite after building the required gateway and supervisor images once. The matching required CI gate status on this PR will flip green automatically once the run finishes.

@pimlock pimlock left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

PR Review Status

Thanks @pimlock. I checked your worker-bound update in 43f4c9448: fleet fanout now waits for bounded admission before a sandbox/component key enters the pending map, direct publications fail fast at capacity, and the 10,000-recipient regression test confirms pending delivery work stays bounded. The prior GATOR-d33c96a8-01 obligation is resolved, and the follow-up review found no new blocking findings.

Action required: a maintainer must open the current-head Branch E2E Checks run and click Re-run all jobs so the required E2E suite actually executes with test:e2e; gator remains blocked until that run is queued.

Blocking findings:

  • No blocking findings remain

Carried findings:

  • None
Gator metadata
  • Validation: Project-valid Stage 1 of #1731; the implementation remains within the reviewed gateway/supervisor configuration-delivery scope.
  • Docs: Gateway and sandbox architecture documentation updated for bounded delivery.
  • Checks: Current-head Branch Checks are running; Helm Lint, Trivy, and DCO are green.
  • E2E: test:e2e is applied, but the label-help workflow requires Re-run all jobs on run 34533796187; the required jobs have not been dispatched.
  • Head SHA: e7729ecca7d22751fa759e737bce2b53e33aedb8
  • Base SHA: 5643e1f905f36dbf7d1e922174aaf513919c2260
  • Merge base SHA: 5643e1f905f36dbf7d1e922174aaf513919c2260
  • Patch ID: fa533c9c94b2e2738d497548d32c5ede36c12616
  • Gator payload: 8
  • Review mode: follow_up
  • Previous reviewed SHA: d33c96a87392b28484b7ee64cb8fa10ca63c016e
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Next state: gator:blocked
  • Blocked reason: test_dispatch_required

@pimlock
pimlock added this pull request to stack #3266 September 10, 2026 23:38
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
The startup repair that creates version-one policy history for legacy
sandboxes propagated validation failures, so a single stored policy that
no longer passes current validation rules prevented the gateway from
starting. Skip such sandboxes with a warning and a completion summary so
they keep the pre-repair behavior where only their own configuration reads
report the failure. Store errors remain fatal.

Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Fleet-wide configuration changes spawned one snapshot build per connected
sandbox and component with no concurrency limit, so a global setting or
provider change issued every store query and credential-driver call at
once. Gate builds behind a semaphore sized from the database pool and
start the build deadline only once a permit is held.

Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Sandboxes keep their supervisor binary until they are recreated, so a
gateway upgrade meets supervisors that predate the handshake and report
revision zero. Rejecting them severs every running sandbox with no
automatic recovery. Accept revision zero for one release, log a warning
per session, and count them in
openshell_supervisor_protocol_legacy_sessions_total. The supervisor
mirrors the allowance for gateways that predate the handshake.

Add a shared ConnectSupervisor test harness and handler-level tests for
legacy acceptance and unknown-revision rejection. Move the skill
troubleshooting paragraph out of the numbered deployment list so the
list renders.

Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
@pimlock
pimlock force-pushed the 1731-config-update-stage-1/pimlock branch from e7729ec to 70773d3 Compare September 11, 2026 02:08
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gator:blocked Gator is blocked by process or repository gates test:e2e Requires end-to-end coverage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant