Skip to content

fix(gateway): make the WebSocket tunnel opt-in - #3727

Merged
drew merged 1 commit into
mainfrom
feat/ws-tunnel-opt-in
Sep 25, 2026
Merged

drew merged 1 commit into
mainfrom
feat/ws-tunnel-opt-in

Conversation

@drew

@drew drew commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

This PR mounts the tunnel only when it is explicitly enabled for edge-proxy deployments.

Related Issue

No issue required: localized hardening of a gateway default.

Changes

  • New enable_websocket_tunnel setting (default false): [openshell.gateway] in gateway.toml, --enable-websocket-tunnel, or OPENSHELL_ENABLE_WEBSOCKET_TUNNEL. CLI and environment override the file.
  • http_router merges the ws_tunnel router only when the setting is enabled; otherwise /_ws_tunnel returns 404.
  • Helm: server.enableWebsocketTunnel (default false) rendered into gateway.toml, with chart unit tests.
  • The Docker and Podman e2e gateways enable the tunnel so edge_tunnel_e2e keeps covering it.
  • Light docs: gateway config reference, edge-auth section, architecture overview, and the cluster debug skill.

Testing

  • mise run pre-commit passes
  • Unit tests added/updated: cargo test -p openshell-server --lib (1821 passed; includes a router mount test and CLI/file precedence test) and mise run helm:test (all chart tests pass)
  • E2E tests added/updated (if applicable): e2e gateways updated to enable the tunnel; not run locally

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

The /_ws_tunnel endpoint pipes a WebSocket into the full gRPC service. On a
plaintext loopback gateway any web page could open it, since browsers do not
apply CORS to WebSocket upgrades. Mount the tunnel only when
enable_websocket_tunnel is set (config file, --enable-websocket-tunnel, or
OPENSHELL_ENABLE_WEBSOCKET_TUNNEL; server.enableWebsocketTunnel in Helm).

BREAKING CHANGE: gateways behind an authenticating edge proxy must set
enable_websocket_tunnel = true for CLI edge-tunnel connections.

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
@github-actions

Copy link
Copy Markdown

@drew drew changed the title fix(gateway)!: make the WebSocket tunnel opt-in fix(gateway): make the WebSocket tunnel opt-in Sep 25, 2026
@drew
drew added this pull request to the merge queue Sep 25, 2026
Merged via the queue into main with commit d4f5034 Sep 25, 2026
74 checks passed
@drew
drew deleted the feat/ws-tunnel-opt-in branch September 25, 2026 23:53
@drew drew added this to the OpenShell 0.1.1 milestone Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants