diff --git a/crates/openshell-cli/src/commands/provider.rs b/crates/openshell-cli/src/commands/provider.rs index 05ec158e42..22e534d7d3 100644 --- a/crates/openshell-cli/src/commands/provider.rs +++ b/crates/openshell-cli/src/commands/provider.rs @@ -869,30 +869,7 @@ async fn discover_existing_provider_data( Ok(discovered) } -/// Canonical provider type string for Google Vertex AI. -const VERTEX_AI_PROVIDER_TYPE: &str = "google-vertex-ai"; - -/// Canonical provider type string for Google Cloud (GCP APIs). -const GOOGLE_CLOUD_PROVIDER_TYPE: &str = "google-cloud"; - fn missing_credentials_error(provider_type: &str) -> miette::Report { - if provider_type == VERTEX_AI_PROVIDER_TYPE { - return miette::miette!( - "no credentials resolved for provider type '{provider_type}'. \ - Set GOOGLE_VERTEX_AI_TOKEN, VERTEX_AI_TOKEN, \ - GOOGLE_VERTEX_AI_SERVICE_ACCOUNT_TOKEN, or VERTEX_AI_SERVICE_ACCOUNT_TOKEN; \ - or use --from-gcloud-adc or --from-existing with those env vars set." - ); - } - - if provider_type == GOOGLE_CLOUD_PROVIDER_TYPE { - return miette::miette!( - "no credentials resolved for provider type '{provider_type}'. \ - Set GCP_ADC_ACCESS_TOKEN or GCP_SA_ACCESS_TOKEN; \ - or use --from-gcloud-adc / --from-existing with those env vars set." - ); - } - miette::miette!( "no credentials resolved for provider type '{provider_type}'. \ Use --credential KEY[=VALUE], --runtime-credentials for runtime-resolved profile credentials, or --from-existing \ diff --git a/crates/openshell-cli/tests/provider_commands_integration.rs b/crates/openshell-cli/tests/provider_commands_integration.rs index 2cbeaffdf6..f5ce508237 100644 --- a/crates/openshell-cli/tests/provider_commands_integration.rs +++ b/crates/openshell-cli/tests/provider_commands_integration.rs @@ -4500,6 +4500,7 @@ async fn provider_create_from_existing_uses_profile_discovery() { }], discovery: Some(ProviderProfileDiscovery { credentials: vec!["api_key".to_string()], + config_env_vars: Vec::new(), }), ..Default::default() }, @@ -4676,6 +4677,7 @@ async fn provider_create_from_existing_fails_when_profile_discovery_finds_nothin }], discovery: Some(ProviderProfileDiscovery { credentials: vec!["api_key".to_string()], + config_env_vars: Vec::new(), }), ..Default::default() }, @@ -4725,6 +4727,7 @@ async fn provider_update_from_existing_uses_profile_discovery() { }], discovery: Some(ProviderProfileDiscovery { credentials: vec!["api_key".to_string()], + config_env_vars: Vec::new(), }), ..Default::default() }, @@ -4796,6 +4799,7 @@ async fn provider_update_from_existing_preserves_global_profile_scope() { }], discovery: Some(ProviderProfileDiscovery { credentials: vec!["api_key".to_string()], + config_env_vars: Vec::new(), }), ..Default::default() }, @@ -5822,7 +5826,7 @@ async fn provider_create_from_gcloud_adc_rolls_back_provider_when_initial_rotate } #[tokio::test] -async fn provider_create_from_existing_vertex_config_only_reports_missing_vertex_credentials() { +async fn provider_create_from_existing_vertex_config_only_reports_missing_credentials() { let ts = run_server().await; let _env = EnvVarGuard::set(&[ ("VERTEX_AI_PROJECT_ID", "vertex-config-only-project"), @@ -5845,7 +5849,7 @@ async fn provider_create_from_existing_vertex_config_only_reports_missing_vertex let msg = err.to_string(); assert!( - msg.contains("GOOGLE_VERTEX_AI_TOKEN") && msg.contains("VERTEX_AI_SERVICE_ACCOUNT_TOKEN"), + msg.contains("no credentials resolved") && msg.contains("--credential KEY[=VALUE]"), "unexpected error: {msg}" ); assert!( diff --git a/crates/openshell-core/build.rs b/crates/openshell-core/build.rs index 38c961b1d4..5deb3d813d 100644 --- a/crates/openshell-core/build.rs +++ b/crates/openshell-core/build.rs @@ -51,6 +51,9 @@ fn main() -> Result<(), Box> { .build_server(true) .build_client(true) .include_file("openshell.rs") + // Profile snapshots hash their protobuf encoding. Keep environment + // maps ordered across storage round trips so revisions remain stable. + .btree_map(".openshell.v1.ProviderProfileEnvironment") // Emit a binary FileDescriptorSet so the server can enumerate every // RPC at runtime (used by the per-handler auth exhaustiveness test). .file_descriptor_set_path(&descriptor_path) diff --git a/crates/openshell-core/src/google_cloud.rs b/crates/openshell-core/src/google_cloud.rs deleted file mode 100644 index fcab45ae08..0000000000 --- a/crates/openshell-core/src/google_cloud.rs +++ /dev/null @@ -1,111 +0,0 @@ -// SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. -// SPDX-License-Identifier: Apache-2.0 - -//! Shared GCP constants for the metadata emulator, provider env injection, -//! and credential resolution. -//! -//! This module is the single source of truth for GCP naming: env var aliases, -//! provider config keys, token search order, and Vertex-specific env vars. -//! `openshell-server`, `openshell-providers`, and `openshell-sandbox` -//! import from here. - -// ── Metadata emulator ─────────────────────────────────────────────────────── - -/// Hostname served by the GCE metadata emulator via proxy interception. -pub const METADATA_HOST: &str = "gcp.metadata.openshell.internal"; - -/// Loopback address for the GCE metadata server inside sandbox namespaces. -/// Go's metadata client dials this directly (bypasses `HTTP_PROXY`). -pub const METADATA_LOOPBACK_ADDR: &str = "127.0.0.1:8174"; - -// ── Env var alias arrays ──────────────────────────────────────────────────── - -/// Env vars that carry the GCP project ID inside sandboxes. -pub const PROJECT_ID_ENV_VARS: &[&str] = &["GCP_PROJECT_ID", "GOOGLE_CLOUD_PROJECT"]; - -/// Env vars that carry the GCP region/location inside sandboxes. -pub const REGION_ENV_VARS: &[&str] = &["CLOUD_ML_REGION", "GCP_LOCATION"]; - -/// Env vars that carry the GCP service account email inside sandboxes. -pub const SERVICE_ACCOUNT_EMAIL_ENV_VARS: &[&str] = &["GCP_SERVICE_ACCOUNT_EMAIL"]; - -// ── Provider config keys ──────────────────────────────────────────────────── - -/// Config key for project ID in `gcp` providers. -pub const GCP_PROJECT_ID_CONFIG_KEY: &str = "project_id"; - -/// Config key for region in `gcp` providers. -pub const GCP_REGION_CONFIG_KEY: &str = "region"; - -/// Config key for service account email in `gcp` providers. -pub const GCP_SERVICE_ACCOUNT_EMAIL_CONFIG_KEY: &str = "service_account_email"; - -// ── Token search order ────────────────────────────────────────────────────── - -/// GCP token env vars searched in priority order by the metadata emulator. -/// SA token wins over ADC if both are configured, matching GCP's own -/// credential precedence. -pub const TOKEN_ENV_KEYS: &[&str] = &["GCP_SA_ACCESS_TOKEN", "GCP_ADC_ACCESS_TOKEN"]; - -// ── Vertex-specific env vars ──────────────────────────────────────────────── - -/// Env var injected to signal Vertex AI usage to Goose. -pub const GOOSE_PROVIDER_ENV_VAR: &str = "GOOSE_PROVIDER"; - -/// Env var for Anthropic Vertex project ID (consumed by Claude Code SDK). -pub const ANTHROPIC_VERTEX_PROJECT_ID_ENV_VAR: &str = "ANTHROPIC_VERTEX_PROJECT_ID"; - -/// Env var for Vertex location (consumed by Claude Code SDK). -pub const VERTEX_LOCATION_ENV_VAR: &str = "VERTEX_LOCATION"; - -/// Non-secret GCP/Vertex config vars that must be resolved to real values -/// in the child environment. Everything else stays as placeholders for -/// proxy-time resolution. -/// -/// This list MUST be the union of all alias arrays above plus all -/// Vertex-specific env vars. If you add an alias to `PROJECT_ID_ENV_VARS`, -/// `REGION_ENV_VARS`, or a Vertex constant, add it here too. -pub const STATIC_CONFIG_KEYS: &[&str] = &[ - // project_id aliases - "GCP_PROJECT_ID", - "GOOGLE_CLOUD_PROJECT", - // region aliases - "CLOUD_ML_REGION", - "GCP_LOCATION", - // service account email - "GCP_SERVICE_ACCOUNT_EMAIL", - // Vertex-specific non-secret config - GOOSE_PROVIDER_ENV_VAR, - ANTHROPIC_VERTEX_PROJECT_ID_ENV_VAR, - VERTEX_LOCATION_ENV_VAR, -]; - -#[cfg(test)] -mod tests { - use super::*; - use std::collections::HashSet; - - #[test] - fn static_config_keys_matches_alias_arrays_and_vertex_vars() { - let expected: HashSet<&str> = PROJECT_ID_ENV_VARS - .iter() - .chain(REGION_ENV_VARS) - .chain(SERVICE_ACCOUNT_EMAIL_ENV_VARS) - .copied() - .chain([ - GOOSE_PROVIDER_ENV_VAR, - ANTHROPIC_VERTEX_PROJECT_ID_ENV_VAR, - VERTEX_LOCATION_ENV_VAR, - ]) - .collect(); - let actual: HashSet<&str> = STATIC_CONFIG_KEYS.iter().copied().collect(); - assert_eq!( - expected, - actual, - "STATIC_CONFIG_KEYS must be the union of all alias arrays + Vertex vars. \ - Missing: {:?}, Extra: {:?}", - expected.difference(&actual).collect::>(), - actual.difference(&expected).collect::>(), - ); - } -} diff --git a/crates/openshell-core/src/lib.rs b/crates/openshell-core/src/lib.rs index 472175f511..3cf7c01ca2 100644 --- a/crates/openshell-core/src/lib.rs +++ b/crates/openshell-core/src/lib.rs @@ -24,7 +24,6 @@ pub mod extension_protocol; #[cfg(unix)] pub mod external_driver_socket; pub mod forward; -pub mod google_cloud; pub mod gpu; pub mod grpc_client; pub mod host_pattern; diff --git a/crates/openshell-core/src/provider_credentials.rs b/crates/openshell-core/src/provider_credentials.rs index 6988d1f4be..2f3a9ee785 100644 --- a/crates/openshell-core/src/provider_credentials.rs +++ b/crates/openshell-core/src/provider_credentials.rs @@ -416,21 +416,10 @@ impl ProviderCredentialState { inner.current = Arc::new(env); } - /// Return `child_env` with explicitly non-secret config vars resolved. - /// - /// The credential pipeline placeholderizes all env values. Workloads need - /// non-secret configuration, including provider file paths, at process - /// startup before any HTTP request flows through the proxy. Credential - /// values remain placeholders. - /// - /// Three layers of env var injection: - /// 1. **Synthetic vars** (`GCE_METADATA_IP`, `METADATA_SERVER_DETECTION`) - /// — sandbox-internal config not from user - /// input, inserted directly here with real values. - /// 2. **Classified non-secret keys** — user-provided config and provider - /// file paths un-placeholderized so workloads can read them at startup. - /// 3. Everything else stays as placeholders for proxy-time resolution. - pub fn child_env_with_gcp_resolved(&self) -> HashMap { + /// Resolve only environment keys explicitly classified as non-secret by + /// the gateway, including provider file paths needed at process startup. + /// Credentials remain placeholders for proxy-time resolution. + pub fn child_env_with_non_secret_resolved(&self) -> HashMap { let inner = self .inner .read() @@ -445,7 +434,7 @@ impl ProviderCredentialState { /// revision must describe the exact environment sent across the boundary, /// so callers must not obtain the two values through separate lock /// acquisitions. - pub fn child_env_snapshot_with_gcp_resolved( + pub fn child_env_snapshot_with_non_secret_resolved( &self, ) -> std::io::Result<(u64, HashMap)> { let inner = self @@ -481,47 +470,12 @@ impl ProviderCredentialState { fn resolve_child_env_snapshot( inner: &ProviderCredentialStateInner, ) -> (u64, HashMap) { - use crate::google_cloud; - let mut env = inner.current.child_env.clone(); - - let has_gcp_metadata = env.contains_key("GCE_METADATA_HOST") - && inner - .non_secret_environment_keys - .contains("GCE_METADATA_HOST"); - if !has_gcp_metadata && inner.non_secret_environment_keys.is_empty() { - return (inner.current.revision, env); - } - - if has_gcp_metadata { - // Synthetic vars: sandbox-internal config that doesn't originate - // from user input and was never placeholderized. - env.insert( - "GCE_METADATA_HOST".to_string(), - google_cloud::METADATA_LOOPBACK_ADDR.to_string(), - ); - // Python's google-auth builds its ping URL as http://{GCE_METADATA_IP} - // so the value must include the port. - env.insert( - "GCE_METADATA_IP".to_string(), - google_cloud::METADATA_LOOPBACK_ADDR.to_string(), - ); - // Node.js gcp-metadata uses METADATA_SERVER_DETECTION to skip the - // runtime ping that otherwise fails in sandboxed environments. - env.insert( - "METADATA_SERVER_DETECTION".to_string(), - "assume-present".to_string(), - ); - } - - // Only explicitly classified non-secret values may be unwrapped. - if let Some(ref resolver) = inner.combined_resolver { + if let Some(resolver) = &inner.current_resolver { for key in &inner.non_secret_environment_keys { - if !env.contains_key(key) || (has_gcp_metadata && key == "GCE_METADATA_HOST") { - continue; - } - let placeholder = crate::secrets::placeholder_for_env_key(key); - if let Some(value) = resolver.resolve_placeholder(&placeholder) { + if let Some(placeholder) = env.get(key) + && let Some(value) = resolver.resolve_placeholder(placeholder) + { env.insert(key.clone(), value.to_string()); } } @@ -573,45 +527,6 @@ impl ProviderCredentialState { Ok(revision) } - /// Return the GCP token placeholder and its remaining lifetime in seconds. - /// - /// Searches `google_cloud::TOKEN_ENV_KEYS` in priority order (SA before - /// ADC) atomically to avoid inconsistency during credential - /// refresh. Returns `None` if no GCP token is configured or all are - /// expired. The `expires_in` defaults to 3600 when expiry is unknown. - pub fn gcp_token_response(&self) -> Option<(String, i64)> { - const DEFAULT_EXPIRES_IN: i64 = 3600; - let inner = self - .inner - .read() - .expect("provider credential state poisoned"); - let resolver = inner.current_resolver.as_ref()?; - for key in crate::google_cloud::TOKEN_ENV_KEYS { - let Some(placeholder) = inner.current.child_env.get(*key).cloned() else { - continue; - }; - if resolver.resolve_placeholder(&placeholder).is_none() { - continue; - } - let expires_in = resolver.expires_at_ms_for_placeholder(&placeholder).map_or( - DEFAULT_EXPIRES_IN, - |expires_at_ms| { - if expires_at_ms <= 0 { - DEFAULT_EXPIRES_IN - } else { - let now = crate::time::now_ms(); - expires_at_ms.saturating_sub(now) / 1000 - } - }, - ); - if expires_in <= 0 { - continue; - } - return Some((placeholder, expires_in)); - } - None - } - pub fn install_environment( &self, revision: u64, @@ -1025,7 +940,6 @@ fn merge_resolvers( #[cfg(test)] mod tests { use super::*; - use crate::google_cloud; #[test] fn body_classification_distinguishes_literal_foreign_bound_and_revoked() { @@ -2130,14 +2044,14 @@ mod tests { } #[test] - fn child_env_with_gcp_resolved_without_gcp_returns_unchanged() { + fn child_env_with_non_secret_resolved_without_classified_keys_returns_unchanged() { let state = ProviderCredentialState::from_environment( 1, HashMap::from([("GITHUB_TOKEN".to_string(), "ghp_abc".to_string())]), HashMap::new(), HashMap::new(), ); - let env = state.child_env_with_gcp_resolved(); + let env = state.child_env_with_non_secret_resolved(); assert_eq!( env.get("GITHUB_TOKEN").map(String::as_str), Some("openshell:resolve:env:v1_GITHUB_TOKEN"), @@ -2166,7 +2080,7 @@ mod tests { ) .expect("classified provider environment"); - let env = state.child_env_with_gcp_resolved(); + let env = state.child_env_with_non_secret_resolved(); assert_eq!(env.get("ACME_CONFIG_FILE").map(String::as_str), Some(path)); assert_eq!( env.get("ACME_TOKEN").map(String::as_str), @@ -2175,17 +2089,17 @@ mod tests { } #[test] - fn child_env_with_gcp_resolved_overrides_gcp_static_vars() { + fn child_env_with_non_secret_resolved_resolves_declared_custom_config() { let state = ProviderCredentialState::from_bound_environment( 1, HashMap::from([ - ("GCE_METADATA_HOST".to_string(), "marker".to_string()), + ("CUSTOM_ENDPOINT".to_string(), "marker".to_string()), ( "GCP_ADC_ACCESS_TOKEN".to_string(), "ya29.secret".to_string(), ), - ("GCP_PROJECT_ID".to_string(), "my-project".to_string()), - ("CLOUD_ML_REGION".to_string(), "us-central1".to_string()), + ("CUSTOM_PROJECT".to_string(), "my-project".to_string()), + ("CUSTOM_REGION".to_string(), "us-central1".to_string()), ]), HashMap::new(), HashMap::new(), @@ -2194,30 +2108,30 @@ mod tests { binding("oauth2.googleapis.com", 443, "/**"), )]), vec![ - "GCE_METADATA_HOST".to_string(), - "GCP_PROJECT_ID".to_string(), - "CLOUD_ML_REGION".to_string(), + "CUSTOM_ENDPOINT".to_string(), + "CUSTOM_PROJECT".to_string(), + "CUSTOM_REGION".to_string(), ], ) - .expect("classified GCP environment"); - let env = state.child_env_with_gcp_resolved(); + .expect("classified provider environment"); + let env = state.child_env_with_non_secret_resolved(); assert_eq!( - env.get("GCE_METADATA_HOST").map(String::as_str), - Some(google_cloud::METADATA_LOOPBACK_ADDR), - "GCE_METADATA_HOST should be the loopback address" + env.get("CUSTOM_ENDPOINT").map(String::as_str), + Some("marker"), + "non-secret values must be preserved without GCP-specific rewriting" ); assert!( !env.contains_key("CLAUDE_CODE_USE_VERTEX"), "inference-specific vars should not be injected" ); assert_eq!( - env.get("GCP_PROJECT_ID").map(String::as_str), + env.get("CUSTOM_PROJECT").map(String::as_str), Some("my-project"), "static config should be resolved to real value" ); assert_eq!( - env.get("CLOUD_ML_REGION").map(String::as_str), + env.get("CUSTOM_REGION").map(String::as_str), Some("us-central1"), ); @@ -2229,7 +2143,7 @@ mod tests { } #[test] - fn child_env_with_gcp_resolved_handles_missing_config_keys() { + fn child_env_with_non_secret_resolved_handles_missing_config_keys() { let state = ProviderCredentialState::from_bound_environment( 1, HashMap::from([ @@ -2245,11 +2159,11 @@ mod tests { vec!["GCE_METADATA_HOST".to_string()], ) .expect("classified GCP environment"); - let env = state.child_env_with_gcp_resolved(); + let env = state.child_env_with_non_secret_resolved(); assert_eq!( env.get("GCE_METADATA_HOST").map(String::as_str), - Some(google_cloud::METADATA_LOOPBACK_ADDR), + Some("marker"), ); assert!( !env.contains_key("GCP_PROJECT_ID") @@ -2262,109 +2176,7 @@ mod tests { } #[test] - fn gcp_token_response_returns_sa_over_adc() { - let state = ProviderCredentialState::from_environment( - 1, - HashMap::from([ - ("GCP_SA_ACCESS_TOKEN".to_string(), "sa-tok".to_string()), - ("GCP_ADC_ACCESS_TOKEN".to_string(), "adc-tok".to_string()), - ]), - HashMap::new(), - HashMap::new(), - ); - let (placeholder, _) = state.gcp_token_response().expect("should find token"); - assert_eq!( - placeholder, "openshell:resolve:env:v1_GCP_SA_ACCESS_TOKEN", - "metadata must return the current revision-scoped SA placeholder" - ); - } - - #[test] - fn gcp_token_response_falls_back_to_adc() { - let state = ProviderCredentialState::from_environment( - 1, - HashMap::from([("GCP_ADC_ACCESS_TOKEN".to_string(), "adc-tok".to_string())]), - HashMap::new(), - HashMap::new(), - ); - let (placeholder, _) = state.gcp_token_response().expect("should find ADC token"); - assert_eq!( - placeholder, "openshell:resolve:env:v1_GCP_ADC_ACCESS_TOKEN", - "metadata must return the current revision-scoped ADC placeholder" - ); - } - - #[test] - fn gcp_token_response_returns_none_without_gcp() { - let state = ProviderCredentialState::from_environment( - 1, - HashMap::from([("GITHUB_TOKEN".to_string(), "ghp_abc".to_string())]), - HashMap::new(), - HashMap::new(), - ); - assert!(state.gcp_token_response().is_none()); - } - - #[test] - fn gcp_token_response_defaults_expires_in_to_3600() { - let state = ProviderCredentialState::from_environment( - 1, - HashMap::from([("GCP_ADC_ACCESS_TOKEN".to_string(), "adc-tok".to_string())]), - HashMap::new(), - HashMap::new(), - ); - let (_, expires_in) = state.gcp_token_response().unwrap(); - assert_eq!( - expires_in, 3600, - "should default to 3600 when no expiry set" - ); - } - - #[test] - fn gcp_token_response_calculates_remaining() { - let now_ms = i64::try_from( - std::time::SystemTime::now() - .duration_since(std::time::UNIX_EPOCH) - .unwrap() - .as_millis(), - ) - .unwrap(); - let state = ProviderCredentialState::from_environment( - 1, - HashMap::from([("GCP_ADC_ACCESS_TOKEN".to_string(), "adc-tok".to_string())]), - HashMap::from([("GCP_ADC_ACCESS_TOKEN".to_string(), now_ms + 120_000)]), - HashMap::new(), - ); - let (_, expires_in) = state.gcp_token_response().unwrap(); - assert!( - (110..=120).contains(&expires_in), - "expected ~120s remaining, got {expires_in}" - ); - } - - #[test] - fn gcp_token_response_handles_already_expired_token_without_panic() { - let now_ms = i64::try_from( - std::time::SystemTime::now() - .duration_since(std::time::UNIX_EPOCH) - .unwrap() - .as_millis(), - ) - .unwrap(); - let state = ProviderCredentialState::from_environment( - 1, - HashMap::from([("GCP_ADC_ACCESS_TOKEN".to_string(), "adc-tok".to_string())]), - HashMap::from([("GCP_ADC_ACCESS_TOKEN".to_string(), now_ms - 1_000)]), - HashMap::new(), - ); - assert!( - state.gcp_token_response().is_none(), - "expired token should be skipped rather than panic" - ); - } - - #[test] - fn child_env_with_gcp_resolved_resolves_vertex_vars_without_metadata_host() { + fn child_env_with_non_secret_resolved_resolves_vertex_vars_without_metadata_host() { let state = ProviderCredentialState::from_bound_environment( 1, HashMap::from([ @@ -2385,7 +2197,7 @@ mod tests { ], ) .expect("classified Vertex environment"); - let env = state.child_env_with_gcp_resolved(); + let env = state.child_env_with_non_secret_resolved(); assert_eq!( env.get("GOOSE_PROVIDER").map(String::as_str), Some("gcp_vertex_ai"), @@ -2406,7 +2218,7 @@ mod tests { } #[test] - fn child_env_with_gcp_resolved_only_unwraps_explicitly_non_secret_config() { + fn child_env_with_non_secret_resolved_only_unwraps_explicitly_non_secret_config() { let state = ProviderCredentialState::from_bound_environment( 1, HashMap::from([ @@ -2452,7 +2264,7 @@ mod tests { ) .expect("refreshed GCP environment"); - let env = state.child_env_with_gcp_resolved(); + let env = state.child_env_with_non_secret_resolved(); assert_eq!( env.get("GCP_PROJECT_ID").map(String::as_str), Some("visible-project-config"), @@ -2651,7 +2463,7 @@ mod tests { "opaque revisions may move numerically backwards" ); - let (revision, env) = state.child_env_snapshot_with_gcp_resolved().unwrap(); + let (revision, env) = state.child_env_snapshot_with_non_secret_resolved().unwrap(); assert_eq!(revision, 2); assert!(env.is_empty(), "an empty snapshot must revoke the old env"); } @@ -2693,7 +2505,7 @@ mod tests { .compare_and_install_child_env_snapshot(4, 5, HashMap::new()) .is_err() ); - assert!(state.child_env_snapshot_with_gcp_resolved().is_err()); + assert!(state.child_env_snapshot_with_non_secret_resolved().is_err()); } #[test] diff --git a/crates/openshell-providers/README.md b/crates/openshell-providers/README.md index f0b5b79233..1804b1e38f 100644 --- a/crates/openshell-providers/README.md +++ b/crates/openshell-providers/README.md @@ -1,18 +1,20 @@ # openshell-providers -Provider discovery and normalization for credentials that sandboxes need at -runtime. +Imported provider profile parsing, validation, discovery, and environment +defaults. The gateway persists provider records. The sandbox supervisor fetches resolved provider environment from the gateway and injects credentials into agent child -processes. This crate keeps provider-specific discovery and normalization logic -out of the CLI and gateway control flow. +processes. Profile declarations determine the behavior; profile IDs do not +select compiled provider plugins. ## Responsibilities -- Discover local credentials from environment variables and known config files. -- Normalize discovered data into provider records. -- Keep provider-specific parsing rules in provider modules. +- Parse and round-trip the YAML, JSON, and protobuf profile schema. +- Discover credentials and non-secret config from declared environment keys. +- Apply bounded, literal non-secret environment defaults without overwriting + existing values. +- Validate credential collisions and named platform adapter requirements. - Avoid logging credential values. ## Non-Responsibilities @@ -22,7 +24,27 @@ out of the CLI and gateway control flow. - Injecting credentials into sandbox child processes. - Routing inference requests. -Those are owned by the gateway, sandbox supervisor, and router. +Those are owned by the gateway and sandbox supervisor. + +## Provider Behavior Inventory + +| Behavior | Declaration or disposition | +|---|---| +| GCP and Vertex project, region, and SDK aliases | `environment.config` | +| Metadata SDK variables and Goose provider default | `environment.fixed` | +| Credential discovery | `discovery.credentials` and credential `env_vars` | +| Vertex config discovery | `discovery.config_env_vars` | +| Workload resolution of non-secret values | Gateway key classification, independent of provider names | +| Platform service dependency | `required_platform_adapter`; unavailable requirements reject import and attachment | +| Vertex service account JSON credential | Removed from the example; configure gateway refresh material directly | +| ID-selected provider plugins | Removed | +| ID-selected CLI credential hints | Removed; setup guidance applies to the imported profile | +| `ProviderDiscoverySpec` and `discover_with_spec` | Removed; no supported caller | +| GCP token response helper and compiled config-key catalog | Removed; the metadata service has no remaining caller and profile data supplies the keys | + +Credential refresh strategies remain explicitly declared in credential metadata. +The `gcp-metadata` adapter name is recognized, but this build has no metadata +server to satisfy it. ## Security Notes diff --git a/crates/openshell-providers/src/discovery.rs b/crates/openshell-providers/src/discovery.rs index 2249adaf4a..e040a22091 100644 --- a/crates/openshell-providers/src/discovery.rs +++ b/crates/openshell-providers/src/discovery.rs @@ -1,35 +1,9 @@ // SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. // SPDX-License-Identifier: Apache-2.0 -use crate::{ - DiscoveredProvider, DiscoveryContext, ProviderDiscoverySpec, ProviderError, ProviderTypeProfile, -}; +use crate::{DiscoveredProvider, DiscoveryContext, ProviderError, ProviderTypeProfile}; use std::collections::HashSet; -pub fn discover_with_spec( - spec: &ProviderDiscoverySpec, - context: &dyn DiscoveryContext, -) -> Result, ProviderError> { - let mut discovered = DiscoveredProvider::default(); - - for key in spec.credential_env_vars { - if let Some(value) = context.env_var(key) - && !value.trim().is_empty() - { - discovered - .credentials - .entry((*key).to_string()) - .or_insert(value); - } - } - - if discovered.is_empty() { - Ok(None) - } else { - Ok(Some(discovered)) - } -} - pub fn discover_from_profile( profile: &ProviderTypeProfile, context: &dyn DiscoveryContext, @@ -66,13 +40,11 @@ pub fn discover_from_profile( } } - if profile.id == "google-vertex-ai" { - for key in crate::VERTEX_AI_CONFIG_KEY_NAMES { - if let Some(value) = context.env_var(key) - && !value.trim().is_empty() - { - discovered.config.entry((*key).to_string()).or_insert(value); - } + for key in &profile.discovery.config_env_vars { + if let Some(value) = context.env_var(key) + && !value.trim().is_empty() + { + discovered.config.entry(key.clone()).or_insert(value); } } @@ -88,7 +60,7 @@ mod tests { use super::discover_from_profile; use crate::profiles::{CredentialProfile, DiscoveryProfile}; use crate::test_helpers::MockDiscoveryContext; - use crate::{ProviderError, ProviderTypeProfile}; + use crate::{EnvironmentProfile, ProviderError, ProviderTypeProfile}; fn profile() -> ProviderTypeProfile { ProviderTypeProfile { @@ -130,7 +102,10 @@ mod tests { inference_capable: false, discovery: DiscoveryProfile { credentials: vec!["api_key".to_string(), "secondary".to_string()], + config_env_vars: Vec::new(), }, + environment: EnvironmentProfile::default(), + required_platform_adapter: String::new(), source: String::new(), scope: String::new(), } @@ -178,9 +153,10 @@ mod tests { } #[test] - fn vertex_profile_discovery_includes_supported_configuration() { + fn profile_discovery_includes_declared_configuration() { let mut profile = profile(); - profile.id = "google-vertex-ai".to_string(); + profile.discovery.config_env_vars = + vec!["VERTEX_AI_PROJECT_ID".into(), "VERTEX_AI_REGION".into()]; let ctx = MockDiscoveryContext::new() .with_env("CUSTOM_API_KEY", "vertex-token") .with_env("VERTEX_AI_PROJECT_ID", "project-a") diff --git a/crates/openshell-providers/src/environment_tests.rs b/crates/openshell-providers/src/environment_tests.rs new file mode 100644 index 0000000000..6ae58c42cf --- /dev/null +++ b/crates/openshell-providers/src/environment_tests.rs @@ -0,0 +1,278 @@ +// SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. +// SPDX-License-Identifier: Apache-2.0 + +use std::collections::HashMap; + +use crate::test_helpers::MockDiscoveryContext; +use crate::{ + EnvironmentProfile, ProviderTypeProfile, discover_from_profile, parse_profile_yaml, + profile_to_yaml, validate_profile_set, +}; + +fn profile() -> ProviderTypeProfile { + parse_profile_yaml( + r" +id: custom +display_name: Custom +credentials: + - name: token + env_vars: [CUSTOM_TOKEN] +environment: + config: + CUSTOM_PROJECT: project + fixed: + CUSTOM_MODE: native +discovery: + credentials: [token] + config_env_vars: [CUSTOM_PROJECT] +required_platform_adapter: gcp-metadata +", + ) + .unwrap() +} + +#[test] +fn environment_and_discovery_declarations_round_trip() { + let profile = profile(); + let proto = profile.to_proto(); + let restored = ProviderTypeProfile::from_proto(&proto); + assert_eq!(restored.to_proto(), proto); + let yaml = profile_to_yaml(&restored).unwrap(); + assert_eq!(parse_profile_yaml(&yaml).unwrap().to_proto(), proto); + assert!(validate_profile_set(&[("custom.yaml".into(), profile)]).is_empty()); +} + +#[test] +fn projection_preserves_existing_values_and_skips_blank_config() { + let profile = profile(); + let config = HashMap::from([("project".into(), " project-a ".into())]); + let mut env = HashMap::new(); + profile.environment.inject(&config, &mut env); + assert_eq!( + env, + HashMap::from([ + ("CUSTOM_PROJECT".into(), "project-a".into()), + ("CUSTOM_MODE".into(), "native".into()) + ]) + ); + + let mut existing = HashMap::from([ + ("CUSTOM_PROJECT".into(), String::new()), + ("CUSTOM_MODE".into(), "caller".into()), + ]); + let before = existing.clone(); + profile.environment.inject(&config, &mut existing); + assert_eq!(existing, before); + + for config in [ + HashMap::new(), + HashMap::from([("project".into(), " \t ".into())]), + ] { + let mut env = HashMap::new(); + profile.environment.inject(&config, &mut env); + assert!(!env.contains_key("CUSTOM_PROJECT")); + assert_eq!(env["CUSTOM_MODE"], "native"); + } +} + +#[test] +fn projection_skips_legacy_private_key_defaults_in_stored_profiles() { + let mut profile = profile(); + profile.environment.config.insert( + crate::LEGACY_VERTEX_PRIVATE_KEY_ENV.into(), + "private_key".into(), + ); + let config = HashMap::from([("private_key".into(), "secret".into())]); + let mut env = HashMap::new(); + profile.environment.inject(&config, &mut env); + assert!(!env.contains_key(crate::LEGACY_VERTEX_PRIVATE_KEY_ENV)); + + profile.environment.config.clear(); + profile + .environment + .fixed + .insert(crate::LEGACY_VERTEX_PRIVATE_KEY_ENV.into(), "secret".into()); + profile.environment.inject(&config, &mut env); + assert!(!env.contains_key(crate::LEGACY_VERTEX_PRIVATE_KEY_ENV)); +} + +#[test] +fn renamed_google_examples_keep_environment_and_discovery_behavior() { + let config = HashMap::from([ + ("project_id".into(), "cloud-project".into()), + ("region".into(), "us-east1".into()), + ("service_account_email".into(), "sa@example.com".into()), + ("VERTEX_AI_PROJECT_ID".into(), "vertex-project".into()), + ("VERTEX_AI_REGION".into(), "us-central1".into()), + ]); + let context = MockDiscoveryContext::new() + .with_env("GOOGLE_VERTEX_AI_TOKEN", "test-token") + .with_env("GCP_ADC_ACCESS_TOKEN", "test-adc-token") + .with_env("VERTEX_AI_PROJECT_ID", "vertex-project") + .with_env("VERTEX_AI_REGION", "us-central1"); + for id in ["google-cloud", "google-vertex-ai"] { + let canonical = crate::example_profiles::load(id); + let mut renamed = canonical.clone(); + renamed.id = "acme-fork".into(); + let mut canonical_env = HashMap::new(); + let mut renamed_env = HashMap::new(); + canonical.environment.inject(&config, &mut canonical_env); + renamed.environment.inject(&config, &mut renamed_env); + assert!(!canonical_env.is_empty()); + assert_eq!(canonical_env, renamed_env); + assert_eq!( + canonical + .ensure_platform_adapter_available() + .map_err(|error| error.to_string()), + renamed + .ensure_platform_adapter_available() + .map_err(|error| error.to_string()), + ); + assert_eq!( + discover_from_profile(&canonical, &context).unwrap(), + discover_from_profile(&renamed, &context).unwrap() + ); + } +} + +#[test] +fn canonical_id_without_declarations_has_no_special_behavior() { + let mut profile = profile(); + profile.id = "google-vertex-ai".into(); + profile.environment = EnvironmentProfile::default(); + profile.discovery.config_env_vars.clear(); + let mut env = HashMap::new(); + profile.environment.inject( + &HashMap::from([("VERTEX_AI_PROJECT_ID".into(), "project".into())]), + &mut env, + ); + assert!(env.is_empty()); + assert!( + discover_from_profile( + &profile, + &MockDiscoveryContext::new().with_env("VERTEX_AI_PROJECT_ID", "project") + ) + .unwrap() + .is_none() + ); +} + +#[test] +fn lint_rejects_non_secret_credential_collisions_and_duplicate_targets() { + let mut profile = profile(); + profile + .environment + .fixed + .insert("CUSTOM_TOKEN".into(), "value".into()); + profile + .environment + .fixed + .insert("CUSTOM_PROJECT".into(), "other".into()); + profile + .discovery + .config_env_vars + .push("CUSTOM_TOKEN".into()); + let diagnostics = validate_profile_set(&[("custom.yaml".into(), profile)]); + assert!( + diagnostics + .iter() + .any(|d| d.field == "environment" && d.message.contains("credential env_vars")) + ); + assert!( + diagnostics + .iter() + .any(|d| d.message.contains("both config and fixed")) + ); + assert!(diagnostics.iter().any( + |d| d.field == "discovery.config_env_vars" && d.message.contains("credential env_vars") + )); +} + +#[test] +fn lint_bounds_environment_and_discovery_declarations() { + let mut profile = profile(); + profile + .environment + .fixed + .insert("INVALID=NAME".into(), "value".into()); + profile + .environment + .fixed + .insert("LONG_VALUE".into(), "x".repeat(4097)); + profile + .discovery + .config_env_vars + .push("CUSTOM_PROJECT".into()); + profile.discovery.config_env_vars.push(" padded ".into()); + let diagnostics = validate_profile_set(&[("custom.yaml".into(), profile)]); + assert!(diagnostics.iter().any(|d| d.field == "environment")); + assert!(diagnostics.iter().any(|d| d.field == "environment.fixed")); + assert!( + diagnostics + .iter() + .any(|d| d.message == "duplicate discovery config key") + ); + assert!( + diagnostics + .iter() + .any(|d| d.message.contains("discovery config keys must")) + ); +} + +#[test] +fn lint_enforces_declaration_count_limits() { + let mut profile = profile(); + profile.environment.config.clear(); + profile.environment.fixed = (0..64) + .map(|index| (format!("CONFIG_{index}"), String::new())) + .collect(); + profile.discovery.config_env_vars = profile.environment.fixed.keys().cloned().collect(); + assert!(validate_profile_set(&[("custom.yaml".into(), profile.clone())]).is_empty()); + + profile + .environment + .config + .insert("EXTRA".into(), "extra".into()); + profile.discovery.config_env_vars.push("EXTRA".into()); + let diagnostics = validate_profile_set(&[("custom.yaml".into(), profile)]); + assert!( + diagnostics + .iter() + .any(|diagnostic| diagnostic.message == "at most 64 environment defaults are allowed") + ); + assert!( + diagnostics + .iter() + .any(|diagnostic| diagnostic.message == "at most 64 discovery config keys are allowed") + ); +} + +#[test] +fn unknown_and_unavailable_adapters_have_bounded_errors() { + let mut profile = profile(); + assert!( + profile + .ensure_platform_adapter_available() + .unwrap_err() + .to_string() + .contains("unavailable") + ); + profile.required_platform_adapter = "unknown".repeat(10_000); + let diagnostics = validate_profile_set(&[("custom.yaml".into(), profile.clone())]); + assert!( + diagnostics + .iter() + .any(|d| d.field == "required_platform_adapter") + ); + assert!(diagnostics.iter().all(|d| d.message.len() < 256)); + assert!( + profile + .ensure_platform_adapter_available() + .unwrap_err() + .to_string() + .len() + < 128 + ); + profile.required_platform_adapter.clear(); + assert!(profile.ensure_platform_adapter_available().is_ok()); +} diff --git a/crates/openshell-providers/src/lib.rs b/crates/openshell-providers/src/lib.rs index 87ac5d8007..393ff39345 100644 --- a/crates/openshell-providers/src/lib.rs +++ b/crates/openshell-providers/src/lib.rs @@ -5,10 +5,11 @@ mod context; mod discovery; +#[cfg(test)] +mod environment_tests; #[cfg(any(test, feature = "example-profiles"))] pub mod example_profiles; mod profiles; -mod providers; #[cfg(test)] mod test_helpers; @@ -16,25 +17,19 @@ use std::collections::HashMap; pub use openshell_core::proto::Provider; +/// Legacy Vertex bootstrap material must never become a workload credential. +/// Older stored profiles may still declare this key as an injectable env var. +pub const LEGACY_VERTEX_PRIVATE_KEY_ENV: &str = "GOOGLE_SERVICE_ACCOUNT_KEY"; + pub use context::{DiscoveryContext, RealDiscoveryContext}; -pub use discovery::{discover_from_profile, discover_with_spec}; +pub use discovery::discover_from_profile; pub use profiles::{ - CredentialRefreshProfile, ProfileError, ProfileValidationDiagnostic, ProviderTypeProfile, - is_gateway_mintable_strategy, normalize_profile_id, parse_profile_json, parse_profile_yaml, - profile_to_json, profile_to_yaml, profiles_to_json, profiles_to_yaml, strategy_output_env_key, - strategy_output_spec, strategy_primary_env_key, validate_profile_set, + CredentialRefreshProfile, EnvironmentProfile, ProfileError, ProfileValidationDiagnostic, + ProviderTypeProfile, is_gateway_mintable_strategy, normalize_profile_id, parse_profile_json, + parse_profile_yaml, profile_to_json, profile_to_yaml, profiles_to_json, profiles_to_yaml, + strategy_output_env_key, strategy_output_spec, strategy_primary_env_key, validate_profile_set, }; -pub const VERTEX_AI_PROJECT_ID_KEY: &str = "VERTEX_AI_PROJECT_ID"; -pub const VERTEX_AI_REGION_KEY: &str = "VERTEX_AI_REGION"; -pub const VERTEX_AI_CONFIG_KEY_NAMES: &[&str] = &[ - VERTEX_AI_PROJECT_ID_KEY, - VERTEX_AI_REGION_KEY, - "GOOGLE_VERTEX_AI_BASE_URL", - "VERTEX_AI_BASE_URL", - "VERTEX_AI_PUBLISHER", -]; - #[derive(Debug, thiserror::Error)] pub enum ProviderError { #[error("unsupported provider type: {0}")] @@ -46,6 +41,10 @@ pub enum ProviderError { profile_id: String, credential_name: String, }, + #[error("required platform adapter 'gcp-metadata' is unavailable in this build")] + UnavailableGcpMetadataAdapter, + #[error("unknown required platform adapter")] + UnknownPlatformAdapter, } #[derive(Debug, Clone, Default, PartialEq, Eq)] @@ -60,67 +59,3 @@ impl DiscoveredProvider { self.credentials.is_empty() && self.config.is_empty() } } - -#[derive(Debug, Clone, Copy)] -pub struct ProviderDiscoverySpec { - pub id: &'static str, - pub credential_env_vars: &'static [&'static str], -} - -trait ProviderPlugin: Send + Sync { - /// Canonical provider id. - fn id(&self) -> &'static str; - - /// Inject provider-specific environment variables into the sandbox env. - /// - /// Called during sandbox creation to project provider config (project IDs, - /// regions, SDK flags) into env vars the sandbox process will inherit. - /// Default is a no-op; GCP and Vertex providers override this. - fn inject_env(&self, _provider: &Provider, _env: &mut HashMap) {} -} - -#[derive(Default)] -pub struct ProviderRegistry { - plugins: HashMap<&'static str, Box>, -} - -impl ProviderRegistry { - #[must_use] - pub fn new() -> Self { - let mut registry = Self::default(); - // Keep only the legacy config projectors required to run existing - // Google Cloud and Vertex records. Public provider discovery is - // profile-driven; this registry is an internal compatibility adapter. - registry.register(providers::google_cloud::GoogleCloudProvider); - registry.register(providers::vertex::VertexProvider); - registry - } - - fn register

(&mut self, plugin: P) - where - P: ProviderPlugin + 'static, - { - self.plugins.insert(plugin.id(), Box::new(plugin)); - } - - #[must_use] - fn get(&self, id: &str) -> Option<&dyn ProviderPlugin> { - self.plugins.get(id).map(Box::as_ref) - } - - /// Inject provider-specific config for a resolved profile ID. - /// - /// Plugins are selected by the exact ID of the profile the gateway - /// resolved. There is no alias table: a profile activates the plugin whose - /// ID it matches, and nothing else does. - pub fn inject_env_for_profile_id( - &self, - provider: &Provider, - profile_id: &str, - env: &mut HashMap, - ) { - if let Some(plugin) = self.get(profile_id) { - plugin.inject_env(provider, env); - } - } -} diff --git a/crates/openshell-providers/src/profiles.rs b/crates/openshell-providers/src/profiles.rs index 74d7e44234..937198e2f8 100644 --- a/crates/openshell-providers/src/profiles.rs +++ b/crates/openshell-providers/src/profiles.rs @@ -13,7 +13,8 @@ use openshell_core::proto::{ ProviderCredentialRefreshMaterial, ProviderCredentialRefreshOutput, ProviderCredentialRefreshStrategy, ProviderCredentialTokenGrantSubjectToken, ProviderCredentialTokenGrantType, ProviderProfile, ProviderProfileCategory, - ProviderProfileCredential, ProviderProfileDiscovery, ProviderProfileFile, + ProviderProfileCredential, ProviderProfileDiscovery, ProviderProfileEnvironment, + ProviderProfileFile, }; use openshell_core::secrets::uses_reserved_revision_namespace; use openshell_policy::{ @@ -23,7 +24,7 @@ use openshell_policy::{ validate_l7_endpoint_semantics, }; use serde::{Deserialize, Deserializer, Serialize, Serializer, de}; -use std::collections::{BTreeSet, HashMap, HashSet}; +use std::collections::{BTreeMap, BTreeSet, HashMap, HashSet}; use std::net::IpAddr; const PATH_TEMPLATE_CREDENTIAL_PLACEHOLDER: &str = "{credential}"; @@ -318,6 +319,47 @@ pub struct CredentialRefreshOutputProfile { pub struct DiscoveryProfile { #[serde(default, skip_serializing_if = "Vec::is_empty")] pub credentials: Vec, + #[serde(default, skip_serializing_if = "Vec::is_empty")] + pub config_env_vars: Vec, +} + +/// Literal, non-secret workload environment defaults. +#[derive(Debug, Clone, Default, Deserialize, Serialize, PartialEq, Eq)] +#[serde(deny_unknown_fields)] +pub struct EnvironmentProfile { + /// Destination environment key -> provider config key. + #[serde(default, skip_serializing_if = "BTreeMap::is_empty")] + pub config: BTreeMap, + /// Destination environment key -> literal value. + #[serde(default, skip_serializing_if = "BTreeMap::is_empty")] + pub fixed: BTreeMap, +} + +impl EnvironmentProfile { + fn is_empty(&self) -> bool { + self.config.is_empty() && self.fixed.is_empty() + } + + /// Fill missing values only. Projection never changes a caller's value, + /// including an explicitly empty value. + pub fn inject(&self, config: &HashMap, env: &mut HashMap) { + for (key, config_key) in &self.config { + if key == crate::LEGACY_VERTEX_PRIVATE_KEY_ENV { + continue; + } + if let Some(value) = config.get(config_key).map(|value| value.trim()) + && !value.is_empty() + { + env.entry(key.clone()).or_insert_with(|| value.to_string()); + } + } + for (key, value) in &self.fixed { + if key == crate::LEGACY_VERTEX_PRIVATE_KEY_ENV { + continue; + } + env.entry(key.clone()).or_insert_with(|| value.clone()); + } + } } // These YAML/JSON DTOs mirror the network policy protos intentionally. Keep @@ -709,6 +751,10 @@ pub struct ProviderTypeProfile { pub inference_capable: bool, #[serde(default, skip_serializing_if = "discovery_is_empty")] pub discovery: DiscoveryProfile, + #[serde(default, skip_serializing_if = "EnvironmentProfile::is_empty")] + pub environment: EnvironmentProfile, + #[serde(default, skip_serializing_if = "String::is_empty")] + pub required_platform_adapter: String, #[serde(default, skip_serializing_if = "String::is_empty")] pub source: String, #[serde(default, skip_serializing_if = "String::is_empty")] @@ -795,6 +841,16 @@ fn valid_file_config_key(key: &str) -> bool { // narrower shape; direct gRPC imports and CLI YAML imports must preserve the // same policy intent through storage and JIT composition. impl ProviderTypeProfile { + /// Check runtime capability separately from schema lint. Recognizing an + /// adapter name does not imply this build provides the required service. + pub fn ensure_platform_adapter_available(&self) -> Result<(), crate::ProviderError> { + match self.required_platform_adapter.as_str() { + "" => Ok(()), + "gcp-metadata" => Err(crate::ProviderError::UnavailableGcpMetadataAdapter), + _ => Err(crate::ProviderError::UnknownPlatformAdapter), + } + } + #[must_use] pub fn from_proto(profile: &ProviderProfile) -> Self { Self { @@ -843,6 +899,14 @@ impl ProviderTypeProfile { .unwrap_or_default(), source: profile.source.clone(), scope: profile.scope.clone(), + environment: profile.environment.as_ref().map_or_else( + EnvironmentProfile::default, + |environment| EnvironmentProfile { + config: environment.config.clone(), + fixed: environment.fixed.clone(), + }, + ), + required_platform_adapter: profile.required_platform_adapter.clone(), } } @@ -1015,6 +1079,11 @@ impl ProviderTypeProfile { .then(|| discovery_to_proto(&self.discovery)), source: self.source.clone(), scope: self.scope.clone(), + environment: (!self.environment.is_empty()).then(|| ProviderProfileEnvironment { + config: self.environment.config.clone(), + fixed: self.environment.fixed.clone(), + }), + required_platform_adapter: self.required_platform_adapter.clone(), } } @@ -1206,7 +1275,7 @@ pub fn strategy_output_env_key( } fn discovery_is_empty(discovery: &DiscoveryProfile) -> bool { - discovery.credentials.is_empty() + discovery.credentials.is_empty() && discovery.config_env_vars.is_empty() } impl Serialize for BinaryProfile { @@ -1621,12 +1690,14 @@ fn token_grant_audience_override_to_proto( fn discovery_from_proto(discovery: &ProviderProfileDiscovery) -> DiscoveryProfile { DiscoveryProfile { credentials: discovery.credentials.clone(), + config_env_vars: discovery.config_env_vars.clone(), } } fn discovery_to_proto(discovery: &DiscoveryProfile) -> ProviderProfileDiscovery { ProviderProfileDiscovery { credentials: discovery.credentials.clone(), + config_env_vars: discovery.config_env_vars.clone(), } } @@ -2109,6 +2180,7 @@ pub fn validate_profile_set( let mut diagnostics = Vec::new(); let mut ids = HashSet::new(); for (source, profile) in profiles { + collect_environment_diagnostics(source, profile, &mut diagnostics); let raw_profile_id = profile.id.as_str(); let profile_id = raw_profile_id.trim(); if profile_id.is_empty() { @@ -3043,6 +3115,134 @@ pub fn validate_profile_set( diagnostics } +// Keep this declaration surface bounded and data-only. These limits apply to +// both YAML and protobuf imports through the shared profile validator. +const MAX_ENVIRONMENT_ENTRIES: usize = 64; +const MAX_ENVIRONMENT_KEY_BYTES: usize = 128; +const MAX_FIXED_ENVIRONMENT_VALUE_BYTES: usize = 4096; + +fn valid_environment_key(key: &str) -> bool { + let mut bytes = key.bytes(); + key.len() <= MAX_ENVIRONMENT_KEY_BYTES + && bytes + .next() + .is_some_and(|byte| byte == b'_' || byte.is_ascii_alphabetic()) + && bytes.all(|byte| byte == b'_' || byte.is_ascii_alphanumeric()) + && !uses_reserved_revision_namespace(key) +} + +fn collect_environment_diagnostics( + source: &str, + profile: &ProviderTypeProfile, + diagnostics: &mut Vec, +) { + let mut error = |field: &str, message: &str| { + diagnostics.push(ProfileValidationDiagnostic::error( + source, + &profile.id, + field, + message, + )); + }; + if !matches!( + profile.required_platform_adapter.as_str(), + "" | "gcp-metadata" + ) { + error( + "required_platform_adapter", + "unknown platform adapter; the only recognized adapter is gcp-metadata", + ); + } + let environment = &profile.environment; + if environment.config.len() + environment.fixed.len() > MAX_ENVIRONMENT_ENTRIES { + error("environment", "at most 64 environment defaults are allowed"); + } + let credential_keys = profile.credential_env_vars(); + for key in environment + .config + .keys() + .chain(environment.fixed.keys()) + .take(MAX_ENVIRONMENT_ENTRIES) + { + if key == crate::LEGACY_VERTEX_PRIVATE_KEY_ENV { + error( + "environment", + "GOOGLE_SERVICE_ACCOUNT_KEY contains private key material and cannot be a non-secret environment default", + ); + } + if !valid_environment_key(key) { + error( + "environment", + "environment keys must be valid non-reserved variable names of at most 128 bytes", + ); + } + if credential_keys.contains(&key.as_str()) { + error( + "environment", + "non-secret environment defaults must not collide with credential env_vars", + ); + } + } + for (key, config_key) in environment.config.iter().take(MAX_ENVIRONMENT_ENTRIES) { + if config_key.is_empty() + || config_key.trim() != config_key + || config_key.len() > MAX_ENVIRONMENT_KEY_BYTES + || config_key.contains('\0') + { + error( + "environment.config", + "config keys must be nonempty, unpadded strings of at most 128 bytes without NUL", + ); + } + if environment.fixed.contains_key(key) { + error( + "environment", + "an environment key cannot have both config and fixed defaults", + ); + } + } + for value in environment.fixed.values().take(MAX_ENVIRONMENT_ENTRIES) { + if value.len() > MAX_FIXED_ENVIRONMENT_VALUE_BYTES || value.contains('\0') { + error( + "environment.fixed", + "fixed values must contain at most 4096 bytes and no NUL", + ); + } + } + if profile.discovery.config_env_vars.len() > MAX_ENVIRONMENT_ENTRIES { + error( + "discovery.config_env_vars", + "at most 64 discovery config keys are allowed", + ); + } + let mut discovered = HashSet::new(); + for key in profile + .discovery + .config_env_vars + .iter() + .take(MAX_ENVIRONMENT_ENTRIES) + { + if !valid_environment_key(key) { + error( + "discovery.config_env_vars", + "discovery config keys must be valid non-reserved variable names of at most 128 bytes", + ); + } + if !discovered.insert(key) { + error( + "discovery.config_env_vars", + "duplicate discovery config key", + ); + } + if credential_keys.contains(&key.as_str()) { + error( + "discovery.config_env_vars", + "non-secret discovery config must not collide with credential env_vars", + ); + } + } +} + fn collect_mcp_profile_diagnostics( source: &str, profile_id: &str, @@ -3616,12 +3816,12 @@ mod tests { use openshell_core::proto::{ProviderCredentialTokenGrantType, ProviderProfileCategory}; use super::{ - DiscoveryProfile, EndpointProfile, L7AllowProfile, L7QueryMatcherProfile, - ProfileDurationWkt, ProfileError, ProviderTypeProfile, is_mcp_diagnostic_field, - normalize_profile_id, parse_profile_catalog_yamls, parse_profile_json, parse_profile_yaml, - profile_duration_to_proto, profile_to_json, profile_to_yaml, profiles_to_json, - profiles_to_yaml, token_grant_from_proto, token_grant_to_proto, validate_profile_duration, - validate_profile_set, + DiscoveryProfile, EndpointProfile, EnvironmentProfile, L7AllowProfile, + L7QueryMatcherProfile, ProfileDurationWkt, ProfileError, ProviderTypeProfile, + is_mcp_diagnostic_field, normalize_profile_id, parse_profile_catalog_yamls, + parse_profile_json, parse_profile_yaml, profile_duration_to_proto, profile_to_json, + profile_to_yaml, profiles_to_json, profiles_to_yaml, token_grant_from_proto, + token_grant_to_proto, validate_profile_duration, validate_profile_set, }; /// The example profiles in `providers/`, parsed once per test binary. @@ -5919,6 +6119,8 @@ binaries: ["", /usr/bin/broken] binaries: Vec::new(), inference_capable: false, discovery: DiscoveryProfile::default(), + environment: EnvironmentProfile::default(), + required_platform_adapter: String::new(), source: String::new(), scope: String::new(), }, @@ -5938,6 +6140,8 @@ binaries: ["", /usr/bin/broken] binaries: Vec::new(), inference_capable: false, discovery: DiscoveryProfile::default(), + environment: EnvironmentProfile::default(), + required_platform_adapter: String::new(), source: String::new(), scope: String::new(), }, @@ -5957,6 +6161,8 @@ binaries: ["", /usr/bin/broken] binaries: Vec::new(), inference_capable: false, discovery: DiscoveryProfile::default(), + environment: EnvironmentProfile::default(), + required_platform_adapter: String::new(), source: String::new(), scope: String::new(), }, diff --git a/crates/openshell-providers/src/providers/google_cloud.rs b/crates/openshell-providers/src/providers/google_cloud.rs deleted file mode 100644 index 3bea53d825..0000000000 --- a/crates/openshell-providers/src/providers/google_cloud.rs +++ /dev/null @@ -1,161 +0,0 @@ -// SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. -// SPDX-License-Identifier: Apache-2.0 - -use std::collections::HashMap; - -use openshell_core::google_cloud; - -use crate::{Provider, ProviderPlugin}; - -pub struct GoogleCloudProvider; - -impl ProviderPlugin for GoogleCloudProvider { - fn id(&self) -> &'static str { - "google-cloud" - } - - fn inject_env(&self, provider: &Provider, env: &mut HashMap) { - if let Some(project) = provider - .config - .get(google_cloud::GCP_PROJECT_ID_CONFIG_KEY) - .filter(|v| !v.trim().is_empty()) - { - for var in google_cloud::PROJECT_ID_ENV_VARS { - env.entry((*var).to_string()) - .or_insert_with(|| project.trim().to_string()); - } - } - - if let Some(region) = provider - .config - .get(google_cloud::GCP_REGION_CONFIG_KEY) - .filter(|v| !v.trim().is_empty()) - { - for var in google_cloud::REGION_ENV_VARS { - env.entry((*var).to_string()) - .or_insert_with(|| region.trim().to_string()); - } - } - - env.entry("GCE_METADATA_HOST".to_string()) - .or_insert_with(|| google_cloud::METADATA_HOST.to_string()); - - if let Some(email) = provider - .config - .get(google_cloud::GCP_SERVICE_ACCOUNT_EMAIL_CONFIG_KEY) - .filter(|v| !v.trim().is_empty()) - { - for var in google_cloud::SERVICE_ACCOUNT_EMAIL_ENV_VARS { - env.entry((*var).to_string()) - .or_insert_with(|| email.trim().to_string()); - } - } - } -} - -#[cfg(test)] -mod tests { - use super::*; - - fn make_provider(config: HashMap) -> Provider { - Provider { - config, - r#type: "google-cloud".to_string(), - ..Default::default() - } - } - - #[test] - fn injects_project_id_aliases() { - let provider = make_provider(HashMap::from([( - "project_id".to_string(), - "my-project".to_string(), - )])); - let mut env = HashMap::new(); - GoogleCloudProvider.inject_env(&provider, &mut env); - - assert_eq!( - env.get("GCP_PROJECT_ID").map(String::as_str), - Some("my-project") - ); - assert_eq!( - env.get("GOOGLE_CLOUD_PROJECT").map(String::as_str), - Some("my-project") - ); - } - - #[test] - fn injects_region_aliases() { - let provider = make_provider(HashMap::from([( - "region".to_string(), - "us-central1".to_string(), - )])); - let mut env = HashMap::new(); - GoogleCloudProvider.inject_env(&provider, &mut env); - - assert_eq!( - env.get("CLOUD_ML_REGION").map(String::as_str), - Some("us-central1") - ); - assert_eq!( - env.get("GCP_LOCATION").map(String::as_str), - Some("us-central1") - ); - } - - #[test] - fn injects_metadata_host() { - let provider = make_provider(HashMap::new()); - let mut env = HashMap::new(); - GoogleCloudProvider.inject_env(&provider, &mut env); - - assert_eq!( - env.get("GCE_METADATA_HOST").map(String::as_str), - Some(google_cloud::METADATA_HOST) - ); - } - - #[test] - fn injects_service_account_email() { - let provider = make_provider(HashMap::from([( - "service_account_email".to_string(), - "sa@project.iam.gserviceaccount.com".to_string(), - )])); - let mut env = HashMap::new(); - GoogleCloudProvider.inject_env(&provider, &mut env); - - assert_eq!( - env.get("GCP_SERVICE_ACCOUNT_EMAIL").map(String::as_str), - Some("sa@project.iam.gserviceaccount.com") - ); - } - - #[test] - fn does_not_overwrite_existing_env() { - let provider = make_provider(HashMap::from([( - "project_id".to_string(), - "new-project".to_string(), - )])); - let mut env = - HashMap::from([("GCP_PROJECT_ID".to_string(), "existing-project".to_string())]); - GoogleCloudProvider.inject_env(&provider, &mut env); - - assert_eq!( - env.get("GCP_PROJECT_ID").map(String::as_str), - Some("existing-project"), - "should not overwrite existing env" - ); - } - - #[test] - fn skips_empty_config_values() { - let provider = make_provider(HashMap::from([( - "project_id".to_string(), - " ".to_string(), - )])); - let mut env = HashMap::new(); - GoogleCloudProvider.inject_env(&provider, &mut env); - - assert!(!env.contains_key("GCP_PROJECT_ID")); - } -} diff --git a/crates/openshell-providers/src/providers/mod.rs b/crates/openshell-providers/src/providers/mod.rs deleted file mode 100644 index b6450e170e..0000000000 --- a/crates/openshell-providers/src/providers/mod.rs +++ /dev/null @@ -1,5 +0,0 @@ -// SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. -// SPDX-License-Identifier: Apache-2.0 - -pub mod google_cloud; -pub mod vertex; diff --git a/crates/openshell-providers/src/providers/vertex.rs b/crates/openshell-providers/src/providers/vertex.rs deleted file mode 100644 index e8e1857a91..0000000000 --- a/crates/openshell-providers/src/providers/vertex.rs +++ /dev/null @@ -1,149 +0,0 @@ -// SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. -// SPDX-License-Identifier: Apache-2.0 - -use std::collections::HashMap; - -use openshell_core::google_cloud; - -use crate::{Provider, ProviderPlugin, VERTEX_AI_PROJECT_ID_KEY, VERTEX_AI_REGION_KEY}; - -pub struct VertexProvider; - -impl ProviderPlugin for VertexProvider { - fn id(&self) -> &'static str { - "google-vertex-ai" - } - - fn inject_env(&self, provider: &Provider, env: &mut HashMap) { - if let Some(project) = provider - .config - .get(VERTEX_AI_PROJECT_ID_KEY) - .filter(|v| !v.trim().is_empty()) - { - let trimmed = project.trim().to_string(); - for var in google_cloud::PROJECT_ID_ENV_VARS { - env.entry((*var).to_string()) - .or_insert_with(|| trimmed.clone()); - } - env.entry(google_cloud::ANTHROPIC_VERTEX_PROJECT_ID_ENV_VAR.to_string()) - .or_insert_with(|| trimmed.clone()); - } - - if let Some(region) = provider - .config - .get(VERTEX_AI_REGION_KEY) - .filter(|v| !v.trim().is_empty()) - { - let trimmed = region.trim().to_string(); - for var in google_cloud::REGION_ENV_VARS { - env.entry((*var).to_string()) - .or_insert_with(|| trimmed.clone()); - } - env.entry(google_cloud::VERTEX_LOCATION_ENV_VAR.to_string()) - .or_insert_with(|| trimmed.clone()); - } - - env.entry(google_cloud::GOOSE_PROVIDER_ENV_VAR.to_string()) - .or_insert_with(|| "gcp_vertex_ai".to_string()); - } -} - -#[cfg(test)] -mod tests { - use super::*; - - fn make_provider(config: HashMap) -> Provider { - Provider { - config, - r#type: "google-vertex-ai".to_string(), - ..Default::default() - } - } - - #[test] - fn injects_project_id_and_anthropic_alias() { - let provider = make_provider(HashMap::from([( - "VERTEX_AI_PROJECT_ID".to_string(), - "my-vertex-project".to_string(), - )])); - let mut env = HashMap::new(); - VertexProvider.inject_env(&provider, &mut env); - - assert_eq!( - env.get("GCP_PROJECT_ID").map(String::as_str), - Some("my-vertex-project") - ); - assert_eq!( - env.get("GOOGLE_CLOUD_PROJECT").map(String::as_str), - Some("my-vertex-project") - ); - assert_eq!( - env.get("ANTHROPIC_VERTEX_PROJECT_ID").map(String::as_str), - Some("my-vertex-project") - ); - } - - #[test] - fn injects_region_and_vertex_location() { - let provider = make_provider(HashMap::from([( - "VERTEX_AI_REGION".to_string(), - "us-east4".to_string(), - )])); - let mut env = HashMap::new(); - VertexProvider.inject_env(&provider, &mut env); - - assert_eq!( - env.get("CLOUD_ML_REGION").map(String::as_str), - Some("us-east4") - ); - assert_eq!( - env.get("GCP_LOCATION").map(String::as_str), - Some("us-east4") - ); - assert_eq!( - env.get("VERTEX_LOCATION").map(String::as_str), - Some("us-east4") - ); - } - - #[test] - fn injects_inference_flags() { - let provider = make_provider(HashMap::new()); - let mut env = HashMap::new(); - VertexProvider.inject_env(&provider, &mut env); - - assert!(!env.contains_key("CLAUDE_CODE_USE_VERTEX")); - assert_eq!( - env.get("GOOSE_PROVIDER").map(String::as_str), - Some("gcp_vertex_ai") - ); - } - - #[test] - fn does_not_overwrite_existing_env() { - let provider = make_provider(HashMap::from([( - "VERTEX_AI_PROJECT_ID".to_string(), - "new".to_string(), - )])); - let mut env = HashMap::from([("GCP_PROJECT_ID".to_string(), "existing".to_string())]); - VertexProvider.inject_env(&provider, &mut env); - - assert_eq!( - env.get("GCP_PROJECT_ID").map(String::as_str), - Some("existing") - ); - } - - #[test] - fn skips_empty_config_values() { - let provider = make_provider(HashMap::from([( - "VERTEX_AI_PROJECT_ID".to_string(), - " ".to_string(), - )])); - let mut env = HashMap::new(); - VertexProvider.inject_env(&provider, &mut env); - - assert!(!env.contains_key("GCP_PROJECT_ID")); - assert!(!env.contains_key("ANTHROPIC_VERTEX_PROJECT_ID")); - } -} diff --git a/crates/openshell-sandbox/src/boundary_exec.rs b/crates/openshell-sandbox/src/boundary_exec.rs index da35294c06..313c1584a6 100644 --- a/crates/openshell-sandbox/src/boundary_exec.rs +++ b/crates/openshell-sandbox/src/boundary_exec.rs @@ -177,7 +177,10 @@ impl LocalBoundaryExec { command.env(key, value); } } - for (key, value) in self.provider_credentials.child_env_with_gcp_resolved() { + for (key, value) in self + .provider_credentials + .child_env_with_non_secret_resolved() + { if !crate::process::is_supervisor_only_env_var(&key) { command.env(key, value); } diff --git a/crates/openshell-server/src/grpc/policy.rs b/crates/openshell-server/src/grpc/policy.rs index 2d92a64ddc..8d3df496f7 100644 --- a/crates/openshell-server/src/grpc/policy.rs +++ b/crates/openshell-server/src/grpc/policy.rs @@ -3410,6 +3410,21 @@ pub(super) async fn load_sandbox_provider_environment( ) .await?; + // Sandbox template and spec values are caller-owned. Drop only non-secret + // profile defaults for those keys before sending the snapshot to either + // the canonical process or later execs. Credential keys keep their + // existing binding and placeholder precedence. + let caller_has_key = |key: &str| { + spec.environment.contains_key(key) + || spec + .template + .as_ref() + .is_some_and(|template| template.environment.contains_key(key)) + }; + provider_environment.environment.retain(|key, _| { + provider_environment.static_credential_keys.contains(key) || !caller_has_key(key) + }); + let mut readiness_reason = provider_environment.readiness_reason; if supports_static_credential_bindings { @@ -11290,6 +11305,7 @@ mod tests { discovery: None, source: String::new(), scope: String::new(), + ..Default::default() }), }) .await @@ -11397,6 +11413,7 @@ mod tests { discovery: None, source: String::new(), scope: String::new(), + ..Default::default() }), }) .await @@ -11456,6 +11473,7 @@ mod tests { discovery: None, source: String::new(), scope: String::new(), + ..Default::default() }), }) .await @@ -12614,6 +12632,7 @@ mod tests { discovery: None, source: String::new(), scope: String::new(), + ..Default::default() }), } } @@ -12903,6 +12922,74 @@ mod tests { ); } + #[tokio::test] + async fn caller_environment_wins_over_non_secret_profile_defaults_only() { + let state = test_server_state().await; + let mut profile = openshell_providers::example_profiles::load("github"); + profile.id = "declared-env".to_string(); + profile + .environment + .config + .insert("CUSTOM_PROJECT".to_string(), "project".to_string()); + profile + .environment + .fixed + .insert("CUSTOM_MODE".to_string(), "native".to_string()); + profile + .environment + .fixed + .insert("CUSTOM_UNSET".to_string(), "default".to_string()); + state + .store + .put_message(&crate::provider_profile_sources::stored_provider_profile( + profile.to_proto(), + )) + .await + .unwrap(); + + let mut provider = test_provider("work-env", "declared-env"); + provider + .config + .insert("project".to_string(), "profile-project".to_string()); + state.store.put_message(&provider).await.unwrap(); + let mut sandbox = test_sandbox( + "sb-caller-env", + "caller-env", + ProtoSandboxPolicy::default(), + vec!["work-env".to_string()], + ); + let spec = sandbox.spec.as_mut().unwrap(); + spec.environment + .insert("CUSTOM_PROJECT".to_string(), "caller-project".to_string()); + spec.environment + .insert("GITHUB_TOKEN".to_string(), "caller-token".to_string()); + spec.template + .get_or_insert_with(Default::default) + .environment + .insert("CUSTOM_MODE".to_string(), String::new()); + state.store.put_message(&sandbox).await.unwrap(); + + let snapshot = load_sandbox_provider_environment(&state, &sandbox, true) + .await + .unwrap(); + assert!(!snapshot.environment.contains_key("CUSTOM_PROJECT")); + assert!(!snapshot.environment.contains_key("CUSTOM_MODE")); + assert_eq!( + snapshot.environment.get("CUSTOM_UNSET").map(String::as_str), + Some("default") + ); + assert_eq!( + snapshot.environment.get("GITHUB_TOKEN").map(String::as_str), + Some("ghp-test") + ); + assert!( + snapshot + .static_credential_bindings + .contains_key("GITHUB_TOKEN") + ); + assert_eq!(snapshot.non_secret_environment_keys, ["CUSTOM_UNSET"]); + } + #[tokio::test] async fn provider_readiness_snapshot_uses_baseline_static_binding_contract() { let state = test_server_state().await; @@ -13830,6 +13917,7 @@ mod tests { discovery: None, source: String::new(), scope: String::new(), + ..Default::default() }), } } @@ -14166,6 +14254,7 @@ mod tests { discovery: None, source: String::new(), scope: String::new(), + ..Default::default() }), }], workspace_scope: Some(openshell_core::proto::workspace_selector( @@ -17832,6 +17921,7 @@ mod tests { discovery: None, source: String::new(), scope: String::new(), + ..Default::default() }), }) .await diff --git a/crates/openshell-server/src/grpc/provider.rs b/crates/openshell-server/src/grpc/provider.rs index cc2395fe7d..105895cdc5 100644 --- a/crates/openshell-server/src/grpc/provider.rs +++ b/crates/openshell-server/src/grpc/provider.rs @@ -31,6 +31,7 @@ use openshell_core::telemetry::{ LifecycleOperation, ProviderProfile as TelemetryProviderProfile, TelemetryOutcome, }; use openshell_policy::ProviderPolicyLayer; +use openshell_providers::LEGACY_VERTEX_PRIVATE_KEY_ENV; use prost::Message; use sha2::{Digest, Sha256}; use std::collections::{HashMap, HashSet}; @@ -1133,7 +1134,6 @@ pub(super) async fn resolve_provider_environment_from_records_with_policy_bindin let mut readiness_reason = openshell_core::proto::ProviderReadinessReason::Unspecified; let now_ms = crate::persistence::current_time_ms(); validate_provider_environment_records_unique_at(store, catalog, records, now_ms).await?; - let registry = openshell_providers::ProviderRegistry::new(); for record in records { let name = &record.name; @@ -1156,10 +1156,10 @@ pub(super) async fn resolve_provider_environment_from_records_with_policy_bindin .as_ref() .is_none_or(|profile| provider_profile_endpoints_are_active(profile, provider)); let profile_proto = profile.as_ref().map(ProviderTypeProfile::to_proto); - let broker_only_credential_keys = profile_proto - .as_ref() - .map(broker_only_provider_credential_keys) - .unwrap_or_default(); + let broker_only_credential_keys = profile_proto.as_ref().map_or_else( + reserved_bootstrap_credential_keys, + broker_only_provider_credential_keys, + ); let profile_endpoints = profile_proto.as_ref().map(|profile| { if !profile_endpoints_are_active { return Vec::new(); @@ -1203,27 +1203,25 @@ pub(super) async fn resolve_provider_environment_from_records_with_policy_bindin let refresh_epochs = refresh_authorization_epochs_by_key(record)?; for (key, value) in &provider.credentials { - if accepted_stored_credential_keys - .as_ref() - .is_some_and(|accepted| !accepted.contains(key)) - { + if broker_only_credential_keys.contains(key) { warn!( provider_name = %name, key = %key, - "withholding provider credential not declared by resolved profile" + "skipping non-injectable provider credential" ); - readiness_reason = - openshell_core::proto::ProviderReadinessReason::CredentialsWithheld; continue; } - if is_non_injectable_provider_credential(provider, key) - || broker_only_credential_keys.contains(key) + if accepted_stored_credential_keys + .as_ref() + .is_some_and(|accepted| !accepted.contains(key)) { warn!( provider_name = %name, key = %key, - "skipping non-injectable provider credential" + "withholding provider credential not declared by resolved profile" ); + readiness_reason = + openshell_core::proto::ProviderReadinessReason::CredentialsWithheld; continue; } if is_valid_env_key(key) { @@ -1295,34 +1293,30 @@ pub(super) async fn resolve_provider_environment_from_records_with_policy_bindin // Expired handles are removed by the credential runtime before values // reach this loop. Preserve omission evidence without exposing handles. if provider.credential_handles.keys().any(|key| { - !is_non_injectable_provider_credential(provider, key) - && !broker_only_credential_keys.contains(key) - && !resolved_refs.values.contains_key(key) + !broker_only_credential_keys.contains(key) && !resolved_refs.values.contains_key(key) }) { readiness_reason = openshell_core::proto::ProviderReadinessReason::CredentialExpired; } for (key, value) in resolved_refs.values { - if accepted_stored_credential_keys - .as_ref() - .is_some_and(|accepted| !accepted.contains(&key)) - { + if broker_only_credential_keys.contains(&key) { warn!( provider_name = %name, key = %key, - "withholding provider credential handle not declared by resolved profile" + "skipping non-injectable provider credential handle" ); - readiness_reason = - openshell_core::proto::ProviderReadinessReason::CredentialsWithheld; continue; } - if is_non_injectable_provider_credential(provider, &key) - || broker_only_credential_keys.contains(&key) + if accepted_stored_credential_keys + .as_ref() + .is_some_and(|accepted| !accepted.contains(&key)) { warn!( provider_name = %name, key = %key, - "skipping non-injectable provider credential handle" + "withholding provider credential handle not declared by resolved profile" ); + readiness_reason = + openshell_core::proto::ProviderReadinessReason::CredentialsWithheld; continue; } if is_valid_env_key(&key) { @@ -1371,7 +1365,7 @@ pub(super) async fn resolve_provider_environment_from_records_with_policy_bindin // provider's earlier output cannot change how this provider classifies // or populates its own keys. Cross-provider credential/config // collisions have already been rejected by the validation above. - inject_provider_plugin_environment(catalog, provider, ®istry, &mut provider_env); + inject_provider_profile_environment(catalog, provider, &mut provider_env)?; if let Some(profile) = profile.as_ref() { if !profile.files.is_empty() && (name.is_empty() @@ -1868,13 +1862,14 @@ pub async fn validate_provider_profiles_present( else { continue; }; - if get_provider_type_profile_for_scope( + if let Some(profile) = get_provider_type_profile_for_scope( catalog, &provider.r#type, &provider.profile_workspace, - ) - .is_some() - { + ) { + profile + .ensure_platform_adapter_available() + .map_err(|error| Status::failed_precondition(error.to_string()))?; continue; } let requested = provider.r#type.trim(); @@ -1981,7 +1976,7 @@ async fn validate_provider_environment_keys_unique_at( now_ms: i64, ) -> Result<(), Status> { let mut seen_credentials = HashMap::::new(); - let mut seen_plugin_config = HashMap::::new(); + let mut seen_profile_config = HashMap::::new(); let mut dynamic_bindings = Vec::new(); for name in provider_names { let provider = match candidate_provider { @@ -1997,10 +1992,10 @@ async fn validate_provider_environment_keys_unique_at( let provider_name = provider.object_name().to_string(); validate_provider_environment_key_ownership( &mut seen_credentials, - &mut seen_plugin_config, + &mut seen_profile_config, &provider_name, active_provider_environment_keys(store, catalog, &provider, now_ms).await?, - provider_plugin_environment_keys(catalog, &provider), + provider_profile_environment_values(catalog, &provider)?, )?; dynamic_bindings.extend(dynamic_token_grant_bindings_for_provider_with_catalog( catalog, &provider, @@ -2017,13 +2012,13 @@ async fn validate_provider_environment_records_unique_at( now_ms: i64, ) -> Result<(), Status> { let mut seen_credentials = HashMap::::new(); - let mut seen_plugin_config = HashMap::::new(); + let mut seen_profile_config = HashMap::::new(); let mut dynamic_bindings = Vec::new(); for record in records { let provider = &record.provider; validate_provider_environment_key_ownership( &mut seen_credentials, - &mut seen_plugin_config, + &mut seen_profile_config, &record.name, active_provider_environment_keys_for_identity( store, @@ -2033,7 +2028,7 @@ async fn validate_provider_environment_records_unique_at( now_ms, ) .await?, - provider_plugin_environment_keys(catalog, provider), + provider_profile_environment_values(catalog, provider)?, )?; dynamic_bindings.extend(dynamic_token_grant_bindings_for_provider_with_catalog( catalog, provider, @@ -2043,37 +2038,40 @@ async fn validate_provider_environment_records_unique_at( Ok(()) } -fn provider_plugin_environment_keys( +fn provider_profile_environment_values( catalog: &EffectiveProviderProfileCatalog, provider: &Provider, -) -> Vec { - let mut plugin_environment = HashMap::new(); - let registry = openshell_providers::ProviderRegistry::new(); - inject_provider_plugin_environment(catalog, provider, ®istry, &mut plugin_environment); - plugin_environment.into_keys().collect() +) -> Result, Status> { + let mut profile_environment = HashMap::new(); + inject_provider_profile_environment(catalog, provider, &mut profile_environment)?; + let mut values: Vec<_> = profile_environment.into_iter().collect(); + values.sort_unstable_by(|left, right| left.0.cmp(&right.0)); + Ok(values) } -fn inject_provider_plugin_environment( +fn inject_provider_profile_environment( catalog: &EffectiveProviderProfileCatalog, provider: &Provider, - registry: &openshell_providers::ProviderRegistry, environment: &mut HashMap, -) { - // A plugin activates only for a profile the gateway actually resolved. With - // no profile there is nothing to project. +) -> Result<(), Status> { + // Only the resolved profile declares non-secret environment defaults. if let Some(profile) = get_provider_type_profile_for_scope(catalog, &provider.r#type, &provider.profile_workspace) { - registry.inject_env_for_profile_id(provider, &profile.id, environment); + profile + .ensure_platform_adapter_available() + .map_err(|error| Status::failed_precondition(error.to_string()))?; + profile.environment.inject(&provider.config, environment); } + Ok(()) } fn validate_provider_environment_key_ownership( seen_credentials: &mut HashMap, - seen_plugin_config: &mut HashMap, + seen_profile_config: &mut HashMap, provider_name: &str, credential_keys: Vec, - plugin_config_keys: Vec, + profile_config_values: Vec<(String, String)>, ) -> Result<(), Status> { for key in credential_keys { if let Some(first_provider) = seen_credentials.get(&key) { @@ -2085,7 +2083,7 @@ fn validate_provider_environment_key_ownership( } else { seen_credentials.insert(key.clone(), provider_name.to_string()); } - if let Some(config_provider) = seen_plugin_config.get(&key) + if let Some((config_provider, _)) = seen_profile_config.get(&key) && config_provider != provider_name { return Err(provider_credential_config_key_collision( @@ -2096,7 +2094,18 @@ fn validate_provider_environment_key_ownership( } } - for key in plugin_config_keys { + for (key, value) in profile_config_values { + if let Some((config_provider, config_value)) = seen_profile_config.get(&key) + && config_provider != provider_name + && config_value != &value + { + let mut providers = [config_provider.as_str(), provider_name]; + providers.sort_unstable(); + return Err(Status::failed_precondition(format!( + "non-secret env key '{key}' is provided by both provider '{}' and provider '{}'; use provider-specific env names", + providers[0], providers[1] + ))); + } if let Some(credential_provider) = seen_credentials.get(&key) && credential_provider != provider_name { @@ -2106,9 +2115,9 @@ fn validate_provider_environment_key_ownership( provider_name, )); } - seen_plugin_config + seen_profile_config .entry(key) - .or_insert_with(|| provider_name.to_string()); + .or_insert_with(|| (provider_name.to_string(), value)); } Ok(()) } @@ -2329,7 +2338,6 @@ fn active_provider_credential_keys( let mut keys: Vec = provider .credentials .keys() - .filter(|key| !is_non_injectable_provider_credential(provider, key)) .filter(|key| !broker_only_credential_keys.contains(*key)) .filter(|key| is_valid_env_key(key)) .filter(|key| provider_credential_not_expired(provider, key, now_ms)) @@ -2339,7 +2347,6 @@ fn active_provider_credential_keys( provider .credential_handles .keys() - .filter(|key| !is_non_injectable_provider_credential(provider, key)) .filter(|key| !broker_only_credential_keys.contains(*key)) .filter(|key| is_valid_env_key(key)) .filter(|key| provider_credential_not_expired(provider, key, now_ms)) @@ -2355,12 +2362,13 @@ fn broker_only_provider_credential_keys_for_provider( get_provider_type_profile_for_scope(catalog, &provider.r#type, &provider.profile_workspace) .as_ref() .map(ProviderTypeProfile::to_proto) - .map(|profile| broker_only_provider_credential_keys(&profile)) - .unwrap_or_default() + .map_or_else(reserved_bootstrap_credential_keys, |profile| { + broker_only_provider_credential_keys(&profile) + }) } fn broker_only_provider_credential_keys(profile: &ProviderProfile) -> HashSet { - profile + let mut keys: HashSet<_> = profile .credentials .iter() .filter_map(|credential| credential.token_grant.as_ref()) @@ -2375,7 +2383,13 @@ fn broker_only_provider_credential_keys(profile: &ProviderProfile) -> HashSet HashSet { + HashSet::from([LEGACY_VERTEX_PRIVATE_KEY_ENV.to_string()]) } fn provider_credential_not_expired(provider: &Provider, key: &str, now_ms: i64) -> bool { @@ -2386,11 +2400,6 @@ fn provider_credential_not_expired(provider: &Provider, key: &str, now_ms: i64) .is_none_or(|expiration_ms| expiration_ms > now_ms) } -fn is_non_injectable_provider_credential(provider: &Provider, key: &str) -> bool { - normalize_profile_id(&provider.r#type).as_deref() == Some("google-vertex-ai") - && key == "GOOGLE_SERVICE_ACCOUNT_KEY" -} - pub(super) fn is_valid_env_key(key: &str) -> bool { let mut bytes = key.bytes(); let Some(first) = bytes.next() else { @@ -2841,6 +2850,8 @@ pub(super) async fn handle_import_provider_profiles( profile_conflict_diagnostics(state.store.as_ref(), &catalog, &workspace, &profiles).await?, ); diagnostics.extend(validate_profile_set(&profiles)); + diagnostics.extend(profile_adapter_diagnostics(&profiles)); + diagnostics.extend(profile_legacy_credential_diagnostics(&profiles)); if !has_errors(&diagnostics) { diagnostics.extend( profile_attached_sandbox_diagnostics( @@ -2943,6 +2954,8 @@ pub(super) async fn handle_update_provider_profiles( .await?, ); diagnostics.extend(validate_profile_set(&profiles)); + diagnostics.extend(profile_adapter_diagnostics(&profiles)); + diagnostics.extend(profile_legacy_credential_diagnostics(&profiles)); let expected_resource_version = if request.expected_resource_version != 0 { Some(request.expected_resource_version) } else { @@ -3063,6 +3076,7 @@ pub(super) async fn handle_lint_provider_profiles( profile_conflict_diagnostics(state.store.as_ref(), &catalog, &workspace, &profiles).await?, ); diagnostics.extend(validate_profile_set(&profiles)); + diagnostics.extend(profile_legacy_credential_diagnostics(&profiles)); let valid = !has_errors(&diagnostics); Ok(Response::new(LintProviderProfilesResponse { @@ -3477,6 +3491,48 @@ fn normalize_profile_id_request(id: &str) -> Result { }) } +fn profile_adapter_diagnostics( + profiles: &[(String, ProviderTypeProfile)], +) -> Vec { + profiles + .iter() + .filter_map(|(source, profile)| { + profile + .ensure_platform_adapter_available() + .err() + .map(|error| ProfileValidationDiagnostic { + source: source.clone(), + profile_id: profile.id.clone(), + field: "required_platform_adapter".to_string(), + message: error.to_string(), + severity: "error".to_string(), + }) + }) + .collect() +} + +fn profile_legacy_credential_diagnostics( + profiles: &[(String, ProviderTypeProfile)], +) -> Vec { + profiles + .iter() + .filter(|(_, profile)| { + profile.credentials.iter().any(|credential| { + credential + .accepted_stored_keys() + .contains(&LEGACY_VERTEX_PRIVATE_KEY_ENV) + }) + }) + .map(|(source, profile)| ProfileValidationDiagnostic { + source: source.clone(), + profile_id: profile.id.clone(), + field: "credentials.env_vars".to_string(), + message: "GOOGLE_SERVICE_ACCOUNT_KEY contains legacy service-account private key material and cannot be declared as a provider credential; configure refresh material instead".to_string(), + severity: "error".to_string(), + }) + .collect() +} + fn profiles_from_import_items( items: &[ProviderProfileImportItem], ) -> ( @@ -3745,7 +3801,7 @@ async fn profile_attached_sandbox_diagnostics( let has_static_credentials = provider .credentials .keys() - .any(|key| !is_non_injectable_provider_credential(&provider, key)); + .any(|key| profile.credential_env_vars().contains(&key.as_str())); let has_usable_endpoint = profile.to_proto().endpoints.iter().any(|endpoint| { !endpoint_ports(endpoint.port, &endpoint.ports).is_empty() && !endpoint.host.trim().is_empty() @@ -5228,6 +5284,15 @@ mod tests { .await .expect("store example provider profile"); } + // Binding tests need generic non-secret config, without a metadata + // service. Use an explicit data-only fork for those scenarios. + let mut cloud_config = openshell_providers::example_profiles::load("google-cloud"); + cloud_config.id = "cloud-env-fixture".to_string(); + cloud_config.required_platform_adapter.clear(); + store + .put_message(&stored_provider_profile(cloud_config.to_proto())) + .await + .unwrap(); store } use openshell_core::proto::{ @@ -5435,6 +5500,7 @@ mod tests { discovery: None, source: String::new(), scope: String::new(), + ..Default::default() }; let mut dynamic_creds = HashMap::new(); @@ -5450,6 +5516,137 @@ mod tests { } } + #[tokio::test] + async fn unavailable_platform_adapter_rejects_import_and_attachment() { + let state = test_server_state_without_provider_profiles().await; + let mut profile = custom_profile("requires-adapter"); + profile.required_platform_adapter = "gcp-metadata".to_string(); + let response = handle_import_provider_profiles( + &state, + authed_request(ImportProviderProfilesRequest { + profiles: vec![ProviderProfileImportItem { + profile: Some(profile.clone()), + source: "requires-adapter.yaml".to_string(), + }], + ..Default::default() + }), + ) + .await + .unwrap() + .into_inner(); + assert!(!response.imported); + assert!(response.diagnostics.iter().any(|diagnostic| { + diagnostic.field == "required_platform_adapter" + && diagnostic.message.contains("unavailable") + && diagnostic.message.len() < 128 + })); + + // Existing stored profiles and interceptor-vended profiles must also + // fail at attachment, even when they did not pass this build's import. + state + .store + .put_message(&stored_provider_profile(profile)) + .await + .unwrap(); + create_empty_token_grant_provider( + state.store.as_ref(), + "needs-adapter", + "requires-adapter", + ) + .await; + let catalog = ProviderProfileSources::with_default_sources() + .snapshot_catalog(state.store.as_ref(), "default") + .await + .unwrap(); + let error = validate_provider_profiles_present( + state.store.as_ref(), + &catalog, + "default", + &["needs-adapter".to_string()], + ) + .await + .unwrap_err(); + assert_eq!(error.code(), Code::FailedPrecondition); + assert!(error.message().contains("gcp-metadata")); + assert!(error.message().len() < 128); + let error = resolve_provider_environment( + state.store.as_ref(), + "default", + &["needs-adapter".to_string()], + ) + .await + .unwrap_err(); + assert_eq!(error.code(), Code::FailedPrecondition); + } + + #[tokio::test] + async fn import_rejects_legacy_vertex_private_key_declaration() { + let state = test_server_state_without_provider_profiles().await; + let mut profile = openshell_providers::example_profiles::load("google-vertex-ai"); + profile.id = "legacy-vertex-export".into(); + let mut legacy_credential = profile.credentials[0].clone(); + legacy_credential.name = "legacy_service_account_key".into(); + legacy_credential.env_vars = vec![LEGACY_VERTEX_PRIVATE_KEY_ENV.into()]; + legacy_credential.refresh = None; + profile.credentials.push(legacy_credential); + + let response = handle_import_provider_profiles( + &state, + authed_request(ImportProviderProfilesRequest { + profiles: vec![ProviderProfileImportItem { + profile: Some(profile.to_proto()), + source: "legacy.yaml".into(), + }], + ..Default::default() + }), + ) + .await + .unwrap() + .into_inner(); + assert!(!response.imported); + assert!(response.diagnostics.iter().any(|diagnostic| { + diagnostic.field == "credentials.env_vars" + && diagnostic.message.contains(LEGACY_VERTEX_PRIVATE_KEY_ENV) + })); + } + + #[tokio::test] + async fn import_rejects_legacy_vertex_private_key_environment_defaults() { + for config_default in [false, true] { + let state = test_server_state_without_provider_profiles().await; + let mut profile = openshell_providers::example_profiles::load("google-vertex-ai"); + if config_default { + profile + .environment + .config + .insert(LEGACY_VERTEX_PRIVATE_KEY_ENV.into(), "private_key".into()); + } else { + profile + .environment + .fixed + .insert(LEGACY_VERTEX_PRIVATE_KEY_ENV.into(), "private-key".into()); + } + let response = handle_import_provider_profiles( + &state, + authed_request(ImportProviderProfilesRequest { + profiles: vec![ProviderProfileImportItem { + profile: Some(profile.to_proto()), + source: "legacy.yaml".into(), + }], + ..Default::default() + }), + ) + .await + .unwrap() + .into_inner(); + assert!(!response.imported); + assert!(response.diagnostics.iter().any(|diagnostic| { + diagnostic.field == "environment" + && diagnostic.message.contains(LEGACY_VERTEX_PRIVATE_KEY_ENV) + })); + } + } + async fn import_token_grant_profile( state: &Arc, id: &str, @@ -6210,6 +6407,7 @@ mod tests { discovery: None, source: String::new(), scope: String::new(), + ..Default::default() } } @@ -7056,6 +7254,7 @@ mod tests { discovery: None, source: String::new(), scope: String::new(), + ..Default::default() }), source: "advanced-api.yaml".to_string(), }], @@ -10464,6 +10663,7 @@ mod tests { discovery: None, source: String::new(), scope: String::new(), + ..Default::default() }), source: "delegated-refresh-api.yaml".to_string(), }], @@ -12158,7 +12358,7 @@ mod tests { } #[tokio::test] - async fn provider_environment_rejects_plugin_config_credential_collision_in_both_orders() { + async fn provider_environment_rejects_profile_config_credential_collision_in_both_orders() { let store = test_store().await; create_provider_record( &store, @@ -12174,7 +12374,7 @@ mod tests { workspace: "default".to_string(), deletion_time: None, }), - r#type: "google-cloud".to_string(), + r#type: "cloud-env-fixture".to_string(), credentials: std::iter::once(( "GCP_ACCESS_TOKEN".to_string(), "google-token".to_string(), @@ -12247,134 +12447,299 @@ mod tests { } #[tokio::test] - async fn resolve_provider_env_injects_vertex_agent_config() { + async fn provider_environment_rejects_non_secret_overlap_in_both_orders() { let store = test_store().await; - create_provider_record( - &store, - "default", - Provider { - metadata: Some(openshell_core::proto::datamodel::v1::ObjectMeta { - id: String::new(), - name: "vertex-local".to_string(), - created_time: None, - labels: HashMap::new(), - resource_version: 0, - annotations: HashMap::new(), - workspace: "default".to_string(), - deletion_time: None, - }), - r#type: "google-vertex-ai".to_string(), - credentials: std::iter::once(( - "GOOGLE_VERTEX_AI_TOKEN".to_string(), - "ya29.token".to_string(), - )) - .collect(), - config: [ - ( - "VERTEX_AI_PROJECT_ID".to_string(), - "my-gcp-project".to_string(), - ), - ("VERTEX_AI_REGION".to_string(), "us-central1".to_string()), - ] - .into_iter() - .collect(), - credential_expiration_times: HashMap::new(), - profile_workspace: "default".to_string(), - credential_handles: HashMap::new(), - }, - ) - .await - .unwrap(); - - let result = resolve_provider_environment(&store, "default", &["vertex-local".to_string()]) + let mut project_profile = openshell_providers::example_profiles::load("google-cloud"); + project_profile.id = "project-env-fixture".into(); + project_profile.required_platform_adapter.clear(); + project_profile.environment.fixed.clear(); + project_profile + .environment + .config + .retain(|key, _| key == "GCP_PROJECT_ID"); + store + .put_message(&stored_provider_profile(project_profile.to_proto())) + .await + .unwrap(); + for (name, project) in [("project-a", "first"), ("project-b", "second")] { + create_provider_record( + &store, + "default", + Provider { + metadata: Some(openshell_core::proto::datamodel::v1::ObjectMeta { + id: String::new(), + name: name.to_string(), + created_time: None, + labels: HashMap::new(), + resource_version: 0, + annotations: HashMap::new(), + workspace: "default".to_string(), + deletion_time: None, + }), + r#type: "project-env-fixture".to_string(), + credentials: HashMap::new(), + config: HashMap::from([("project_id".to_string(), project.to_string())]), + credential_expiration_times: HashMap::new(), + profile_workspace: "default".to_string(), + credential_handles: HashMap::new(), + }, + ) .await .unwrap(); + } - // Credential still injected. - assert_eq!( - result.get("GOOGLE_VERTEX_AI_TOKEN"), - Some(&"ya29.token".to_string()) - ); - // Static flags. - assert!(!result.contains_key("CLAUDE_CODE_USE_VERTEX")); - assert_eq!( - result.get("GOOSE_PROVIDER"), - Some(&"gcp_vertex_ai".to_string()) - ); - // Project ID derived vars. - assert_eq!( - result.get("ANTHROPIC_VERTEX_PROJECT_ID"), - Some(&"my-gcp-project".to_string()) - ); - assert_eq!( - result.get("GCP_PROJECT_ID"), - Some(&"my-gcp-project".to_string()) - ); - assert_eq!( - result.get("GOOGLE_CLOUD_PROJECT"), - Some(&"my-gcp-project".to_string()) - ); - // Region derived vars. - assert_eq!( - result.get("CLOUD_ML_REGION"), - Some(&"us-central1".to_string()) - ); - assert_eq!(result.get("GCP_LOCATION"), Some(&"us-central1".to_string())); - assert_eq!( - result.get("VERTEX_LOCATION"), - Some(&"us-central1".to_string()) - ); + let mut messages = Vec::new(); + for providers in [ + vec!["project-a".to_string(), "project-b".to_string()], + vec!["project-b".to_string(), "project-a".to_string()], + ] { + let validation_error = + validate_provider_environment_keys_unique(&store, "default", &providers) + .await + .unwrap_err(); + let resolution_error = resolve_provider_environment(&store, "default", &providers) + .await + .unwrap_err(); + assert_eq!(validation_error.code(), Code::FailedPrecondition); + assert_eq!(validation_error.message(), resolution_error.message()); + assert!(validation_error.message().contains("GCP_PROJECT_ID")); + assert!(validation_error.message().contains("project-a")); + assert!(validation_error.message().contains("project-b")); + messages.push(validation_error.message().to_string()); + } + assert_eq!(messages[0], messages[1]); } #[tokio::test] - async fn resolve_provider_env_vertex_never_injects_service_account_key() { + async fn provider_environment_allows_identical_vertex_defaults_from_two_providers() { let store = test_store().await; - create_provider_record( - &store, - "default", - Provider { - metadata: Some(openshell_core::proto::datamodel::v1::ObjectMeta { - id: String::new(), - name: "vertex-bootstrap".to_string(), - created_time: None, - labels: HashMap::new(), - resource_version: 0, - annotations: HashMap::new(), - workspace: "default".to_string(), - deletion_time: None, - }), - r#type: "google-vertex-ai".to_string(), - credentials: [ - ( - "GOOGLE_SERVICE_ACCOUNT_KEY".to_string(), - r#"{"type":"service_account","private_key":"secret"}"#.to_string(), - ), - ( - "GOOGLE_VERTEX_AI_SERVICE_ACCOUNT_TOKEN".to_string(), - "ya29.short-lived".to_string(), - ), - ] - .into_iter() - .collect(), - config: HashMap::new(), - credential_expiration_times: HashMap::new(), - profile_workspace: "default".to_string(), - credential_handles: HashMap::new(), - }, - ) - .await - .unwrap(); + let profile = openshell_providers::example_profiles::load("google-vertex-ai"); + store + .put_message(&stored_provider_profile(profile.to_proto())) + .await + .unwrap(); + for (name, credential_key, token) in [ + ("vertex-a", "GOOGLE_VERTEX_AI_TOKEN", "token-a"), + ( + "vertex-b", + "GOOGLE_VERTEX_AI_SERVICE_ACCOUNT_TOKEN", + "token-b", + ), + ] { + let mut provider = + provider_with_credential_value(name, "google-vertex-ai", credential_key, token); + provider.config = HashMap::from([ + ("VERTEX_AI_PROJECT_ID".into(), "shared-project".into()), + ("VERTEX_AI_REGION".into(), "us-central1".into()), + ]); + create_provider_record(&store, "default", provider) + .await + .unwrap(); + } - let result = - resolve_provider_environment(&store, "default", &["vertex-bootstrap".to_string()]) + for names in [ + ["vertex-a".to_string(), "vertex-b".to_string()], + ["vertex-b".to_string(), "vertex-a".to_string()], + ] { + validate_provider_environment_keys_unique(&store, "default", &names) + .await + .unwrap(); + let result = resolve_provider_environment(&store, "default", &names) + .await + .unwrap(); + assert_eq!(result.get("GOOSE_PROVIDER"), Some(&"gcp_vertex_ai".into())); + assert_eq!(result.get("GCP_PROJECT_ID"), Some(&"shared-project".into())); + assert_eq!( + result.get("GOOGLE_VERTEX_AI_TOKEN"), + Some(&"token-a".into()) + ); + assert_eq!( + result.get("GOOGLE_VERTEX_AI_SERVICE_ACCOUNT_TOKEN"), + Some(&"token-b".into()) + ); + } + } + + #[tokio::test] + async fn resolve_provider_env_injects_vertex_agent_config() { + for profile_id in ["google-vertex-ai", "acme-vertex"] { + let store = test_store().await; + let mut fork = openshell_providers::example_profiles::load("google-vertex-ai"); + fork.id = "acme-vertex".to_string(); + store + .put_message(&stored_provider_profile(fork.to_proto())) .await .unwrap(); + create_provider_record( + &store, + "default", + Provider { + metadata: Some(openshell_core::proto::datamodel::v1::ObjectMeta { + id: String::new(), + name: "vertex-local".to_string(), + created_time: None, + labels: HashMap::new(), + resource_version: 0, + annotations: HashMap::new(), + workspace: "default".to_string(), + deletion_time: None, + }), + r#type: profile_id.to_string(), + credentials: std::iter::once(( + "GOOGLE_VERTEX_AI_TOKEN".to_string(), + "ya29.token".to_string(), + )) + .collect(), + config: [ + ( + "VERTEX_AI_PROJECT_ID".to_string(), + "my-gcp-project".to_string(), + ), + ("VERTEX_AI_REGION".to_string(), "us-central1".to_string()), + ] + .into_iter() + .collect(), + credential_expiration_times: HashMap::new(), + profile_workspace: "default".to_string(), + credential_handles: HashMap::new(), + }, + ) + .await + .unwrap(); - assert!(!result.contains_key("GOOGLE_SERVICE_ACCOUNT_KEY")); - assert_eq!( - result.get("GOOGLE_VERTEX_AI_SERVICE_ACCOUNT_TOKEN"), - Some(&"ya29.short-lived".to_string()) - ); + let result = + resolve_provider_environment(&store, "default", &["vertex-local".to_string()]) + .await + .unwrap(); + + // Credential still injected. + assert_eq!( + result.get("GOOGLE_VERTEX_AI_TOKEN"), + Some(&"ya29.token".to_string()) + ); + // Static flags. + assert!(!result.contains_key("CLAUDE_CODE_USE_VERTEX")); + assert_eq!( + result.get("GOOSE_PROVIDER"), + Some(&"gcp_vertex_ai".to_string()) + ); + // Project ID derived vars. + assert_eq!( + result.get("ANTHROPIC_VERTEX_PROJECT_ID"), + Some(&"my-gcp-project".to_string()) + ); + assert_eq!( + result.get("GCP_PROJECT_ID"), + Some(&"my-gcp-project".to_string()) + ); + assert_eq!( + result.get("GOOGLE_CLOUD_PROJECT"), + Some(&"my-gcp-project".to_string()) + ); + // Region derived vars. + assert_eq!( + result.get("CLOUD_ML_REGION"), + Some(&"us-central1".to_string()) + ); + assert_eq!(result.get("GCP_LOCATION"), Some(&"us-central1".to_string())); + assert_eq!( + result.get("VERTEX_LOCATION"), + Some(&"us-central1".to_string()) + ); + } + } + + #[tokio::test] + async fn resolve_provider_env_vertex_never_injects_service_account_key() { + for (profile_id, declares_legacy_key) in + [("google-vertex-ai", false), ("acme-vertex", true)] + { + let store = test_store().await; + let mut fork = openshell_providers::example_profiles::load("google-vertex-ai"); + fork.id = profile_id.to_string(); + if declares_legacy_key { + let mut legacy_credential = fork.credentials[0].clone(); + legacy_credential.name = "legacy_service_account_key".into(); + legacy_credential.env_vars = vec![LEGACY_VERTEX_PRIVATE_KEY_ENV.into()]; + legacy_credential.refresh = None; + fork.credentials.push(legacy_credential); + } + store + .put_message(&stored_provider_profile(fork.to_proto())) + .await + .unwrap(); + create_provider_record( + &store, + "default", + Provider { + metadata: Some(openshell_core::proto::datamodel::v1::ObjectMeta { + id: String::new(), + name: "vertex-bootstrap".to_string(), + created_time: None, + labels: HashMap::new(), + resource_version: 0, + annotations: HashMap::new(), + workspace: "default".to_string(), + deletion_time: None, + }), + r#type: profile_id.to_string(), + credentials: [ + ( + "GOOGLE_SERVICE_ACCOUNT_KEY".to_string(), + r#"{"type":"service_account","private_key":"secret"}"#.to_string(), + ), + ( + "GOOGLE_VERTEX_AI_SERVICE_ACCOUNT_TOKEN".to_string(), + "ya29.short-lived".to_string(), + ), + ] + .into_iter() + .collect(), + config: HashMap::from([ + ("VERTEX_AI_PROJECT_ID".to_string(), "my-project".to_string()), + ("VERTEX_AI_REGION".to_string(), "us-central1".to_string()), + ]), + credential_expiration_times: HashMap::new(), + profile_workspace: "default".to_string(), + credential_handles: HashMap::new(), + }, + ) + .await + .unwrap(); + + let result = + resolve_provider_environment(&store, "default", &["vertex-bootstrap".to_string()]) + .await + .unwrap(); + + assert!(!result.contains_key("GOOGLE_SERVICE_ACCOUNT_KEY")); + assert!( + !result + .static_credential_bindings + .contains_key("GOOGLE_SERVICE_ACCOUNT_KEY") + ); + assert!( + !result + .static_credential_keys + .contains("GOOGLE_SERVICE_ACCOUNT_KEY") + ); + assert_eq!( + result.get("GOOGLE_VERTEX_AI_SERVICE_ACCOUNT_TOKEN"), + Some(&"ya29.short-lived".to_string()) + ); + assert_eq!( + result.readiness_reason, + openshell_core::proto::ProviderReadinessReason::Unspecified + ); + assert_eq!( + result.get("GCP_PROJECT_ID"), + Some(&"my-project".to_string()) + ); + assert_eq!( + result.get("CLOUD_ML_REGION"), + Some(&"us-central1".to_string()) + ); + } } #[tokio::test] @@ -12644,7 +13009,7 @@ mod tests { } #[tokio::test] - async fn update_provider_rejects_plugin_config_credential_collision() { + async fn update_provider_rejects_profile_config_credential_collision() { let store = test_store().await; create_provider_record( &store, @@ -12660,7 +13025,7 @@ mod tests { workspace: "default".to_string(), deletion_time: None, }), - r#type: "google-cloud".to_string(), + r#type: "cloud-env-fixture".to_string(), credentials: std::iter::once(( "GCP_ACCESS_TOKEN".to_string(), "google-token".to_string(), @@ -14287,7 +14652,7 @@ mod tests { workspace: "default".to_string(), deletion_time: None, }), - r#type: "google-cloud".to_string(), + r#type: "cloud-env-fixture".to_string(), credentials: HashMap::new(), config, credential_expiration_times: HashMap::new(), @@ -14296,143 +14661,6 @@ mod tests { } } - #[test] - fn inject_gcp_env_sets_metadata_host() { - use openshell_core::google_cloud; - let provider = google_cloud_provider(HashMap::new()); - let mut env = HashMap::new(); - openshell_providers::ProviderRegistry::new().inject_env_for_profile_id( - &provider, - &provider.r#type, - &mut env, - ); - assert_eq!( - env.get("GCE_METADATA_HOST").map(String::as_str), - Some(google_cloud::METADATA_HOST), - ); - assert!( - !env.contains_key("CLAUDE_CODE_USE_VERTEX"), - "CLAUDE_CODE_USE_VERTEX is synthetic, should not be injected here" - ); - } - - #[test] - fn inject_gcp_env_propagates_project_id() { - use openshell_core::google_cloud; - let provider = google_cloud_provider(HashMap::from([( - "project_id".to_string(), - "my-project".to_string(), - )])); - let mut env = HashMap::new(); - openshell_providers::ProviderRegistry::new().inject_env_for_profile_id( - &provider, - &provider.r#type, - &mut env, - ); - for var in google_cloud::PROJECT_ID_ENV_VARS { - assert_eq!( - env.get(*var).map(String::as_str), - Some("my-project"), - "{var} should be set to project_id config value" - ); - } - } - - #[test] - fn inject_gcp_env_propagates_region() { - use openshell_core::google_cloud; - let provider = google_cloud_provider(HashMap::from([( - "region".to_string(), - "us-central1".to_string(), - )])); - let mut env = HashMap::new(); - openshell_providers::ProviderRegistry::new().inject_env_for_profile_id( - &provider, - &provider.r#type, - &mut env, - ); - for var in google_cloud::REGION_ENV_VARS { - assert_eq!( - env.get(*var).map(String::as_str), - Some("us-central1"), - "{var} should be set to region config value" - ); - } - } - - #[test] - fn inject_gcp_env_propagates_service_account_email() { - use openshell_core::google_cloud; - let provider = google_cloud_provider(HashMap::from([( - "service_account_email".to_string(), - "sa@proj.iam.gserviceaccount.com".to_string(), - )])); - let mut env = HashMap::new(); - openshell_providers::ProviderRegistry::new().inject_env_for_profile_id( - &provider, - &provider.r#type, - &mut env, - ); - for var in google_cloud::SERVICE_ACCOUNT_EMAIL_ENV_VARS { - assert_eq!( - env.get(*var).map(String::as_str), - Some("sa@proj.iam.gserviceaccount.com"), - "{var} should be set to service_account_email config value" - ); - } - } - - #[test] - fn inject_gcp_env_does_not_overwrite_existing_values() { - let provider = google_cloud_provider(HashMap::from([( - "project_id".to_string(), - "from-config".to_string(), - )])); - let mut env = HashMap::from([("GCP_PROJECT_ID".to_string(), "user-override".to_string())]); - openshell_providers::ProviderRegistry::new().inject_env_for_profile_id( - &provider, - &provider.r#type, - &mut env, - ); - assert_eq!( - env.get("GCP_PROJECT_ID").map(String::as_str), - Some("user-override"), - "user-provided value should not be overwritten" - ); - } - - #[test] - fn inject_non_gcp_provider_does_nothing() { - let provider = Provider { - metadata: Some(openshell_core::proto::datamodel::v1::ObjectMeta { - id: String::new(), - name: "github".to_string(), - created_time: None, - labels: HashMap::new(), - resource_version: 0, - annotations: HashMap::new(), - workspace: "default".to_string(), - deletion_time: None, - }), - r#type: "github".to_string(), - credentials: HashMap::new(), - config: HashMap::from([("project_id".to_string(), "should-be-ignored".to_string())]), - credential_expiration_times: HashMap::new(), - profile_workspace: "default".to_string(), - credential_handles: HashMap::new(), - }; - let mut env = HashMap::new(); - openshell_providers::ProviderRegistry::new().inject_env_for_profile_id( - &provider, - &provider.r#type, - &mut env, - ); - assert!( - env.is_empty(), - "non-GCP provider should not inject any env vars" - ); - } - #[tokio::test] async fn provider_crud_is_workspace_isolated() { use openshell_core::proto::{ diff --git a/crates/openshell-server/src/provider_profile_sources.rs b/crates/openshell-server/src/provider_profile_sources.rs index 6728b2f0c1..cf46cb1ae5 100644 --- a/crates/openshell-server/src/provider_profile_sources.rs +++ b/crates/openshell-server/src/provider_profile_sources.rs @@ -971,6 +971,51 @@ mod tests { .expect("canonical provider profile MCP options") } + #[test] + fn environment_profile_fingerprints_survive_storage_round_trips() { + let profile = openshell_providers::example_profiles::load("google-vertex-ai").to_proto(); + let encoded = profile.encode_to_vec(); + let revision = profile_snapshot_revision(std::slice::from_ref(&profile)); + let fingerprint = |profile| { + let catalog = build_effective_profiles(vec![CollectedProviderProfileSnapshot { + source_id: "external/test".to_string(), + revision: "same-revision".to_string(), + profiles: vec![ScopedSnapshotProfile { + scope: ProfileScope::Static, + profile, + }], + user_managed: false, + allow_empty: false, + }]) + .expect("valid environment profile"); + let mut hash = Sha256::new(); + catalog.hash_type_profile_revision_for_scope("google-vertex-ai", "", &mut hash); + hash.finalize() + }; + let original_fingerprint = fingerprint(profile.clone()); + for _ in 0..16 { + let decoded = ProviderProfile::decode(encoded.as_slice()).unwrap(); + assert_eq!( + profile_snapshot_revision(std::slice::from_ref(&decoded)), + revision + ); + assert_eq!(fingerprint(decoded), original_fingerprint); + } + + let mut changed = profile; + changed + .environment + .as_mut() + .unwrap() + .fixed + .insert("GOOSE_PROVIDER".to_string(), "custom_vertex".to_string()); + assert_ne!( + profile_snapshot_revision(std::slice::from_ref(&changed)), + revision + ); + assert_ne!(fingerprint(changed), original_fingerprint); + } + #[test] fn equivalent_mcp_version_order_produces_identical_source_profile_fingerprints() { let catalog = |versions: &[&str]| { diff --git a/crates/openshell-server/src/storage_proto.rs b/crates/openshell-server/src/storage_proto.rs index e6d8730aa0..d323df797d 100644 --- a/crates/openshell-server/src/storage_proto.rs +++ b/crates/openshell-server/src/storage_proto.rs @@ -121,19 +121,18 @@ mod tests { // Restart policy is stored in SandboxSpec, and the count and well-known // timestamps are stored in SandboxStatus. Legacy payloads decode with // Unspecified (treated as Never), zero count, and absent timestamps. - // ProviderProfileFile is reachable from stored provider profiles. Its - // additive declaration changes the durable and public/durable overlap - // inventories; the provider-environment file map is public-only. The - // request has no provider-file capability field: older supervisors ignore - // the additive file map while retaining the rest of the response. + // ProviderProfileFile and ProviderProfileEnvironment are reachable from + // stored provider profiles. Their additive declarations belong to the + // public and durable closures while preserving existing field tags and + // legacy payload decoding. // Service authorization also extends both schemas additively. Legacy // payloads retain the safe Strip default. const PUBLIC_RPC_SCHEMA_SHA256: &str = - "2e156c6ad3c8eb51bcd30dc13b173fe339b38207a1b1f98f7be2e0cad8e3bd45"; + "05dbd2f44792a9380bbe62cc083740f1b3e3ba05c82b8c2e4397ab8b00e9898f"; const DURABLE_SCHEMA_SHA256: &str = - "38165d9d76f49fcfe98a12f241e032838a2376c1d1a87ea2796fd33b9b1a3541"; + "1e6810d012862fa8a4b364d1d395a3f1dca1381f457a4f5ad34c023d7a1714cb"; const PUBLIC_DURABLE_OVERLAP_SHA256: &str = - "761dea31a521b0650840fe2a823ad6e36a265ed323ba4506889781d630df0ee3"; + "e6823be4512eb3731a1a04aa89215b6c2c2acaef1c99735c1a4c9e3b50ff8ee4"; // A persisted Sandbox without endpoint status retains its lifecycle fields; // the absent repeated field decodes empty and needs no database rewrite. const SANDBOX_WITHOUT_ENDPOINT_STATUS: &str = "0a1e0a0a73616e64626f782d6964120773616e64626f783a0764656661756c741a2b0a0773616e64626f782a0d0a05526561647912045472756530023807420d73757065727669736f722d6964"; @@ -598,9 +597,9 @@ mod tests { overlap_hash.as_str(), ), ( - (306, 27), - (93, 21), - (81, 21), + (309, 27), + (96, 21), + (84, 21), PUBLIC_RPC_SCHEMA_SHA256, DURABLE_SCHEMA_SHA256, PUBLIC_DURABLE_OVERLAP_SHA256 @@ -724,6 +723,8 @@ mod tests { let profile = profile.profile.expect("profile"); assert_eq!(profile.id, "profile"); assert_eq!(profile.display_name, "Legacy"); + assert!(profile.environment.is_none()); + assert!(profile.required_platform_adapter.is_empty()); let policy_payload = PolicyRevisionPayload::decode(legacy_bytes(V0_0_116_POLICY_PAYLOAD).as_slice()) diff --git a/crates/openshell-supervisor/src/lib.rs b/crates/openshell-supervisor/src/lib.rs index 63c5302673..cd287513b6 100644 --- a/crates/openshell-supervisor/src/lib.rs +++ b/crates/openshell-supervisor/src/lib.rs @@ -5878,7 +5878,7 @@ network_policies: static_provider_environment(1, Some("initial")), &readiness, ); - let (revision, child_env) = state.child_env_snapshot_with_gcp_resolved().unwrap(); + let (revision, child_env) = state.child_env_snapshot_with_non_secret_resolved().unwrap(); let reference = &child_env["EXTERNAL_TOKEN"]; assert_eq!(revision, 1); assert_eq!(reference, "openshell:resolve:env:v1_EXTERNAL_TOKEN"); diff --git a/docs/how-it-works/providers/google.mdx b/docs/how-it-works/providers/google.mdx index 2c7091476c..6a35c17b72 100644 --- a/docs/how-it-works/providers/google.mdx +++ b/docs/how-it-works/providers/google.mdx @@ -7,201 +7,47 @@ description: "Authenticate with Google Cloud APIs and Vertex AI inside OpenShell keywords: "Generative AI, Google Cloud, Vertex AI, GCP, OAuth2, Credentials, Sandbox" --- -The `google-cloud` provider gives sandboxes native GCP credentials so -any Google Cloud SDK works out of the box — Cloud Storage, BigQuery, Drive, -Maps, Discovery Engine, or any other GCP API. A GCE metadata server emulator -on loopback provides credential placeholders that the -sandbox proxy resolves to real tokens at request time. The sandbox process -never holds a real GCP credential. +Google provider profiles declare credential refresh, environment defaults, and +local discovery behavior. The Vertex AI profile supports native API requests +with gateway-refreshed bearer tokens. -## Quick Start +## Google Cloud Metadata -Import the `google-cloud` profile first; a gateway serves only the profiles you -imported: +The `google-cloud` example requires the `gcp-metadata` platform adapter for GCP +SDK metadata discovery. Current runtimes do not provide this adapter. Import, +update, and attachment reject that requirement with: -```shell -openshell profile import --url https://raw.githubusercontent.com/NVIDIA/OpenShell/main/providers/google-cloud.yaml --global -``` - -If you already have `gcloud` configured with Application Default Credentials, -create a provider with automatic credential refresh in one command: - -```shell -openshell provider create \ - --name my-gcp \ - --type google-cloud \ - --from-gcloud-adc \ - --config project_id="$(gcloud config get-value project)" \ - --config region=global -``` - -`--from-gcloud-adc` reads your ADC file, configures OAuth2 refresh on the -gateway, and mints the first access token before the command returns. The -gateway rotates the token automatically — no manual refresh needed. - -## Authentication Flows - -Two credential flows are supported. Choose based on your environment. - -### Application Default Credentials (gcloud ADC) - -Use credentials from `gcloud auth application-default login`. The gateway -exchanges the refresh token for short-lived access tokens automatically. - -```shell -openshell provider create \ - --name my-gcp \ - --type google-cloud \ - --config project_id=my-project \ - --config region=us-central1 \ - --credential GCP_ADC_ACCESS_TOKEN=placeholder -``` - -Configure credential refresh with the ADC JSON fields: - -```shell -openshell provider refresh configure my-gcp \ - --credential-key GCP_ADC_ACCESS_TOKEN \ - --strategy oauth2-refresh-token \ - --material client_id=YOUR_CLIENT_ID \ - --material client_secret=YOUR_CLIENT_SECRET \ - --material refresh_token=YOUR_REFRESH_TOKEN \ - --secret-material-key client_secret \ - --secret-material-key refresh_token -``` - -Find these values in your ADC file at -`~/.config/gcloud/application_default_credentials.json`. - -Trigger the first token mint: - -```shell -openshell provider refresh rotate my-gcp \ - --credential-key GCP_ADC_ACCESS_TOKEN -``` - -### Service Account Key - -Use a GCP service account JSON key file. The gateway signs JWTs and -exchanges them for access tokens using the `google-service-account-jwt` -strategy. - -```shell -openshell provider create \ - --name my-gcp \ - --type google-cloud \ - --config project_id=my-project \ - --config region=us-central1 \ - --credential GCP_SA_ACCESS_TOKEN=placeholder -``` - -```shell -openshell provider refresh configure my-gcp \ - --credential-key GCP_SA_ACCESS_TOKEN \ - --strategy google-service-account-jwt \ - --material client_email=sa@my-project.iam.gserviceaccount.com \ - --material private_key="$(jq -r .private_key /path/to/sa-key.json)" \ - --secret-material-key private_key +```text +required platform adapter 'gcp-metadata' is unavailable in this build ``` -```shell -openshell provider refresh rotate my-gcp \ - --credential-key GCP_SA_ACCESS_TOKEN -``` - -## Configuration Keys - -Set these with `--config key=value` during provider creation: - -| Key | Description | Example | -|-----|-------------|---------| -| `project_id` | GCP project ID | `my-project-123` | -| `region` | GCP region | `us-central1` | -| `service_account_email` | SA email for metadata endpoint | `sa@proj.iam.gserviceaccount.com` | - -## How It Works - -When a sandbox starts with the `google-cloud` provider attached: - -1. The gateway mints a fresh GCP access token and stores it in the - sandbox proxy's credential resolver. -2. A loopback HTTP server on `127.0.0.1:8174` emulates the GCE instance - metadata API, serving **credential placeholders** (not real tokens) to - GCP SDKs. The sandbox process never holds a real GCP credential. -3. When the SDK makes an API call, it sends the placeholder in the - `Authorization` header. The sandbox proxy TLS-terminates the - outbound connection, resolves the placeholder to the real token, - and forwards the request to GCP. -4. When the token approaches expiry, the gateway refreshes it. The - proxy's resolver is updated atomically — subsequent API calls - use the new token automatically. - -Configuration values (`project_id`, `region`, `service_account_email`) -are **visible in plain text** inside the sandbox — they appear as -environment variables and are served by the metadata endpoint. These are -non-secret identifiers, not credentials. Access tokens are never exposed; -only placeholders reach the sandbox process. - -### Injected Environment Variables - -The provider automatically injects these into the sandbox. Non-secret -vars are resolved to real values at process spawn time; token vars stay -as placeholders for proxy-time resolution. - -| Variable | Value | Purpose | -|----------|-------|---------| -| `GCE_METADATA_HOST` | `127.0.0.1:8174` | GCP SDK metadata discovery (loopback server) | -| `GCE_METADATA_IP` | `127.0.0.1:8174` | Python google-auth ping detection | -| `METADATA_SERVER_DETECTION` | `assume-present` | Node.js gcp-metadata skip detection | -| `GCP_PROJECT_ID` | from `project_id` config | GCP SDK project | -| `GOOGLE_CLOUD_PROJECT` | from `project_id` config | Alternative project var | -| `CLOUD_ML_REGION` | from `region` config | GCP region | -| `GCP_LOCATION` | from `region` config | Alternative region var | - -## Using with GCP APIs - -The metadata emulator serves tokens with the `cloud-platform` OAuth2 scope, -which grants access to any GCP API the underlying service account has IAM -permissions for. Add the target API hosts to your sandbox network policy: - -Attach `my-gcp` to the sandbox first. Because the `google-cloud` profile has no -endpoints, each API endpoint must bind to that provider instance. Without the -binding, OpenShell withholds its access token from the sandbox. - -```yaml -network_policies: - gcp_apis: - name: gcp-apis - endpoints: - - host: "*.googleapis.com" - port: 443 - protocol: rest - access: read-write - enforcement: enforce - credential_binding: - provider: my-gcp - binaries: - - { path: /usr/bin/curl } - - { path: /usr/bin/node } - - { path: "/sandbox/.uv/python/**" } - - { path: "/sandbox/.venv/**" } -``` - -For a running sandbox, export its base policy. Remove the metadata header above -the `---` line, add the endpoint and binaries shown above, then apply the file: - -```shell -openshell policy get my-sandbox --base > sandbox-policy.yaml -# Edit sandbox-policy.yaml to add the gcp_apis rule shown above. -openshell policy set my-sandbox --policy sandbox-policy.yaml --wait -``` - -## Network Policy - -The `google-cloud` provider type does not include any network policy -endpoints by default. You must add endpoint rules to your sandbox policy -for each GCP API the sandbox needs to reach. See "Using with GCP APIs" -above for an example. +The metadata server was removed during the supervisor/sandbox runtime split in +[PR #2942](https://github.com/NVIDIA/OpenShell/pull/2942). The example now declares +its dependency so provider setup reports the missing capability before a +workload attempts metadata authentication. Removing the requirement does not +supply a metadata server. + +The example records these non-secret defaults as profile data: + +| Variable | Declared value | +|---|---| +| `GCE_METADATA_HOST` | `127.0.0.1:8174` | +| `GCE_METADATA_IP` | `127.0.0.1:8174` | +| `METADATA_SERVER_DETECTION` | `assume-present` | +| `GCP_PROJECT_ID`, `GOOGLE_CLOUD_PROJECT` | `project_id` config | +| `CLOUD_ML_REGION`, `GCP_LOCATION` | `region` config | +| `GCP_SERVICE_ACCOUNT_EMAIL` | `service_account_email` config | + +For other Google Cloud APIs, author a +[provider profile](/how-it-works/providers/profiles) that declares the API endpoints, +client `binaries`, non-secret project and region settings, and an ADC or +service-account refresh strategy. Configure the refresh grant on the provider. +Clients must send the token placeholder from their provider environment in an +`Authorization: Bearer` header. If the profile declares no endpoints, bind the +attached provider to each allowed host +in the [sandbox policy](/how-it-works/providers/profiles#understand-static-credential-endpoint-binding). +GCP SDKs that rely on metadata discovery still require the unavailable +`gcp-metadata` adapter. ## Vertex AI @@ -222,21 +68,42 @@ native Vertex endpoint and request format for its selected model. ### Create a Vertex AI Provider -Import the `google-vertex-ai` profile first: +Copy the example profile and set its top-level `binaries` to the absolute paths +of the clients that will call Vertex AI from your sandbox image. The example +declares no binaries, so importing it unchanged does not authorize a client. +For a native Claude Code installation, use the resolved executable path inside +the image; `command -v claude` may return a symlink to a versioned binary. For +an npm or other script installation, use the resolved Node.js interpreter path +instead. OpenShell authorizes the executable and its trusted executable +ancestors, not the script path from the process command line. Include the path +to `curl` if you plan to use the native API example below. ```shell -openshell profile import --url https://raw.githubusercontent.com/NVIDIA/OpenShell/main/providers/google-vertex-ai.yaml --global +curl -fsSLo google-vertex-ai.yaml https://raw.githubusercontent.com/NVIDIA/OpenShell/main/providers/google-vertex-ai.yaml +# Edit google-vertex-ai.yaml and add, for example: +# Native Claude Code: +# binaries: [/usr/bin/curl, /path/to/resolved/claude] +# npm-installed Claude Code: +# binaries: [/usr/bin/curl, /path/to/resolved/node] +openshell profile lint -f google-vertex-ai.yaml +openshell profile import -f google-vertex-ai.yaml --global ``` +For a native installation, find the resolved path with +`readlink -f "$(command -v claude)"`. For an npm installation, find the Node.js +interpreter with `readlink -f "$(command -v node)"`. Run the applicable command +inside the image. + #### Service Account Key -Create the provider with the JSON key as gateway-only bootstrap material: +Create the provider for runtime credentials: ```shell openshell provider create \ --name vertex-prod \ --type google-vertex-ai \ - --credential GOOGLE_SERVICE_ACCOUNT_KEY="$(cat /path/to/key.json)" \ + --global-profile \ + --runtime-credentials \ --config VERTEX_AI_PROJECT_ID=my-gcp-project \ --config VERTEX_AI_REGION=us-central1 ``` @@ -255,6 +122,16 @@ openshell provider refresh configure vertex-prod \ The private key remains in the gateway credential store. Sandboxes receive only an opaque placeholder for the short-lived access token. +The profile's `environment` and `discovery.config_env_vars` declarations supply +SDK configuration and local discovery behavior. A copy imported under another +ID keeps those effects. Do not store `GOOGLE_SERVICE_ACCOUNT_KEY` as a provider +credential or non-secret environment default; supply the private key through +refresh configuration. If an older provider record still holds that key after +the profile declaration is removed, the gateway omits it and continues to +provide the access token and SDK configuration. Two Vertex providers can share +the same non-secret SDK defaults when their values match and their credential +environment keys differ. + #### gcloud Application Default Credentials For local development: @@ -265,6 +142,7 @@ gcloud auth application-default login openshell provider create \ --name vertex-local \ --type google-vertex-ai \ + --global-profile \ --from-gcloud-adc \ --config VERTEX_AI_PROJECT_ID=my-gcp-project \ --config VERTEX_AI_REGION=us-central1 @@ -279,7 +157,7 @@ file and refresh token do not enter the sandbox. | Key | Required | Default | Description | |---|---|---|---| | `VERTEX_AI_PROJECT_ID` | Yes | — | GCP project ID exposed as non-secret workload configuration. | -| `VERTEX_AI_REGION` | No | `us-central1` | Vertex location exposed as non-secret workload configuration. | +| `VERTEX_AI_REGION` | Client dependent | — | Vertex location exposed as non-secret workload configuration. Set it explicitly for regional endpoints. | When the provider is attached, OpenShell also projects standard project and location aliases such as `GOOGLE_CLOUD_PROJECT`, `ANTHROPIC_VERTEX_PROJECT_ID`, @@ -306,6 +184,36 @@ Launch a new process after runtime attachment so it receives the provider environment. Existing processes do not gain newly attached environment variables. +### Run Claude Code with Vertex AI + +Use an image with Claude Code installed. In the imported profile's `binaries`, +include the resolved Claude executable for a native installation or the +resolved Node.js interpreter for an npm installation. After attaching the +provider, start an interactive shell: + +```shell +openshell sandbox connect vertex-agent +``` + +Then start Claude Code inside the sandbox: + +```shell +vertex_token=${GOOGLE_VERTEX_AI_SERVICE_ACCOUNT_TOKEN:-${GOOGLE_VERTEX_AI_TOKEN:-}} +test -n "$vertex_token" || { echo "Vertex token unavailable" >&2; exit 1; } +ANTHROPIC_AUTH_TOKEN="$vertex_token" \ + CLAUDE_CODE_USE_VERTEX=1 \ + CLAUDE_CODE_SKIP_VERTEX_AUTH=1 \ + claude +``` + +Run these commands in the sandbox shell so the token comes from the attached +provider. The project and region variables come from the profile. Claude Code +uses `ANTHROPIC_AUTH_TOKEN` for the bearer Authorization header and +`CLAUDE_CODE_SKIP_VERTEX_AUTH=1` to skip its own Google credential lookup. +OpenShell replaces the token placeholder on authorized Vertex requests. See +[Claude Code's gateway authentication settings](https://docs.anthropic.com/en/docs/claude-code/llm-gateway) +for the client environment variables. + ### Call the Native Vertex API Claude models use Vertex's publisher-model endpoint. Run a request from a new @@ -355,8 +263,13 @@ Common failures: provider profile's endpoint binding. - A Vertex 400 or 404 usually means the model, location, publisher path, or request body does not match the native API. -- A Vertex 401 or 403 can indicate an expired refresh grant or missing GCP IAM - permission. Check `provider refresh status` and the Vertex AI User role. +- A Vertex 401 with `CREDENTIALS_MISSING` means the request reached Google + without a usable Authorization header. For Claude Code, pass the provider + token through `ANTHROPIC_AUTH_TOKEN` as shown above; setting only + `CLAUDE_CODE_SKIP_VERTEX_AUTH=1` leaves the request unauthenticated. +- Other 401 responses can indicate an expired refresh grant. Check + `provider refresh status`. A 403 can indicate missing GCP IAM permission or + model access; check the Vertex AI User role and access to the selected model. Provider creation does not verify model access. The native request is the end-to-end check. diff --git a/docs/how-it-works/providers/profiles.mdx b/docs/how-it-works/providers/profiles.mdx index 11c5438d3c..949014f167 100644 --- a/docs/how-it-works/providers/profiles.mdx +++ b/docs/how-it-works/providers/profiles.mdx @@ -38,7 +38,7 @@ Provider profiles include these user-facing features: - `openshell profile export`, `import`, `update`, `lint`, and `delete` for custom profiles. - Provider instances created from imported profile IDs with `openshell provider create --type `. - Provider instances whose submitted credentials can be stored by a configured gateway credential driver. -- Profile-backed credential discovery for explicit `openshell provider create --from-existing` and `openshell provider update --from-existing` flows. The `google-vertex-ai` profile also supplements discovery with Vertex config env vars such as `VERTEX_AI_PROJECT_ID` and `VERTEX_AI_REGION`. +- Profile-backed discovery for explicit `openshell provider create --from-existing` and `openshell provider update --from-existing` flows. `discovery.credentials` selects credentials, and `discovery.config_env_vars` selects non-secret configuration variables. - Just-in-time effective policy composition from sandbox policy plus attached provider profiles. - Runtime sandbox provider commands under `openshell sandbox provider list|attach|detach|status`, with an option to wait until the sandbox applies a change. - Credential refresh configuration with `openshell provider refresh status|configure|rotate|delete`. @@ -46,6 +46,52 @@ Provider profiles include these user-facing features: - Dynamic token grants that use the sandbox's SPIFFE JWT-SVID as an OAuth2 client assertion and inject short-lived tokens into supported headers for matching profile endpoints. - Endpoint-bound static credential placeholders. The sandbox proxy resolves a static credential only for request hosts, ports, and paths declared by its provider profile or explicitly bound in sandbox policy for an endpointless profile. +## Declare Environment and Discovery Behavior + +The profile ID identifies a definition. Renaming a profile does not activate or +disable SDK configuration. Declare every non-secret environment default in the +profile: + +```yaml +environment: + config: + CUSTOM_PROJECT: CUSTOM_PROJECT + CUSTOM_REGION: CUSTOM_REGION + fixed: + CUSTOM_MODE: native +discovery: + credentials: [api_key] + config_env_vars: [CUSTOM_PROJECT, CUSTOM_REGION] +``` + +`environment.config` maps each destination environment variable to a provider +config key. OpenShell trims the config value and skips missing or blank values. +`environment.fixed` supplies literal values, including an explicitly empty +string. Sandbox template and create-time environment values, including an +explicitly empty value, take precedence over these non-secret defaults. +Provider credential keys remain credential-owned and reach the workload as +opaque placeholders. + +`discovery.config_env_vars` copies nonempty local environment values into +provider config under the same key. Use that key in `environment.config` if the +discovered value should become a workload environment default. Discovery does +not read undeclared keys or infer behavior from the profile ID. + +Profiles allow at most 64 environment defaults and 64 discovery config keys. +Environment names and config keys are limited to 128 bytes; fixed values are +limited to 4096 bytes. Values do not support interpolation or scripts. Lint +rejects invalid environment names, duplicate destinations across `config` and +`fixed`, and collisions with credential `env_vars`. The legacy +`GOOGLE_SERVICE_ACCOUNT_KEY` cannot be a non-secret default. Attachment accepts +the same non-secret destination from multiple providers when their values +match. It rejects differing values and overlapping credential keys. Use +distinct destination names when providers need different values. + +Use `required_platform_adapter` when a profile depends on a named runtime +capability. Lint rejects unknown adapter names. Import, update, and attachment +reject a recognized adapter that the deployment cannot provide, with a bounded +diagnostic. The recognized `gcp-metadata` adapter is currently unavailable. + ## Understand Static Credential Endpoint Binding Static credential endpoint binding prevents a placeholder for one service from @@ -293,12 +339,19 @@ Import one profile file at platform scope: openshell profile import -f providers/github.yaml --global ``` -Import all non-recursive `*.yaml`, `*.yml`, and `*.json` files from a directory: +Import all non-recursive `*.yaml`, `*.yml`, and `*.json` files from a directory +of profiles you reviewed and selected: ```shell -openshell profile import --from ./providers --global +mkdir -p selected-profiles +cp providers/github.yaml providers/openai.yaml selected-profiles/ +openshell profile import --from ./selected-profiles --global ``` +Include only profiles whose platform requirements the deployment supports. +Imports are atomic: a batch containing the Google Cloud metadata example fails +because the `gcp-metadata` adapter is unavailable. + Omit `--global` to import into the current workspace instead. Export a profile as YAML, to edit or to keep before an upgrade: diff --git a/docs/upgrade/0-1-0.mdx b/docs/upgrade/0-1-0.mdx index 7801b48179..6894d2c7bb 100644 --- a/docs/upgrade/0-1-0.mdx +++ b/docs/upgrade/0-1-0.mdx @@ -28,9 +28,32 @@ If you run OpenShell for a team, start here. - **Export provider profiles before upgrading.** The gateway no longer includes built-in profiles. Import the saved profiles after the upgrade at the same global or workspace scope. Replace profile aliases such as `claude` and `gh` with the canonical IDs `claude-code` and `github` ([PR #2962](https://github.com/NVIDIA/OpenShell/pull/2962), [PR #3383](https://github.com/NVIDIA/OpenShell/pull/3383)). + Google Cloud and Vertex profiles must also declare their environment and + discovery effects. Merge `environment.config`, `environment.fixed`, and + `discovery.config_env_vars` from the current examples into existing profiles. + Their IDs no longer activate SDK defaults or discovery keys. Keep credentials + out of these non-secret fields; lint rejects collisions with credential + `env_vars`. For Vertex service accounts, create with `--runtime-credentials` + and configure refresh material directly. Remove the obsolete + `GOOGLE_SERVICE_ACCOUNT_KEY` credential declaration. See + [profile environment declarations](/how-it-works/providers/profiles#declare-environment-and-discovery-behavior). + New imports reject that legacy credential key. Gateways also withhold it + from workloads when an older profile remains stored, but operators should + remove the obsolete declaration and migrate its private key to refresh + material. A stored provider record may retain the old key during the upgrade; + it remains excluded from the workload without withholding the provider's + access token or non-secret SDK settings. The key is also rejected in + `environment.config` and `environment.fixed`. + + The Google Cloud metadata example also declares + `required_platform_adapter: gcp-metadata`. The metadata server was removed in + the runtime split ([PR #2942](https://github.com/NVIDIA/OpenShell/pull/2942)); + current builds reject that requirement during import or attachment. Native + Vertex bearer-token authentication does not require this adapter. + ```shell openshell provider profile export -o yaml --global > .yaml - openshell profile import --from ./profiles --global + openshell profile import -f --global ``` - **Migrate `gateway.toml` to schema version 2.** Add the version, replace the plural compute-driver selector, move driver settings under `[openshell.drivers.]`, and apply the renamed Docker, Podman, and VM fields. Validate the file before restarting. See [Gateway Configuration](/how-it-works/gateways/configuration#migrate-to-schema-version-2) for the complete field mapping and [PR #2814](https://github.com/NVIDIA/OpenShell/pull/2814) for the implementation. diff --git a/e2e/python/test_sandbox_providers.py b/e2e/python/test_sandbox_providers.py index 43badec291..2577a708ef 100644 --- a/e2e/python/test_sandbox_providers.py +++ b/e2e/python/test_sandbox_providers.py @@ -155,6 +155,25 @@ def imported_provider_profile( _delete_provider_profile(stub, profile.id) +def _endpointless_credential_profile(profile_id: str) -> openshell_pb2.ProviderProfile: + """Build an endpointless credential profile without a platform adapter.""" + return openshell_pb2.ProviderProfile( + id=profile_id, + display_name=f"{profile_id} display", + category=openshell_pb2.PROVIDER_PROFILE_CATEGORY_OTHER, + credentials=[ + openshell_pb2.ProviderProfileCredential( + name="api_token", + description="E2E endpointless credential", + env_vars=["E2E_ENDPOINTLESS_TOKEN"], + required=True, + auth_style="bearer", + header_name="authorization", + ) + ], + ) + + def _native_inference_profile( *, profile_id: str, @@ -344,24 +363,33 @@ def test_endpointless_profile_credentials_fail_closed_without_policy_binding( sandbox_client: SandboxClient, ) -> None: """Endpointless profile credentials are withheld without an explicit binding.""" - with provider( - sandbox_client._stub, - name="e2e-test-google-cloud-without-policy-binding", - provider_type="google-cloud", - credentials={"GCP_ADC_ACCESS_TOKEN": "gcp-e2e-token"}, - ) as provider_name: + profile_id = "e2e-endpointless-without-policy-binding" + with ( + imported_provider_profile( + sandbox_client._stub, + profile=_endpointless_credential_profile(profile_id), + source=f"{profile_id}.yaml", + ), + provider( + sandbox_client._stub, + name="e2e-test-endpointless-without-policy-binding", + provider_type=profile_id, + credentials={"E2E_ENDPOINTLESS_TOKEN": "e2e-token"}, + profile_workspace="default", + ) as provider_name, + ): spec = datamodel_pb2.SandboxSpec( policy=_default_policy(), providers=[provider_name], ) - def read_gcp_token() -> str: + def read_token() -> str: import os - return os.environ.get("GCP_ADC_ACCESS_TOKEN", "NOT_SET") + return os.environ.get("E2E_ENDPOINTLESS_TOKEN", "NOT_SET") with sandbox(spec=spec, delete_on_exit=True) as sb: - result = sb.exec_python(read_gcp_token) + result = sb.exec_python(read_token) assert result.exit_code == 0, result.stderr assert result.stdout.strip() == "NOT_SET" @@ -371,19 +399,28 @@ def test_endpointless_profile_credentials_use_explicit_policy_binding( sandbox_client: SandboxClient, ) -> None: """An endpointless profile emits credentials only with an explicit binding.""" - with provider( - sandbox_client._stub, - name="e2e-test-google-cloud-policy-binding", - provider_type="google-cloud", - credentials={"GCP_ADC_ACCESS_TOKEN": "gcp-e2e-token"}, - ) as provider_name: + profile_id = "e2e-endpointless-policy-binding" + with ( + imported_provider_profile( + sandbox_client._stub, + profile=_endpointless_credential_profile(profile_id), + source=f"{profile_id}.yaml", + ), + provider( + sandbox_client._stub, + name="e2e-test-endpointless-policy-binding", + provider_type=profile_id, + credentials={"E2E_ENDPOINTLESS_TOKEN": "e2e-token"}, + profile_workspace="default", + ) as provider_name, + ): policy = _default_policy() - policy.network_policies["gcp_storage"].CopyFrom( + policy.network_policies["endpointless_api"].CopyFrom( sandbox_pb2.NetworkPolicyRule( - name="gcp_storage", + name="endpointless_api", endpoints=[ sandbox_pb2.NetworkEndpoint( - host="storage.googleapis.com", + host="api.example.com", port=443, protocol="rest", access=sandbox_pb2.NETWORK_ACCESS_PRESET_FULL, @@ -399,16 +436,16 @@ def test_endpointless_profile_credentials_use_explicit_policy_binding( providers=[provider_name], ) - def read_gcp_token() -> str: + def read_token() -> str: import os - return os.environ.get("GCP_ADC_ACCESS_TOKEN", "NOT_SET") + return os.environ.get("E2E_ENDPOINTLESS_TOKEN", "NOT_SET") with sandbox(spec=spec, delete_on_exit=True) as sb: - result = sb.exec_python(read_gcp_token) + result = sb.exec_python(read_token) assert result.exit_code == 0, result.stderr assert _is_placeholder_for_env_key( - result.stdout.strip(), "GCP_ADC_ACCESS_TOKEN" + result.stdout.strip(), "E2E_ENDPOINTLESS_TOKEN" ) diff --git a/e2e/rust/tests/provider_refresh_handles.rs b/e2e/rust/tests/provider_refresh_handles.rs index 1de651415d..4204494961 100644 --- a/e2e/rust/tests/provider_refresh_handles.rs +++ b/e2e/rust/tests/provider_refresh_handles.rs @@ -9,6 +9,8 @@ //! retains its original environment while the gateway rotates the provider 12 //! times. The shell must continue reaching the resource with the newest token, //! and explicit refresh reconfiguration must revoke its old handle. +//! Declared non-secret defaults must reach the shell as literal values, while +//! caller environment takes precedence in both main and exec processes. use std::io::Write; use std::process::Stdio; @@ -113,6 +115,13 @@ fn write_profile(resource_port: u16, token_port: u16) -> Result Result<(), String> { PROFILE_ID, "--credential", TOKEN_ENV, + "--config", + "project=custom-profile-project", ], &[(TOKEN_ENV, "bootstrap-token")], ) @@ -301,8 +312,9 @@ async fn long_running_process_survives_rotations_and_reconfigure_revokes() -> Re delete_provider_resources().await; let fixture_port = find_free_port(); let fixture_script = FIXTURE_SCRIPT.replace("__PORT__", &fixture_port.to_string()); - let fixture = - HostSupportContainer::start_python_on_host_network(&fixture_script, fixture_port).await?; + // Publish the fixture for both the native gateway and the supervisor. On + // macOS, Podman's host network is inside its VM, not the gateway's host. + let fixture = HostSupportContainer::start_python(&fixture_script, fixture_port).await?; let profile = write_profile(fixture.port, fixture.port)?; let policy = write_policy(fixture.port)?; configure_refresh(&profile).await?; @@ -314,6 +326,10 @@ async fn long_running_process_survives_rotations_and_reconfigure_revokes() -> Re openshell:resolve:env:s*_REFRESH_E2E_ACCESS_TOKEN) ;; *) exit 64 ;; esac +test "$REFRESH_E2E_PROJECT" = caller-project || exit 65 +test "${{REFRESH_E2E_MODE+x}}" = x && test -z "$REFRESH_E2E_MODE" || exit 66 +test "$REFRESH_E2E_DEFAULT_PROJECT" = custom-profile-project || exit 67 +test "$REFRESH_E2E_DEFAULT_MODE" = native || exit 68 echo {READY_MARKER} while true; do if [ -f /sandbox/probe-trigger ]; then @@ -328,13 +344,36 @@ while true; do done"# ); let mut sandbox = SandboxGuard::create_keep_with_args( - &["--provider", PROVIDER_NAME, "--policy", &policy_path], + &[ + "--provider", + PROVIDER_NAME, + "--policy", + &policy_path, + "--env", + "REFRESH_E2E_PROJECT=caller-project", + "--env", + "REFRESH_E2E_MODE=", + "--env", + "REFRESH_E2E_ACCESS_TOKEN=caller-token", + ], &["sh", "-c", &parent_script], READY_MARKER, ) .await?; let result = async { + sandbox + .exec(&[ + "sh", + "-c", + r#"test "$REFRESH_E2E_PROJECT" = caller-project && +test "${REFRESH_E2E_MODE+x}" = x && test -z "$REFRESH_E2E_MODE" && +test "$REFRESH_E2E_DEFAULT_PROJECT" = custom-profile-project && +test "$REFRESH_E2E_DEFAULT_MODE" = native && +case "$REFRESH_E2E_ACCESS_TOKEN" in openshell:resolve:env:s*_REFRESH_E2E_ACCESS_TOKEN) true;; *) false;; esac"#, + ]) + .await?; + if trigger_probe(&sandbox).await? != "ok" { return Err(format!( "initial long-running credential probe failed; fixture logs:\n{}", diff --git a/e2e/support/gateway-common.sh b/e2e/support/gateway-common.sh index d13d258479..19482818e9 100644 --- a/e2e/support/gateway-common.sh +++ b/e2e/support/gateway-common.sh @@ -237,12 +237,22 @@ EOF e2e_import_example_provider_profiles() { local cli_bin=$1 local root=$2 + local profile adapter echo "Importing example provider profiles from ${root}/providers..." - if ! "${cli_bin}" provider profile import --from "${root}/providers" --global; then - echo "ERROR: failed to import example provider profiles" >&2 - return 1 - fi + for profile in "${root}"/providers/*.yaml; do + adapter="$(yq -r '.required_platform_adapter // ""' "${profile}")" || return 1 + # The standard test runtimes provide no platform adapters. Specialized + # suites must provision the capability before importing a profile needing it. + if [ -n "${adapter}" ]; then + echo "Skipping ${profile}: requires platform adapter ${adapter}" + continue + fi + if ! "${cli_bin}" provider profile import --file "${profile}" --global; then + echo "ERROR: failed to import example provider profile ${profile}" >&2 + return 1 + fi + done } # Register an administrator OIDC session for a gateway, non-interactively. diff --git a/proto/openshell.proto b/proto/openshell.proto index 83ffbe75ad..f9f3e7d369 100644 --- a/proto/openshell.proto +++ b/proto/openshell.proto @@ -2382,6 +2382,17 @@ message ProviderCredentialRefreshStatus { message ProviderProfileDiscovery { // Credential names from ProviderProfile.credentials eligible for local discovery. repeated string credentials = 1; + // Non-secret environment keys copied into provider config under the same key. + repeated string config_env_vars = 2; +} + +// Bounded, non-secret environment defaults. Existing workload values win. +// Values are literal strings; interpolation and scripts are not supported. +message ProviderProfileEnvironment { + // Destination environment key -> provider config key. Blank config is skipped. + map config = 1; + // Destination environment key -> literal non-secret value. + map fixed = 2; } message GetProviderRefreshStatusRequest { @@ -2472,13 +2483,13 @@ message ProviderProfile { repeated openshell.sandbox.v1.NetworkBinary binaries = 7; bool inference_capable = 8; ProviderProfileDiscovery discovery = 9; - // Storage resource version for custom profiles. Built-in profiles and new - // profile files use 0. Gateway responses set this for stored custom profiles. + // Storage resource version. New profile files use 0; gateway responses set + // this for stored profiles. // Update calls use this for optimistic concurrency. uint64 resource_version = 10; // Optional non-secret annotations attached by profile sources or importers. map annotations = 11; - // Server-set provenance: "builtin", "user", or "interceptor/{name}". + // Server-set provenance: "user" or "interceptor/{name}". // Ignored on import/update payloads. string source = 12; // Server-set visibility: "platform", "workspace", or empty for @@ -2487,6 +2498,11 @@ message ProviderProfile { // EXPERIMENTAL: Non-secret files rendered from provider configuration for the // workload. This API and its behavior may change or be removed. repeated ProviderProfileFile files = 14; + // Non-secret environment defaults declared by this profile. + ProviderProfileEnvironment environment = 15; + // Named runtime capability required by this profile. Empty requires none. + // Import and attachment reject requirements unavailable in this deployment. + string required_platform_adapter = 16; } // EXPERIMENTAL: Provider file templates may change or be removed. diff --git a/providers/README.md b/providers/README.md index 9a721af9a8..f5f2b602cb 100644 --- a/providers/README.md +++ b/providers/README.md @@ -16,14 +16,19 @@ openshell provider profile lint -f providers/github.yaml openshell provider profile import -f providers/github.yaml --global ``` -Or import the whole directory: +To import several profiles, put compatible copies in a separate directory: ```shell -openshell provider profile import --from providers --global +openshell provider profile import --from ./selected-profiles --global ``` Drop `--global` to import into the current workspace instead. +The `google-cloud.yaml` example requires the `gcp-metadata` platform adapter, +which current runtimes do not provide. Import rejects a batch containing that +requirement. The Vertex example uses bearer-token authentication and does not +require this adapter. + ## Read the header before importing Every file opens with a comment block naming its expected client binaries, the @@ -48,6 +53,8 @@ workload, and import your copy. injection safe. - Keep `endpoints` limited to the hosts the credential should reach. A credential is only sent to the endpoints its profile declares. +- Review non-secret `environment` defaults, `discovery.config_env_vars`, and + `required_platform_adapter`. Renaming the profile preserves these declarations. - Run `openshell provider profile lint` before importing. See [Provider profiles](https://docs.nvidia.com/openshell/latest/how-it-works/providers/profiles) for the diff --git a/providers/google-cloud.yaml b/providers/google-cloud.yaml index 17fa04fa14..b64eef88c5 100644 --- a/providers/google-cloud.yaml +++ b/providers/google-cloud.yaml @@ -10,10 +10,9 @@ # below, so it has to name the paths in *your* image. # # Client binaries: none declared — this profile grants no egress. -# Reference layout: any image whose GCP SDKs honour the metadata server. The -# sandbox reaches credentials through OpenShell's GCE metadata -# emulator, so gcloud, google-cloud-* libraries and anything -# else using Application Default Credentials work unmodified. +# Reference layout: requires the gcp-metadata platform adapter. The current +# runtime does not provide this service. Import and attachment +# report the unavailable adapter before a workload starts. # Credential scope: a gateway-refreshed GCP access token, as GCP_SA_ACCESS_TOKEN # (service-account JWT flow) or GCP_ADC_ACCESS_TOKEN (gcloud # ADC flow). Configure the refresh material with @@ -31,6 +30,21 @@ display_name: Google Cloud (GCP APIs) description: Native GCP SDK credentials for sandboxes via metadata emulator category: other inference_capable: false +# The metadata server is not available in current runtimes. Import/attachment +# rejects this requirement until a deployment implements the adapter. +required_platform_adapter: gcp-metadata + +environment: + config: + GCP_PROJECT_ID: project_id + GOOGLE_CLOUD_PROJECT: project_id + CLOUD_ML_REGION: region + GCP_LOCATION: region + GCP_SERVICE_ACCOUNT_EMAIL: service_account_email + fixed: + GCE_METADATA_HOST: "127.0.0.1:8174" + GCE_METADATA_IP: "127.0.0.1:8174" + METADATA_SERVER_DETECTION: assume-present credentials: # Service account JWT flow: gateway signs a JWT and exchanges it for an diff --git a/providers/google-vertex-ai.yaml b/providers/google-vertex-ai.yaml index a0994e413e..15d2576169 100644 --- a/providers/google-vertex-ai.yaml +++ b/providers/google-vertex-ai.yaml @@ -18,8 +18,8 @@ # Credential scope: a gateway-refreshed Google access token, as # GOOGLE_VERTEX_AI_SERVICE_ACCOUNT_TOKEN (service-account JWT) # or GOOGLE_VERTEX_AI_TOKEN (gcloud ADC), sent as a bearer -# authorization header. GOOGLE_SERVICE_ACCOUNT_KEY is refresh -# bootstrap material and is never injected into the sandbox. +# authorization header. Supply service account private keys +# through refresh configuration, not provider credentials. # Endpoint access: the aiplatform.googleapis.com regional and replicated hosts, # read-write, L7 enforced. # Smoke test: openshell sandbox create --provider -- \ @@ -31,11 +31,17 @@ display_name: Google Vertex AI description: Google Vertex AI inference provider (Anthropic Claude, Gemini, and third-party models) category: inference inference_capable: true +environment: + config: + GCP_PROJECT_ID: VERTEX_AI_PROJECT_ID + GOOGLE_CLOUD_PROJECT: VERTEX_AI_PROJECT_ID + ANTHROPIC_VERTEX_PROJECT_ID: VERTEX_AI_PROJECT_ID + CLOUD_ML_REGION: VERTEX_AI_REGION + GCP_LOCATION: VERTEX_AI_REGION + VERTEX_LOCATION: VERTEX_AI_REGION + fixed: + GOOSE_PROVIDER: gcp_vertex_ai credentials: - - name: service_account_key - description: Google service account JSON refresh bootstrap material; not injected into sandboxes - env_vars: [GOOGLE_SERVICE_ACCOUNT_KEY] - required: false - name: service_account_token description: Google Cloud access token refreshed from service account JWT material env_vars: [GOOGLE_VERTEX_AI_SERVICE_ACCOUNT_TOKEN, VERTEX_AI_SERVICE_ACCOUNT_TOKEN] @@ -84,6 +90,12 @@ credentials: secret: true discovery: credentials: [service_account_token, gcloud_adc_token] + config_env_vars: + - VERTEX_AI_PROJECT_ID + - VERTEX_AI_REGION + - GOOGLE_VERTEX_AI_BASE_URL + - VERTEX_AI_BASE_URL + - VERTEX_AI_PUBLISHER endpoints: - host: "*-aiplatform.googleapis.com" port: 443 diff --git a/sdk/go/openshell/v1/internal/converter/coverage_test.go b/sdk/go/openshell/v1/internal/converter/coverage_test.go index 43577d61d0..7c82f1051f 100644 --- a/sdk/go/openshell/v1/internal/converter/coverage_test.go +++ b/sdk/go/openshell/v1/internal/converter/coverage_test.go @@ -303,20 +303,22 @@ func TestConverterCoversAllProtoFields_SandboxPolicyRevision(t *testing.T) { func TestConverterCoversAllProtoFields_ProviderProfile(t *testing.T) { handled := fieldSet{ - "id": true, - "display_name": true, - "description": true, - "category": true, - "credentials": true, - "files": true, - "endpoints": true, - "binaries": true, - "inference_capable": true, - "discovery": true, - "resource_version": true, - "annotations": true, - "source": true, - "scope": true, + "id": true, + "display_name": true, + "description": true, + "category": true, + "credentials": true, + "files": true, + "endpoints": true, + "binaries": true, + "inference_capable": true, + "discovery": true, + "resource_version": true, + "annotations": true, + "source": true, + "scope": true, + "environment": true, + "required_platform_adapter": true, } assertAllFieldsCovered(t, (&pb.ProviderProfile{}).ProtoReflect().Descriptor(), handled, nil) diff --git a/sdk/go/openshell/v1/internal/converter/profile.go b/sdk/go/openshell/v1/internal/converter/profile.go index 9ef58e8057..212d588877 100644 --- a/sdk/go/openshell/v1/internal/converter/profile.go +++ b/sdk/go/openshell/v1/internal/converter/profile.go @@ -342,15 +342,16 @@ func ProviderProfileFromProto(p *pb.ProviderProfile) *types.ProviderProfile { } result := &types.ProviderProfile{ - ID: p.GetId(), - DisplayName: p.GetDisplayName(), - Description: p.GetDescription(), - Category: ProfileCategoryFromProto(p.GetCategory()), - InferenceCapable: p.GetInferenceCapable(), - ResourceVersion: p.GetResourceVersion(), - Annotations: CopyStringMap(p.GetAnnotations()), - Source: p.GetSource(), - Scope: p.GetScope(), + ID: p.GetId(), + DisplayName: p.GetDisplayName(), + Description: p.GetDescription(), + Category: ProfileCategoryFromProto(p.GetCategory()), + InferenceCapable: p.GetInferenceCapable(), + ResourceVersion: p.GetResourceVersion(), + Annotations: CopyStringMap(p.GetAnnotations()), + Source: p.GetSource(), + Scope: p.GetScope(), + RequiredPlatformAdapter: p.GetRequiredPlatformAdapter(), } // Credentials @@ -398,7 +399,14 @@ func ProviderProfileFromProto(p *pb.ProviderProfile) *types.ProviderProfile { // Discovery if d := p.GetDiscovery(); d != nil { result.Discovery = types.ProfileDiscovery{ - Credentials: CopyStringSlice(d.GetCredentials()), + Credentials: CopyStringSlice(d.GetCredentials()), + ConfigEnvVars: CopyStringSlice(d.GetConfigEnvVars()), + } + } + if e := p.GetEnvironment(); e != nil { + result.Environment = &types.ProfileEnvironment{ + Config: CopyStringMap(e.GetConfig()), + Fixed: CopyStringMap(e.GetFixed()), } } @@ -412,15 +420,16 @@ func ProviderProfileToProto(p *types.ProviderProfile) *pb.ProviderProfile { } result := &pb.ProviderProfile{ - Id: p.ID, - DisplayName: p.DisplayName, - Description: p.Description, - Category: ProfileCategoryToProto(p.Category), - InferenceCapable: p.InferenceCapable, - ResourceVersion: p.ResourceVersion, - Annotations: CopyStringMap(p.Annotations), - Source: p.Source, - Scope: p.Scope, + Id: p.ID, + DisplayName: p.DisplayName, + Description: p.Description, + Category: ProfileCategoryToProto(p.Category), + InferenceCapable: p.InferenceCapable, + ResourceVersion: p.ResourceVersion, + Annotations: CopyStringMap(p.Annotations), + Source: p.Source, + Scope: p.Scope, + RequiredPlatformAdapter: p.RequiredPlatformAdapter, } // Credentials @@ -458,9 +467,16 @@ func ProviderProfileToProto(p *types.ProviderProfile) *pb.ProviderProfile { } // Discovery - if len(p.Discovery.Credentials) > 0 { + if len(p.Discovery.Credentials) > 0 || len(p.Discovery.ConfigEnvVars) > 0 { result.Discovery = &pb.ProviderProfileDiscovery{ - Credentials: CopyStringSlice(p.Discovery.Credentials), + Credentials: CopyStringSlice(p.Discovery.Credentials), + ConfigEnvVars: CopyStringSlice(p.Discovery.ConfigEnvVars), + } + } + if p.Environment != nil { + result.Environment = &pb.ProviderProfileEnvironment{ + Config: CopyStringMap(p.Environment.Config), + Fixed: CopyStringMap(p.Environment.Fixed), } } diff --git a/sdk/go/openshell/v1/internal/converter/profile_test.go b/sdk/go/openshell/v1/internal/converter/profile_test.go index e1aaf0af75..852874133c 100644 --- a/sdk/go/openshell/v1/internal/converter/profile_test.go +++ b/sdk/go/openshell/v1/internal/converter/profile_test.go @@ -461,6 +461,35 @@ func TestProfileDiagnosticFromProto_Nil(t *testing.T) { // --- ProviderProfile --- +func TestProviderProfileEnvironmentRoundTripAndCopies(t *testing.T) { + profile := &v1.ProviderProfile{ + ID: "custom", + RequiredPlatformAdapter: "gcp-metadata", + Environment: &v1.ProfileEnvironment{ + Config: map[string]string{"CUSTOM_PROJECT": "project"}, + Fixed: map[string]string{"CUSTOM_MODE": "native"}, + }, + Discovery: v1.ProfileDiscovery{ConfigEnvVars: []string{"CUSTOM_PROJECT"}}, + } + wire := ProviderProfileToProto(profile) + restored := ProviderProfileFromProto(wire) + assert.Equal(t, profile.Environment, restored.Environment) + assert.Equal(t, profile.Discovery, restored.Discovery) + assert.Equal(t, profile.RequiredPlatformAdapter, restored.RequiredPlatformAdapter) + profile.Environment.Config["CUSTOM_PROJECT"] = "changed-source" + profile.Environment.Fixed["CUSTOM_MODE"] = "changed-source" + profile.Discovery.ConfigEnvVars[0] = "CHANGED_SOURCE" + assert.Equal(t, "project", wire.Environment.Config["CUSTOM_PROJECT"]) + assert.Equal(t, "native", wire.Environment.Fixed["CUSTOM_MODE"]) + assert.Equal(t, "CUSTOM_PROJECT", wire.Discovery.ConfigEnvVars[0]) + wire.Environment.Config["CUSTOM_PROJECT"] = "changed-wire" + wire.Environment.Fixed["CUSTOM_MODE"] = "changed-wire" + wire.Discovery.ConfigEnvVars[0] = "CHANGED_WIRE" + assert.Equal(t, "project", restored.Environment.Config["CUSTOM_PROJECT"]) + assert.Equal(t, "native", restored.Environment.Fixed["CUSTOM_MODE"]) + assert.Equal(t, "CUSTOM_PROJECT", restored.Discovery.ConfigEnvVars[0]) +} + func TestProviderProfileFromProto(t *testing.T) { proto := &pb.ProviderProfile{ Id: "prof-1", diff --git a/sdk/go/openshell/v1/profile.go b/sdk/go/openshell/v1/profile.go index 7de1951e4f..6fec20a05c 100644 --- a/sdk/go/openshell/v1/profile.go +++ b/sdk/go/openshell/v1/profile.go @@ -27,6 +27,9 @@ type NetworkBinary = types.NetworkBinary // ProfileDiscovery holds local discovery configuration for a profile. type ProfileDiscovery = types.ProfileDiscovery +// ProfileEnvironment declares non-secret workload environment defaults. +type ProfileEnvironment = types.ProfileEnvironment + // ProfileImportItem is an item submitted for profile import or lint validation. type ProfileImportItem = types.ProfileImportItem diff --git a/sdk/go/openshell/v1/types/profile.go b/sdk/go/openshell/v1/types/profile.go index fdffd2bfe6..53296511c1 100644 --- a/sdk/go/openshell/v1/types/profile.go +++ b/sdk/go/openshell/v1/types/profile.go @@ -26,15 +26,25 @@ type ProviderProfile struct { Category ProfileCategory Credentials []ProfileCredential // Files is EXPERIMENTAL. This API and its behavior may change or be removed. - Files []ProfileFile - Endpoints []NetworkEndpoint - Binaries []NetworkBinary - InferenceCapable bool - Discovery ProfileDiscovery - ResourceVersion uint64 - Annotations map[string]string - Source string - Scope string + Files []ProfileFile + Endpoints []NetworkEndpoint + Binaries []NetworkBinary + InferenceCapable bool + Discovery ProfileDiscovery + ResourceVersion uint64 + Annotations map[string]string + Source string + Scope string + Environment *ProfileEnvironment + RequiredPlatformAdapter string +} + +// ProfileEnvironment declares non-secret workload environment defaults. +type ProfileEnvironment struct { + // Config maps destination environment keys to provider config keys. + Config map[string]string + // Fixed maps destination environment keys to literal values. + Fixed map[string]string } // ProfileFile declares non-secret content served at a virtual sandbox path. @@ -149,7 +159,8 @@ type NetworkBinary struct { // ProfileDiscovery holds local discovery configuration for a profile. type ProfileDiscovery struct { - Credentials []string + Credentials []string + ConfigEnvVars []string } // ProfileImportItem is an item submitted for profile import or lint validation. diff --git a/sdk/go/proto/openshellv1/openshell.pb.go b/sdk/go/proto/openshellv1/openshell.pb.go index 109d2ef454..f3a36d80dc 100644 --- a/sdk/go/proto/openshellv1/openshell.pb.go +++ b/sdk/go/proto/openshellv1/openshell.pb.go @@ -9580,7 +9580,9 @@ func (x *ProviderCredentialRefreshStatus) GetLastErrorTime() *timestamppb.Timest type ProviderProfileDiscovery struct { state protoimpl.MessageState `protogen:"open.v1"` // Credential names from ProviderProfile.credentials eligible for local discovery. - Credentials []string `protobuf:"bytes,1,rep,name=credentials,proto3" json:"credentials,omitempty"` + Credentials []string `protobuf:"bytes,1,rep,name=credentials,proto3" json:"credentials,omitempty"` + // Non-secret environment keys copied into provider config under the same key. + ConfigEnvVars []string `protobuf:"bytes,2,rep,name=config_env_vars,json=configEnvVars,proto3" json:"config_env_vars,omitempty"` unknownFields protoimpl.UnknownFields sizeCache protoimpl.SizeCache } @@ -9622,6 +9624,69 @@ func (x *ProviderProfileDiscovery) GetCredentials() []string { return nil } +func (x *ProviderProfileDiscovery) GetConfigEnvVars() []string { + if x != nil { + return x.ConfigEnvVars + } + return nil +} + +// Bounded, non-secret environment defaults. Existing workload values win. +// Values are literal strings; interpolation and scripts are not supported. +type ProviderProfileEnvironment struct { + state protoimpl.MessageState `protogen:"open.v1"` + // Destination environment key -> provider config key. Blank config is skipped. + Config map[string]string `protobuf:"bytes,1,rep,name=config,proto3" json:"config,omitempty" protobuf_key:"bytes,1,opt,name=key" protobuf_val:"bytes,2,opt,name=value"` + // Destination environment key -> literal non-secret value. + Fixed map[string]string `protobuf:"bytes,2,rep,name=fixed,proto3" json:"fixed,omitempty" protobuf_key:"bytes,1,opt,name=key" protobuf_val:"bytes,2,opt,name=value"` + unknownFields protoimpl.UnknownFields + sizeCache protoimpl.SizeCache +} + +func (x *ProviderProfileEnvironment) Reset() { + *x = ProviderProfileEnvironment{} + mi := &file_openshell_proto_msgTypes[113] + ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) + ms.StoreMessageInfo(mi) +} + +func (x *ProviderProfileEnvironment) String() string { + return protoimpl.X.MessageStringOf(x) +} + +func (*ProviderProfileEnvironment) ProtoMessage() {} + +func (x *ProviderProfileEnvironment) ProtoReflect() protoreflect.Message { + mi := &file_openshell_proto_msgTypes[113] + if x != nil { + ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) + if ms.LoadMessageInfo() == nil { + ms.StoreMessageInfo(mi) + } + return ms + } + return mi.MessageOf(x) +} + +// Deprecated: Use ProviderProfileEnvironment.ProtoReflect.Descriptor instead. +func (*ProviderProfileEnvironment) Descriptor() ([]byte, []int) { + return file_openshell_proto_rawDescGZIP(), []int{113} +} + +func (x *ProviderProfileEnvironment) GetConfig() map[string]string { + if x != nil { + return x.Config + } + return nil +} + +func (x *ProviderProfileEnvironment) GetFixed() map[string]string { + if x != nil { + return x.Fixed + } + return nil +} + type GetProviderRefreshStatusRequest struct { state protoimpl.MessageState `protogen:"open.v1"` // Workspace scope. Only a named workspace selection is accepted. @@ -9634,7 +9699,7 @@ type GetProviderRefreshStatusRequest struct { func (x *GetProviderRefreshStatusRequest) Reset() { *x = GetProviderRefreshStatusRequest{} - mi := &file_openshell_proto_msgTypes[113] + mi := &file_openshell_proto_msgTypes[114] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -9646,7 +9711,7 @@ func (x *GetProviderRefreshStatusRequest) String() string { func (*GetProviderRefreshStatusRequest) ProtoMessage() {} func (x *GetProviderRefreshStatusRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[113] + mi := &file_openshell_proto_msgTypes[114] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -9659,7 +9724,7 @@ func (x *GetProviderRefreshStatusRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use GetProviderRefreshStatusRequest.ProtoReflect.Descriptor instead. func (*GetProviderRefreshStatusRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{113} + return file_openshell_proto_rawDescGZIP(), []int{114} } func (x *GetProviderRefreshStatusRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -9692,7 +9757,7 @@ type GetProviderRefreshStatusResponse struct { func (x *GetProviderRefreshStatusResponse) Reset() { *x = GetProviderRefreshStatusResponse{} - mi := &file_openshell_proto_msgTypes[114] + mi := &file_openshell_proto_msgTypes[115] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -9704,7 +9769,7 @@ func (x *GetProviderRefreshStatusResponse) String() string { func (*GetProviderRefreshStatusResponse) ProtoMessage() {} func (x *GetProviderRefreshStatusResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[114] + mi := &file_openshell_proto_msgTypes[115] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -9717,7 +9782,7 @@ func (x *GetProviderRefreshStatusResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use GetProviderRefreshStatusResponse.ProtoReflect.Descriptor instead. func (*GetProviderRefreshStatusResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{114} + return file_openshell_proto_rawDescGZIP(), []int{115} } func (x *GetProviderRefreshStatusResponse) GetCredentials() []*ProviderCredentialRefreshStatus { @@ -9749,7 +9814,7 @@ type ConfigureProviderRefreshRequest struct { func (x *ConfigureProviderRefreshRequest) Reset() { *x = ConfigureProviderRefreshRequest{} - mi := &file_openshell_proto_msgTypes[115] + mi := &file_openshell_proto_msgTypes[116] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -9761,7 +9826,7 @@ func (x *ConfigureProviderRefreshRequest) String() string { func (*ConfigureProviderRefreshRequest) ProtoMessage() {} func (x *ConfigureProviderRefreshRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[115] + mi := &file_openshell_proto_msgTypes[116] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -9774,7 +9839,7 @@ func (x *ConfigureProviderRefreshRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use ConfigureProviderRefreshRequest.ProtoReflect.Descriptor instead. func (*ConfigureProviderRefreshRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{115} + return file_openshell_proto_rawDescGZIP(), []int{116} } func (x *ConfigureProviderRefreshRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -9842,7 +9907,7 @@ type ConfigureProviderRefreshResponse struct { func (x *ConfigureProviderRefreshResponse) Reset() { *x = ConfigureProviderRefreshResponse{} - mi := &file_openshell_proto_msgTypes[116] + mi := &file_openshell_proto_msgTypes[117] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -9854,7 +9919,7 @@ func (x *ConfigureProviderRefreshResponse) String() string { func (*ConfigureProviderRefreshResponse) ProtoMessage() {} func (x *ConfigureProviderRefreshResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[116] + mi := &file_openshell_proto_msgTypes[117] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -9867,7 +9932,7 @@ func (x *ConfigureProviderRefreshResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use ConfigureProviderRefreshResponse.ProtoReflect.Descriptor instead. func (*ConfigureProviderRefreshResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{116} + return file_openshell_proto_rawDescGZIP(), []int{117} } func (x *ConfigureProviderRefreshResponse) GetStatus() *ProviderCredentialRefreshStatus { @@ -9892,7 +9957,7 @@ type RotateProviderCredentialRequest struct { func (x *RotateProviderCredentialRequest) Reset() { *x = RotateProviderCredentialRequest{} - mi := &file_openshell_proto_msgTypes[117] + mi := &file_openshell_proto_msgTypes[118] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -9904,7 +9969,7 @@ func (x *RotateProviderCredentialRequest) String() string { func (*RotateProviderCredentialRequest) ProtoMessage() {} func (x *RotateProviderCredentialRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[117] + mi := &file_openshell_proto_msgTypes[118] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -9917,7 +9982,7 @@ func (x *RotateProviderCredentialRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use RotateProviderCredentialRequest.ProtoReflect.Descriptor instead. func (*RotateProviderCredentialRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{117} + return file_openshell_proto_rawDescGZIP(), []int{118} } func (x *RotateProviderCredentialRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -9957,7 +10022,7 @@ type RotateProviderCredentialResponse struct { func (x *RotateProviderCredentialResponse) Reset() { *x = RotateProviderCredentialResponse{} - mi := &file_openshell_proto_msgTypes[118] + mi := &file_openshell_proto_msgTypes[119] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -9969,7 +10034,7 @@ func (x *RotateProviderCredentialResponse) String() string { func (*RotateProviderCredentialResponse) ProtoMessage() {} func (x *RotateProviderCredentialResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[118] + mi := &file_openshell_proto_msgTypes[119] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -9982,7 +10047,7 @@ func (x *RotateProviderCredentialResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use RotateProviderCredentialResponse.ProtoReflect.Descriptor instead. func (*RotateProviderCredentialResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{118} + return file_openshell_proto_rawDescGZIP(), []int{119} } func (x *RotateProviderCredentialResponse) GetStatus() *ProviderCredentialRefreshStatus { @@ -10008,7 +10073,7 @@ type DeleteProviderRefreshRequest struct { func (x *DeleteProviderRefreshRequest) Reset() { *x = DeleteProviderRefreshRequest{} - mi := &file_openshell_proto_msgTypes[119] + mi := &file_openshell_proto_msgTypes[120] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -10020,7 +10085,7 @@ func (x *DeleteProviderRefreshRequest) String() string { func (*DeleteProviderRefreshRequest) ProtoMessage() {} func (x *DeleteProviderRefreshRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[119] + mi := &file_openshell_proto_msgTypes[120] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -10033,7 +10098,7 @@ func (x *DeleteProviderRefreshRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use DeleteProviderRefreshRequest.ProtoReflect.Descriptor instead. func (*DeleteProviderRefreshRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{119} + return file_openshell_proto_rawDescGZIP(), []int{120} } func (x *DeleteProviderRefreshRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -10080,7 +10145,7 @@ type DeleteProviderRefreshResponse struct { func (x *DeleteProviderRefreshResponse) Reset() { *x = DeleteProviderRefreshResponse{} - mi := &file_openshell_proto_msgTypes[120] + mi := &file_openshell_proto_msgTypes[121] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -10092,7 +10157,7 @@ func (x *DeleteProviderRefreshResponse) String() string { func (*DeleteProviderRefreshResponse) ProtoMessage() {} func (x *DeleteProviderRefreshResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[120] + mi := &file_openshell_proto_msgTypes[121] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -10105,7 +10170,7 @@ func (x *DeleteProviderRefreshResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use DeleteProviderRefreshResponse.ProtoReflect.Descriptor instead. func (*DeleteProviderRefreshResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{120} + return file_openshell_proto_rawDescGZIP(), []int{121} } func (x *DeleteProviderRefreshResponse) GetOutcome() DeletionOutcome { @@ -10127,13 +10192,13 @@ type ProviderProfile struct { Binaries []*sandboxv1.NetworkBinary `protobuf:"bytes,7,rep,name=binaries,proto3" json:"binaries,omitempty"` InferenceCapable bool `protobuf:"varint,8,opt,name=inference_capable,json=inferenceCapable,proto3" json:"inference_capable,omitempty"` Discovery *ProviderProfileDiscovery `protobuf:"bytes,9,opt,name=discovery,proto3" json:"discovery,omitempty"` - // Storage resource version for custom profiles. Built-in profiles and new - // profile files use 0. Gateway responses set this for stored custom profiles. + // Storage resource version. New profile files use 0; gateway responses set + // this for stored profiles. // Update calls use this for optimistic concurrency. ResourceVersion uint64 `protobuf:"varint,10,opt,name=resource_version,json=resourceVersion,proto3" json:"resource_version,omitempty"` // Optional non-secret annotations attached by profile sources or importers. Annotations map[string]string `protobuf:"bytes,11,rep,name=annotations,proto3" json:"annotations,omitempty" protobuf_key:"bytes,1,opt,name=key" protobuf_val:"bytes,2,opt,name=value"` - // Server-set provenance: "builtin", "user", or "interceptor/{name}". + // Server-set provenance: "user" or "interceptor/{name}". // Ignored on import/update payloads. Source string `protobuf:"bytes,12,opt,name=source,proto3" json:"source,omitempty"` // Server-set visibility: "platform", "workspace", or empty for @@ -10141,14 +10206,19 @@ type ProviderProfile struct { Scope string `protobuf:"bytes,13,opt,name=scope,proto3" json:"scope,omitempty"` // EXPERIMENTAL: Non-secret files rendered from provider configuration for the // workload. This API and its behavior may change or be removed. - Files []*ProviderProfileFile `protobuf:"bytes,14,rep,name=files,proto3" json:"files,omitempty"` - unknownFields protoimpl.UnknownFields - sizeCache protoimpl.SizeCache + Files []*ProviderProfileFile `protobuf:"bytes,14,rep,name=files,proto3" json:"files,omitempty"` + // Non-secret environment defaults declared by this profile. + Environment *ProviderProfileEnvironment `protobuf:"bytes,15,opt,name=environment,proto3" json:"environment,omitempty"` + // Named runtime capability required by this profile. Empty requires none. + // Import and attachment reject requirements unavailable in this deployment. + RequiredPlatformAdapter string `protobuf:"bytes,16,opt,name=required_platform_adapter,json=requiredPlatformAdapter,proto3" json:"required_platform_adapter,omitempty"` + unknownFields protoimpl.UnknownFields + sizeCache protoimpl.SizeCache } func (x *ProviderProfile) Reset() { *x = ProviderProfile{} - mi := &file_openshell_proto_msgTypes[121] + mi := &file_openshell_proto_msgTypes[122] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -10160,7 +10230,7 @@ func (x *ProviderProfile) String() string { func (*ProviderProfile) ProtoMessage() {} func (x *ProviderProfile) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[121] + mi := &file_openshell_proto_msgTypes[122] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -10173,7 +10243,7 @@ func (x *ProviderProfile) ProtoReflect() protoreflect.Message { // Deprecated: Use ProviderProfile.ProtoReflect.Descriptor instead. func (*ProviderProfile) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{121} + return file_openshell_proto_rawDescGZIP(), []int{122} } func (x *ProviderProfile) GetId() string { @@ -10274,6 +10344,20 @@ func (x *ProviderProfile) GetFiles() []*ProviderProfileFile { return nil } +func (x *ProviderProfile) GetEnvironment() *ProviderProfileEnvironment { + if x != nil { + return x.Environment + } + return nil +} + +func (x *ProviderProfile) GetRequiredPlatformAdapter() string { + if x != nil { + return x.RequiredPlatformAdapter + } + return "" +} + // EXPERIMENTAL: Provider file templates may change or be removed. type ProviderProfileFile struct { state protoimpl.MessageState `protogen:"open.v1"` @@ -10289,7 +10373,7 @@ type ProviderProfileFile struct { func (x *ProviderProfileFile) Reset() { *x = ProviderProfileFile{} - mi := &file_openshell_proto_msgTypes[122] + mi := &file_openshell_proto_msgTypes[123] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -10301,7 +10385,7 @@ func (x *ProviderProfileFile) String() string { func (*ProviderProfileFile) ProtoMessage() {} func (x *ProviderProfileFile) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[122] + mi := &file_openshell_proto_msgTypes[123] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -10314,7 +10398,7 @@ func (x *ProviderProfileFile) ProtoReflect() protoreflect.Message { // Deprecated: Use ProviderProfileFile.ProtoReflect.Descriptor instead. func (*ProviderProfileFile) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{122} + return file_openshell_proto_rawDescGZIP(), []int{123} } func (x *ProviderProfileFile) GetPath() string { @@ -10348,7 +10432,7 @@ type ProviderProfileResponse struct { func (x *ProviderProfileResponse) Reset() { *x = ProviderProfileResponse{} - mi := &file_openshell_proto_msgTypes[123] + mi := &file_openshell_proto_msgTypes[124] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -10360,7 +10444,7 @@ func (x *ProviderProfileResponse) String() string { func (*ProviderProfileResponse) ProtoMessage() {} func (x *ProviderProfileResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[123] + mi := &file_openshell_proto_msgTypes[124] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -10373,7 +10457,7 @@ func (x *ProviderProfileResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use ProviderProfileResponse.ProtoReflect.Descriptor instead. func (*ProviderProfileResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{123} + return file_openshell_proto_rawDescGZIP(), []int{124} } func (x *ProviderProfileResponse) GetProfile() *ProviderProfile { @@ -10395,7 +10479,7 @@ type ListProviderProfilesResponse struct { func (x *ListProviderProfilesResponse) Reset() { *x = ListProviderProfilesResponse{} - mi := &file_openshell_proto_msgTypes[124] + mi := &file_openshell_proto_msgTypes[125] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -10407,7 +10491,7 @@ func (x *ListProviderProfilesResponse) String() string { func (*ListProviderProfilesResponse) ProtoMessage() {} func (x *ListProviderProfilesResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[124] + mi := &file_openshell_proto_msgTypes[125] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -10420,7 +10504,7 @@ func (x *ListProviderProfilesResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use ListProviderProfilesResponse.ProtoReflect.Descriptor instead. func (*ListProviderProfilesResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{124} + return file_openshell_proto_rawDescGZIP(), []int{125} } func (x *ListProviderProfilesResponse) GetProfiles() []*ProviderProfile { @@ -10452,7 +10536,7 @@ type ImportProviderProfilesRequest struct { func (x *ImportProviderProfilesRequest) Reset() { *x = ImportProviderProfilesRequest{} - mi := &file_openshell_proto_msgTypes[125] + mi := &file_openshell_proto_msgTypes[126] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -10464,7 +10548,7 @@ func (x *ImportProviderProfilesRequest) String() string { func (*ImportProviderProfilesRequest) ProtoMessage() {} func (x *ImportProviderProfilesRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[125] + mi := &file_openshell_proto_msgTypes[126] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -10477,7 +10561,7 @@ func (x *ImportProviderProfilesRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use ImportProviderProfilesRequest.ProtoReflect.Descriptor instead. func (*ImportProviderProfilesRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{125} + return file_openshell_proto_rawDescGZIP(), []int{126} } func (x *ImportProviderProfilesRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -10513,7 +10597,7 @@ type ImportProviderProfilesResponse struct { func (x *ImportProviderProfilesResponse) Reset() { *x = ImportProviderProfilesResponse{} - mi := &file_openshell_proto_msgTypes[126] + mi := &file_openshell_proto_msgTypes[127] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -10525,7 +10609,7 @@ func (x *ImportProviderProfilesResponse) String() string { func (*ImportProviderProfilesResponse) ProtoMessage() {} func (x *ImportProviderProfilesResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[126] + mi := &file_openshell_proto_msgTypes[127] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -10538,7 +10622,7 @@ func (x *ImportProviderProfilesResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use ImportProviderProfilesResponse.ProtoReflect.Descriptor instead. func (*ImportProviderProfilesResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{126} + return file_openshell_proto_rawDescGZIP(), []int{127} } func (x *ImportProviderProfilesResponse) GetDiagnostics() []*ProviderProfileDiagnostic { @@ -10584,7 +10668,7 @@ type UpdateProviderProfilesRequest struct { func (x *UpdateProviderProfilesRequest) Reset() { *x = UpdateProviderProfilesRequest{} - mi := &file_openshell_proto_msgTypes[127] + mi := &file_openshell_proto_msgTypes[128] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -10596,7 +10680,7 @@ func (x *UpdateProviderProfilesRequest) String() string { func (*UpdateProviderProfilesRequest) ProtoMessage() {} func (x *UpdateProviderProfilesRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[127] + mi := &file_openshell_proto_msgTypes[128] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -10609,7 +10693,7 @@ func (x *UpdateProviderProfilesRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use UpdateProviderProfilesRequest.ProtoReflect.Descriptor instead. func (*UpdateProviderProfilesRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{127} + return file_openshell_proto_rawDescGZIP(), []int{128} } func (x *UpdateProviderProfilesRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -10659,7 +10743,7 @@ type UpdateProviderProfilesResponse struct { func (x *UpdateProviderProfilesResponse) Reset() { *x = UpdateProviderProfilesResponse{} - mi := &file_openshell_proto_msgTypes[128] + mi := &file_openshell_proto_msgTypes[129] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -10671,7 +10755,7 @@ func (x *UpdateProviderProfilesResponse) String() string { func (*UpdateProviderProfilesResponse) ProtoMessage() {} func (x *UpdateProviderProfilesResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[128] + mi := &file_openshell_proto_msgTypes[129] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -10684,7 +10768,7 @@ func (x *UpdateProviderProfilesResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use UpdateProviderProfilesResponse.ProtoReflect.Descriptor instead. func (*UpdateProviderProfilesResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{128} + return file_openshell_proto_rawDescGZIP(), []int{129} } func (x *UpdateProviderProfilesResponse) GetDiagnostics() []*ProviderProfileDiagnostic { @@ -10720,7 +10804,7 @@ type LintProviderProfilesRequest struct { func (x *LintProviderProfilesRequest) Reset() { *x = LintProviderProfilesRequest{} - mi := &file_openshell_proto_msgTypes[129] + mi := &file_openshell_proto_msgTypes[130] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -10732,7 +10816,7 @@ func (x *LintProviderProfilesRequest) String() string { func (*LintProviderProfilesRequest) ProtoMessage() {} func (x *LintProviderProfilesRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[129] + mi := &file_openshell_proto_msgTypes[130] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -10745,7 +10829,7 @@ func (x *LintProviderProfilesRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use LintProviderProfilesRequest.ProtoReflect.Descriptor instead. func (*LintProviderProfilesRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{129} + return file_openshell_proto_rawDescGZIP(), []int{130} } func (x *LintProviderProfilesRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -10773,7 +10857,7 @@ type LintProviderProfilesResponse struct { func (x *LintProviderProfilesResponse) Reset() { *x = LintProviderProfilesResponse{} - mi := &file_openshell_proto_msgTypes[130] + mi := &file_openshell_proto_msgTypes[131] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -10785,7 +10869,7 @@ func (x *LintProviderProfilesResponse) String() string { func (*LintProviderProfilesResponse) ProtoMessage() {} func (x *LintProviderProfilesResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[130] + mi := &file_openshell_proto_msgTypes[131] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -10798,7 +10882,7 @@ func (x *LintProviderProfilesResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use LintProviderProfilesResponse.ProtoReflect.Descriptor instead. func (*LintProviderProfilesResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{130} + return file_openshell_proto_rawDescGZIP(), []int{131} } func (x *LintProviderProfilesResponse) GetDiagnostics() []*ProviderProfileDiagnostic { @@ -10825,7 +10909,7 @@ type DeleteProviderResponse struct { func (x *DeleteProviderResponse) Reset() { *x = DeleteProviderResponse{} - mi := &file_openshell_proto_msgTypes[131] + mi := &file_openshell_proto_msgTypes[132] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -10837,7 +10921,7 @@ func (x *DeleteProviderResponse) String() string { func (*DeleteProviderResponse) ProtoMessage() {} func (x *DeleteProviderResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[131] + mi := &file_openshell_proto_msgTypes[132] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -10850,7 +10934,7 @@ func (x *DeleteProviderResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use DeleteProviderResponse.ProtoReflect.Descriptor instead. func (*DeleteProviderResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{131} + return file_openshell_proto_rawDescGZIP(), []int{132} } func (x *DeleteProviderResponse) GetOutcome() DeletionOutcome { @@ -10876,7 +10960,7 @@ type DeleteProviderProfileRequest struct { func (x *DeleteProviderProfileRequest) Reset() { *x = DeleteProviderProfileRequest{} - mi := &file_openshell_proto_msgTypes[132] + mi := &file_openshell_proto_msgTypes[133] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -10888,7 +10972,7 @@ func (x *DeleteProviderProfileRequest) String() string { func (*DeleteProviderProfileRequest) ProtoMessage() {} func (x *DeleteProviderProfileRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[132] + mi := &file_openshell_proto_msgTypes[133] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -10901,7 +10985,7 @@ func (x *DeleteProviderProfileRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use DeleteProviderProfileRequest.ProtoReflect.Descriptor instead. func (*DeleteProviderProfileRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{132} + return file_openshell_proto_rawDescGZIP(), []int{133} } func (x *DeleteProviderProfileRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -10942,7 +11026,7 @@ type DeleteProviderProfileResponse struct { func (x *DeleteProviderProfileResponse) Reset() { *x = DeleteProviderProfileResponse{} - mi := &file_openshell_proto_msgTypes[133] + mi := &file_openshell_proto_msgTypes[134] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -10954,7 +11038,7 @@ func (x *DeleteProviderProfileResponse) String() string { func (*DeleteProviderProfileResponse) ProtoMessage() {} func (x *DeleteProviderProfileResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[133] + mi := &file_openshell_proto_msgTypes[134] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -10967,7 +11051,7 @@ func (x *DeleteProviderProfileResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use DeleteProviderProfileResponse.ProtoReflect.Descriptor instead. func (*DeleteProviderProfileResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{133} + return file_openshell_proto_rawDescGZIP(), []int{134} } func (x *DeleteProviderProfileResponse) GetOutcome() DeletionOutcome { @@ -10992,7 +11076,7 @@ type GetSandboxProviderEnvironmentRequest struct { func (x *GetSandboxProviderEnvironmentRequest) Reset() { *x = GetSandboxProviderEnvironmentRequest{} - mi := &file_openshell_proto_msgTypes[134] + mi := &file_openshell_proto_msgTypes[135] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -11004,7 +11088,7 @@ func (x *GetSandboxProviderEnvironmentRequest) String() string { func (*GetSandboxProviderEnvironmentRequest) ProtoMessage() {} func (x *GetSandboxProviderEnvironmentRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[134] + mi := &file_openshell_proto_msgTypes[135] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -11017,7 +11101,7 @@ func (x *GetSandboxProviderEnvironmentRequest) ProtoReflect() protoreflect.Messa // Deprecated: Use GetSandboxProviderEnvironmentRequest.ProtoReflect.Descriptor instead. func (*GetSandboxProviderEnvironmentRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{134} + return file_openshell_proto_rawDescGZIP(), []int{135} } func (x *GetSandboxProviderEnvironmentRequest) GetSandboxId() string { @@ -11046,7 +11130,7 @@ type StaticCredentialEndpointBinding struct { func (x *StaticCredentialEndpointBinding) Reset() { *x = StaticCredentialEndpointBinding{} - mi := &file_openshell_proto_msgTypes[135] + mi := &file_openshell_proto_msgTypes[136] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -11058,7 +11142,7 @@ func (x *StaticCredentialEndpointBinding) String() string { func (*StaticCredentialEndpointBinding) ProtoMessage() {} func (x *StaticCredentialEndpointBinding) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[135] + mi := &file_openshell_proto_msgTypes[136] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -11071,7 +11155,7 @@ func (x *StaticCredentialEndpointBinding) ProtoReflect() protoreflect.Message { // Deprecated: Use StaticCredentialEndpointBinding.ProtoReflect.Descriptor instead. func (*StaticCredentialEndpointBinding) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{135} + return file_openshell_proto_rawDescGZIP(), []int{136} } func (x *StaticCredentialEndpointBinding) GetHost() string { @@ -11115,7 +11199,7 @@ type StaticCredentialBinding struct { func (x *StaticCredentialBinding) Reset() { *x = StaticCredentialBinding{} - mi := &file_openshell_proto_msgTypes[136] + mi := &file_openshell_proto_msgTypes[137] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -11127,7 +11211,7 @@ func (x *StaticCredentialBinding) String() string { func (*StaticCredentialBinding) ProtoMessage() {} func (x *StaticCredentialBinding) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[136] + mi := &file_openshell_proto_msgTypes[137] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -11140,7 +11224,7 @@ func (x *StaticCredentialBinding) ProtoReflect() protoreflect.Message { // Deprecated: Use StaticCredentialBinding.ProtoReflect.Descriptor instead. func (*StaticCredentialBinding) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{136} + return file_openshell_proto_rawDescGZIP(), []int{137} } func (x *StaticCredentialBinding) GetEndpoints() []*StaticCredentialEndpointBinding { @@ -11199,7 +11283,7 @@ type GetSandboxProviderEnvironmentResponse struct { func (x *GetSandboxProviderEnvironmentResponse) Reset() { *x = GetSandboxProviderEnvironmentResponse{} - mi := &file_openshell_proto_msgTypes[137] + mi := &file_openshell_proto_msgTypes[138] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -11211,7 +11295,7 @@ func (x *GetSandboxProviderEnvironmentResponse) String() string { func (*GetSandboxProviderEnvironmentResponse) ProtoMessage() {} func (x *GetSandboxProviderEnvironmentResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[137] + mi := &file_openshell_proto_msgTypes[138] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -11224,7 +11308,7 @@ func (x *GetSandboxProviderEnvironmentResponse) ProtoReflect() protoreflect.Mess // Deprecated: Use GetSandboxProviderEnvironmentResponse.ProtoReflect.Descriptor instead. func (*GetSandboxProviderEnvironmentResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{137} + return file_openshell_proto_rawDescGZIP(), []int{138} } func (x *GetSandboxProviderEnvironmentResponse) GetEnvironment() map[string]string { @@ -11314,7 +11398,7 @@ type ExchangeProviderSubjectTokenRequest struct { func (x *ExchangeProviderSubjectTokenRequest) Reset() { *x = ExchangeProviderSubjectTokenRequest{} - mi := &file_openshell_proto_msgTypes[138] + mi := &file_openshell_proto_msgTypes[139] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -11326,7 +11410,7 @@ func (x *ExchangeProviderSubjectTokenRequest) String() string { func (*ExchangeProviderSubjectTokenRequest) ProtoMessage() {} func (x *ExchangeProviderSubjectTokenRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[138] + mi := &file_openshell_proto_msgTypes[139] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -11339,7 +11423,7 @@ func (x *ExchangeProviderSubjectTokenRequest) ProtoReflect() protoreflect.Messag // Deprecated: Use ExchangeProviderSubjectTokenRequest.ProtoReflect.Descriptor instead. func (*ExchangeProviderSubjectTokenRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{138} + return file_openshell_proto_rawDescGZIP(), []int{139} } func (x *ExchangeProviderSubjectTokenRequest) GetSandboxId() string { @@ -11381,7 +11465,7 @@ type ExchangeProviderSubjectTokenResponse struct { func (x *ExchangeProviderSubjectTokenResponse) Reset() { *x = ExchangeProviderSubjectTokenResponse{} - mi := &file_openshell_proto_msgTypes[139] + mi := &file_openshell_proto_msgTypes[140] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -11393,7 +11477,7 @@ func (x *ExchangeProviderSubjectTokenResponse) String() string { func (*ExchangeProviderSubjectTokenResponse) ProtoMessage() {} func (x *ExchangeProviderSubjectTokenResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[139] + mi := &file_openshell_proto_msgTypes[140] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -11406,7 +11490,7 @@ func (x *ExchangeProviderSubjectTokenResponse) ProtoReflect() protoreflect.Messa // Deprecated: Use ExchangeProviderSubjectTokenResponse.ProtoReflect.Descriptor instead. func (*ExchangeProviderSubjectTokenResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{139} + return file_openshell_proto_rawDescGZIP(), []int{140} } func (x *ExchangeProviderSubjectTokenResponse) GetAccessToken() string { @@ -11479,7 +11563,7 @@ type UpdateConfigRequest struct { func (x *UpdateConfigRequest) Reset() { *x = UpdateConfigRequest{} - mi := &file_openshell_proto_msgTypes[140] + mi := &file_openshell_proto_msgTypes[141] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -11491,7 +11575,7 @@ func (x *UpdateConfigRequest) String() string { func (*UpdateConfigRequest) ProtoMessage() {} func (x *UpdateConfigRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[140] + mi := &file_openshell_proto_msgTypes[141] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -11504,7 +11588,7 @@ func (x *UpdateConfigRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use UpdateConfigRequest.ProtoReflect.Descriptor instead. func (*UpdateConfigRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{140} + return file_openshell_proto_rawDescGZIP(), []int{141} } func (x *UpdateConfigRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -11601,7 +11685,7 @@ type PolicyMergeOperation struct { func (x *PolicyMergeOperation) Reset() { *x = PolicyMergeOperation{} - mi := &file_openshell_proto_msgTypes[141] + mi := &file_openshell_proto_msgTypes[142] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -11613,7 +11697,7 @@ func (x *PolicyMergeOperation) String() string { func (*PolicyMergeOperation) ProtoMessage() {} func (x *PolicyMergeOperation) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[141] + mi := &file_openshell_proto_msgTypes[142] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -11626,7 +11710,7 @@ func (x *PolicyMergeOperation) ProtoReflect() protoreflect.Message { // Deprecated: Use PolicyMergeOperation.ProtoReflect.Descriptor instead. func (*PolicyMergeOperation) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{141} + return file_openshell_proto_rawDescGZIP(), []int{142} } func (x *PolicyMergeOperation) GetOperation() isPolicyMergeOperation_Operation { @@ -11740,7 +11824,7 @@ type AddNetworkRule struct { func (x *AddNetworkRule) Reset() { *x = AddNetworkRule{} - mi := &file_openshell_proto_msgTypes[142] + mi := &file_openshell_proto_msgTypes[143] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -11752,7 +11836,7 @@ func (x *AddNetworkRule) String() string { func (*AddNetworkRule) ProtoMessage() {} func (x *AddNetworkRule) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[142] + mi := &file_openshell_proto_msgTypes[143] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -11765,7 +11849,7 @@ func (x *AddNetworkRule) ProtoReflect() protoreflect.Message { // Deprecated: Use AddNetworkRule.ProtoReflect.Descriptor instead. func (*AddNetworkRule) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{142} + return file_openshell_proto_rawDescGZIP(), []int{143} } func (x *AddNetworkRule) GetRuleName() string { @@ -11793,7 +11877,7 @@ type RemoveNetworkEndpoint struct { func (x *RemoveNetworkEndpoint) Reset() { *x = RemoveNetworkEndpoint{} - mi := &file_openshell_proto_msgTypes[143] + mi := &file_openshell_proto_msgTypes[144] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -11805,7 +11889,7 @@ func (x *RemoveNetworkEndpoint) String() string { func (*RemoveNetworkEndpoint) ProtoMessage() {} func (x *RemoveNetworkEndpoint) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[143] + mi := &file_openshell_proto_msgTypes[144] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -11818,7 +11902,7 @@ func (x *RemoveNetworkEndpoint) ProtoReflect() protoreflect.Message { // Deprecated: Use RemoveNetworkEndpoint.ProtoReflect.Descriptor instead. func (*RemoveNetworkEndpoint) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{143} + return file_openshell_proto_rawDescGZIP(), []int{144} } func (x *RemoveNetworkEndpoint) GetRuleName() string { @@ -11851,7 +11935,7 @@ type RemoveNetworkRule struct { func (x *RemoveNetworkRule) Reset() { *x = RemoveNetworkRule{} - mi := &file_openshell_proto_msgTypes[144] + mi := &file_openshell_proto_msgTypes[145] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -11863,7 +11947,7 @@ func (x *RemoveNetworkRule) String() string { func (*RemoveNetworkRule) ProtoMessage() {} func (x *RemoveNetworkRule) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[144] + mi := &file_openshell_proto_msgTypes[145] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -11876,7 +11960,7 @@ func (x *RemoveNetworkRule) ProtoReflect() protoreflect.Message { // Deprecated: Use RemoveNetworkRule.ProtoReflect.Descriptor instead. func (*RemoveNetworkRule) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{144} + return file_openshell_proto_rawDescGZIP(), []int{145} } func (x *RemoveNetworkRule) GetRuleName() string { @@ -11905,7 +11989,7 @@ type L7RuleTarget struct { func (x *L7RuleTarget) Reset() { *x = L7RuleTarget{} - mi := &file_openshell_proto_msgTypes[145] + mi := &file_openshell_proto_msgTypes[146] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -11917,7 +12001,7 @@ func (x *L7RuleTarget) String() string { func (*L7RuleTarget) ProtoMessage() {} func (x *L7RuleTarget) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[145] + mi := &file_openshell_proto_msgTypes[146] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -11930,7 +12014,7 @@ func (x *L7RuleTarget) ProtoReflect() protoreflect.Message { // Deprecated: Use L7RuleTarget.ProtoReflect.Descriptor instead. func (*L7RuleTarget) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{145} + return file_openshell_proto_rawDescGZIP(), []int{146} } func (x *L7RuleTarget) GetRuleName() string { @@ -11985,7 +12069,7 @@ type AddDenyRules struct { func (x *AddDenyRules) Reset() { *x = AddDenyRules{} - mi := &file_openshell_proto_msgTypes[146] + mi := &file_openshell_proto_msgTypes[147] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -11997,7 +12081,7 @@ func (x *AddDenyRules) String() string { func (*AddDenyRules) ProtoMessage() {} func (x *AddDenyRules) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[146] + mi := &file_openshell_proto_msgTypes[147] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -12010,7 +12094,7 @@ func (x *AddDenyRules) ProtoReflect() protoreflect.Message { // Deprecated: Use AddDenyRules.ProtoReflect.Descriptor instead. func (*AddDenyRules) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{146} + return file_openshell_proto_rawDescGZIP(), []int{147} } func (x *AddDenyRules) GetDenyRules() []*sandboxv1.L7DenyRule { @@ -12037,7 +12121,7 @@ type AddAllowRules struct { func (x *AddAllowRules) Reset() { *x = AddAllowRules{} - mi := &file_openshell_proto_msgTypes[147] + mi := &file_openshell_proto_msgTypes[148] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -12049,7 +12133,7 @@ func (x *AddAllowRules) String() string { func (*AddAllowRules) ProtoMessage() {} func (x *AddAllowRules) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[147] + mi := &file_openshell_proto_msgTypes[148] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -12062,7 +12146,7 @@ func (x *AddAllowRules) ProtoReflect() protoreflect.Message { // Deprecated: Use AddAllowRules.ProtoReflect.Descriptor instead. func (*AddAllowRules) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{147} + return file_openshell_proto_rawDescGZIP(), []int{148} } func (x *AddAllowRules) GetRules() []*sandboxv1.L7Rule { @@ -12089,7 +12173,7 @@ type RemoveNetworkBinary struct { func (x *RemoveNetworkBinary) Reset() { *x = RemoveNetworkBinary{} - mi := &file_openshell_proto_msgTypes[148] + mi := &file_openshell_proto_msgTypes[149] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -12101,7 +12185,7 @@ func (x *RemoveNetworkBinary) String() string { func (*RemoveNetworkBinary) ProtoMessage() {} func (x *RemoveNetworkBinary) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[148] + mi := &file_openshell_proto_msgTypes[149] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -12114,7 +12198,7 @@ func (x *RemoveNetworkBinary) ProtoReflect() protoreflect.Message { // Deprecated: Use RemoveNetworkBinary.ProtoReflect.Descriptor instead. func (*RemoveNetworkBinary) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{148} + return file_openshell_proto_rawDescGZIP(), []int{149} } func (x *RemoveNetworkBinary) GetRuleName() string { @@ -12150,7 +12234,7 @@ type UpdateConfigResponse struct { func (x *UpdateConfigResponse) Reset() { *x = UpdateConfigResponse{} - mi := &file_openshell_proto_msgTypes[149] + mi := &file_openshell_proto_msgTypes[150] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -12162,7 +12246,7 @@ func (x *UpdateConfigResponse) String() string { func (*UpdateConfigResponse) ProtoMessage() {} func (x *UpdateConfigResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[149] + mi := &file_openshell_proto_msgTypes[150] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -12175,7 +12259,7 @@ func (x *UpdateConfigResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use UpdateConfigResponse.ProtoReflect.Descriptor instead. func (*UpdateConfigResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{149} + return file_openshell_proto_rawDescGZIP(), []int{150} } func (x *UpdateConfigResponse) GetVersion() uint32 { @@ -12229,7 +12313,7 @@ type GetSandboxPolicyStatusRequest struct { func (x *GetSandboxPolicyStatusRequest) Reset() { *x = GetSandboxPolicyStatusRequest{} - mi := &file_openshell_proto_msgTypes[150] + mi := &file_openshell_proto_msgTypes[151] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -12241,7 +12325,7 @@ func (x *GetSandboxPolicyStatusRequest) String() string { func (*GetSandboxPolicyStatusRequest) ProtoMessage() {} func (x *GetSandboxPolicyStatusRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[150] + mi := &file_openshell_proto_msgTypes[151] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -12254,7 +12338,7 @@ func (x *GetSandboxPolicyStatusRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use GetSandboxPolicyStatusRequest.ProtoReflect.Descriptor instead. func (*GetSandboxPolicyStatusRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{150} + return file_openshell_proto_rawDescGZIP(), []int{151} } func (x *GetSandboxPolicyStatusRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -12298,7 +12382,7 @@ type GetSandboxPolicyStatusResponse struct { func (x *GetSandboxPolicyStatusResponse) Reset() { *x = GetSandboxPolicyStatusResponse{} - mi := &file_openshell_proto_msgTypes[151] + mi := &file_openshell_proto_msgTypes[152] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -12310,7 +12394,7 @@ func (x *GetSandboxPolicyStatusResponse) String() string { func (*GetSandboxPolicyStatusResponse) ProtoMessage() {} func (x *GetSandboxPolicyStatusResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[151] + mi := &file_openshell_proto_msgTypes[152] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -12323,7 +12407,7 @@ func (x *GetSandboxPolicyStatusResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use GetSandboxPolicyStatusResponse.ProtoReflect.Descriptor instead. func (*GetSandboxPolicyStatusResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{151} + return file_openshell_proto_rawDescGZIP(), []int{152} } func (x *GetSandboxPolicyStatusResponse) GetRevision() *SandboxPolicyRevision { @@ -12360,7 +12444,7 @@ type ListSandboxPoliciesRequest struct { func (x *ListSandboxPoliciesRequest) Reset() { *x = ListSandboxPoliciesRequest{} - mi := &file_openshell_proto_msgTypes[152] + mi := &file_openshell_proto_msgTypes[153] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -12372,7 +12456,7 @@ func (x *ListSandboxPoliciesRequest) String() string { func (*ListSandboxPoliciesRequest) ProtoMessage() {} func (x *ListSandboxPoliciesRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[152] + mi := &file_openshell_proto_msgTypes[153] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -12385,7 +12469,7 @@ func (x *ListSandboxPoliciesRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use ListSandboxPoliciesRequest.ProtoReflect.Descriptor instead. func (*ListSandboxPoliciesRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{152} + return file_openshell_proto_rawDescGZIP(), []int{153} } func (x *ListSandboxPoliciesRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -12437,7 +12521,7 @@ type ListSandboxPoliciesResponse struct { func (x *ListSandboxPoliciesResponse) Reset() { *x = ListSandboxPoliciesResponse{} - mi := &file_openshell_proto_msgTypes[153] + mi := &file_openshell_proto_msgTypes[154] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -12449,7 +12533,7 @@ func (x *ListSandboxPoliciesResponse) String() string { func (*ListSandboxPoliciesResponse) ProtoMessage() {} func (x *ListSandboxPoliciesResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[153] + mi := &file_openshell_proto_msgTypes[154] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -12462,7 +12546,7 @@ func (x *ListSandboxPoliciesResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use ListSandboxPoliciesResponse.ProtoReflect.Descriptor instead. func (*ListSandboxPoliciesResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{153} + return file_openshell_proto_rawDescGZIP(), []int{154} } func (x *ListSandboxPoliciesResponse) GetRevisions() []*SandboxPolicyRevision { @@ -12496,7 +12580,7 @@ type ReportPolicyStatusRequest struct { func (x *ReportPolicyStatusRequest) Reset() { *x = ReportPolicyStatusRequest{} - mi := &file_openshell_proto_msgTypes[154] + mi := &file_openshell_proto_msgTypes[155] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -12508,7 +12592,7 @@ func (x *ReportPolicyStatusRequest) String() string { func (*ReportPolicyStatusRequest) ProtoMessage() {} func (x *ReportPolicyStatusRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[154] + mi := &file_openshell_proto_msgTypes[155] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -12521,7 +12605,7 @@ func (x *ReportPolicyStatusRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use ReportPolicyStatusRequest.ProtoReflect.Descriptor instead. func (*ReportPolicyStatusRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{154} + return file_openshell_proto_rawDescGZIP(), []int{155} } func (x *ReportPolicyStatusRequest) GetSandboxId() string { @@ -12561,7 +12645,7 @@ type ReportPolicyStatusResponse struct { func (x *ReportPolicyStatusResponse) Reset() { *x = ReportPolicyStatusResponse{} - mi := &file_openshell_proto_msgTypes[155] + mi := &file_openshell_proto_msgTypes[156] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -12573,7 +12657,7 @@ func (x *ReportPolicyStatusResponse) String() string { func (*ReportPolicyStatusResponse) ProtoMessage() {} func (x *ReportPolicyStatusResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[155] + mi := &file_openshell_proto_msgTypes[156] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -12586,7 +12670,7 @@ func (x *ReportPolicyStatusResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use ReportPolicyStatusResponse.ProtoReflect.Descriptor instead. func (*ReportPolicyStatusResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{155} + return file_openshell_proto_rawDescGZIP(), []int{156} } type SandboxConfigurationAdmission struct { @@ -12604,7 +12688,7 @@ type SandboxConfigurationAdmission struct { func (x *SandboxConfigurationAdmission) Reset() { *x = SandboxConfigurationAdmission{} - mi := &file_openshell_proto_msgTypes[156] + mi := &file_openshell_proto_msgTypes[157] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -12616,7 +12700,7 @@ func (x *SandboxConfigurationAdmission) String() string { func (*SandboxConfigurationAdmission) ProtoMessage() {} func (x *SandboxConfigurationAdmission) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[156] + mi := &file_openshell_proto_msgTypes[157] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -12629,7 +12713,7 @@ func (x *SandboxConfigurationAdmission) ProtoReflect() protoreflect.Message { // Deprecated: Use SandboxConfigurationAdmission.ProtoReflect.Descriptor instead. func (*SandboxConfigurationAdmission) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{156} + return file_openshell_proto_rawDescGZIP(), []int{157} } func (x *SandboxConfigurationAdmission) GetInstanceId() string { @@ -12693,7 +12777,7 @@ type ReportSandboxConfigurationRequest struct { func (x *ReportSandboxConfigurationRequest) Reset() { *x = ReportSandboxConfigurationRequest{} - mi := &file_openshell_proto_msgTypes[157] + mi := &file_openshell_proto_msgTypes[158] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -12705,7 +12789,7 @@ func (x *ReportSandboxConfigurationRequest) String() string { func (*ReportSandboxConfigurationRequest) ProtoMessage() {} func (x *ReportSandboxConfigurationRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[157] + mi := &file_openshell_proto_msgTypes[158] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -12718,7 +12802,7 @@ func (x *ReportSandboxConfigurationRequest) ProtoReflect() protoreflect.Message // Deprecated: Use ReportSandboxConfigurationRequest.ProtoReflect.Descriptor instead. func (*ReportSandboxConfigurationRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{157} + return file_openshell_proto_rawDescGZIP(), []int{158} } func (x *ReportSandboxConfigurationRequest) GetSandboxId() string { @@ -12750,7 +12834,7 @@ type ReportSandboxConfigurationResponse struct { func (x *ReportSandboxConfigurationResponse) Reset() { *x = ReportSandboxConfigurationResponse{} - mi := &file_openshell_proto_msgTypes[158] + mi := &file_openshell_proto_msgTypes[159] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -12762,7 +12846,7 @@ func (x *ReportSandboxConfigurationResponse) String() string { func (*ReportSandboxConfigurationResponse) ProtoMessage() {} func (x *ReportSandboxConfigurationResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[158] + mi := &file_openshell_proto_msgTypes[159] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -12775,7 +12859,7 @@ func (x *ReportSandboxConfigurationResponse) ProtoReflect() protoreflect.Message // Deprecated: Use ReportSandboxConfigurationResponse.ProtoReflect.Descriptor instead. func (*ReportSandboxConfigurationResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{158} + return file_openshell_proto_rawDescGZIP(), []int{159} } // A versioned policy revision with metadata. @@ -12808,7 +12892,7 @@ type SandboxPolicyRevision struct { func (x *SandboxPolicyRevision) Reset() { *x = SandboxPolicyRevision{} - mi := &file_openshell_proto_msgTypes[159] + mi := &file_openshell_proto_msgTypes[160] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -12820,7 +12904,7 @@ func (x *SandboxPolicyRevision) String() string { func (*SandboxPolicyRevision) ProtoMessage() {} func (x *SandboxPolicyRevision) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[159] + mi := &file_openshell_proto_msgTypes[160] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -12833,7 +12917,7 @@ func (x *SandboxPolicyRevision) ProtoReflect() protoreflect.Message { // Deprecated: Use SandboxPolicyRevision.ProtoReflect.Descriptor instead. func (*SandboxPolicyRevision) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{159} + return file_openshell_proto_rawDescGZIP(), []int{160} } func (x *SandboxPolicyRevision) GetVersion() uint32 { @@ -12913,7 +12997,7 @@ type GetSandboxLogsRequest struct { func (x *GetSandboxLogsRequest) Reset() { *x = GetSandboxLogsRequest{} - mi := &file_openshell_proto_msgTypes[160] + mi := &file_openshell_proto_msgTypes[161] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -12925,7 +13009,7 @@ func (x *GetSandboxLogsRequest) String() string { func (*GetSandboxLogsRequest) ProtoMessage() {} func (x *GetSandboxLogsRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[160] + mi := &file_openshell_proto_msgTypes[161] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -12938,7 +13022,7 @@ func (x *GetSandboxLogsRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use GetSandboxLogsRequest.ProtoReflect.Descriptor instead. func (*GetSandboxLogsRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{160} + return file_openshell_proto_rawDescGZIP(), []int{161} } func (x *GetSandboxLogsRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -12996,7 +13080,7 @@ type PushSandboxLogsRequest struct { func (x *PushSandboxLogsRequest) Reset() { *x = PushSandboxLogsRequest{} - mi := &file_openshell_proto_msgTypes[161] + mi := &file_openshell_proto_msgTypes[162] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -13008,7 +13092,7 @@ func (x *PushSandboxLogsRequest) String() string { func (*PushSandboxLogsRequest) ProtoMessage() {} func (x *PushSandboxLogsRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[161] + mi := &file_openshell_proto_msgTypes[162] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -13021,7 +13105,7 @@ func (x *PushSandboxLogsRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use PushSandboxLogsRequest.ProtoReflect.Descriptor instead. func (*PushSandboxLogsRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{161} + return file_openshell_proto_rawDescGZIP(), []int{162} } func (x *PushSandboxLogsRequest) GetSandboxId() string { @@ -13047,7 +13131,7 @@ type PushSandboxLogsResponse struct { func (x *PushSandboxLogsResponse) Reset() { *x = PushSandboxLogsResponse{} - mi := &file_openshell_proto_msgTypes[162] + mi := &file_openshell_proto_msgTypes[163] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -13059,7 +13143,7 @@ func (x *PushSandboxLogsResponse) String() string { func (*PushSandboxLogsResponse) ProtoMessage() {} func (x *PushSandboxLogsResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[162] + mi := &file_openshell_proto_msgTypes[163] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -13072,7 +13156,7 @@ func (x *PushSandboxLogsResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use PushSandboxLogsResponse.ProtoReflect.Descriptor instead. func (*PushSandboxLogsResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{162} + return file_openshell_proto_rawDescGZIP(), []int{163} } // Get sandbox logs response. @@ -13088,7 +13172,7 @@ type GetSandboxLogsResponse struct { func (x *GetSandboxLogsResponse) Reset() { *x = GetSandboxLogsResponse{} - mi := &file_openshell_proto_msgTypes[163] + mi := &file_openshell_proto_msgTypes[164] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -13100,7 +13184,7 @@ func (x *GetSandboxLogsResponse) String() string { func (*GetSandboxLogsResponse) ProtoMessage() {} func (x *GetSandboxLogsResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[163] + mi := &file_openshell_proto_msgTypes[164] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -13113,7 +13197,7 @@ func (x *GetSandboxLogsResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use GetSandboxLogsResponse.ProtoReflect.Descriptor instead. func (*GetSandboxLogsResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{163} + return file_openshell_proto_rawDescGZIP(), []int{164} } func (x *GetSandboxLogsResponse) GetLogs() []*SandboxLogLine { @@ -13146,7 +13230,7 @@ type SupervisorMessage struct { func (x *SupervisorMessage) Reset() { *x = SupervisorMessage{} - mi := &file_openshell_proto_msgTypes[164] + mi := &file_openshell_proto_msgTypes[165] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -13158,7 +13242,7 @@ func (x *SupervisorMessage) String() string { func (*SupervisorMessage) ProtoMessage() {} func (x *SupervisorMessage) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[164] + mi := &file_openshell_proto_msgTypes[165] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -13171,7 +13255,7 @@ func (x *SupervisorMessage) ProtoReflect() protoreflect.Message { // Deprecated: Use SupervisorMessage.ProtoReflect.Descriptor instead. func (*SupervisorMessage) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{164} + return file_openshell_proto_rawDescGZIP(), []int{165} } func (x *SupervisorMessage) GetPayload() isSupervisorMessage_Payload { @@ -13262,7 +13346,7 @@ type GatewayMessage struct { func (x *GatewayMessage) Reset() { *x = GatewayMessage{} - mi := &file_openshell_proto_msgTypes[165] + mi := &file_openshell_proto_msgTypes[166] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -13274,7 +13358,7 @@ func (x *GatewayMessage) String() string { func (*GatewayMessage) ProtoMessage() {} func (x *GatewayMessage) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[165] + mi := &file_openshell_proto_msgTypes[166] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -13287,7 +13371,7 @@ func (x *GatewayMessage) ProtoReflect() protoreflect.Message { // Deprecated: Use GatewayMessage.ProtoReflect.Descriptor instead. func (*GatewayMessage) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{165} + return file_openshell_proto_rawDescGZIP(), []int{166} } func (x *GatewayMessage) GetPayload() isGatewayMessage_Payload { @@ -13394,7 +13478,7 @@ type SupervisorHello struct { func (x *SupervisorHello) Reset() { *x = SupervisorHello{} - mi := &file_openshell_proto_msgTypes[166] + mi := &file_openshell_proto_msgTypes[167] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -13406,7 +13490,7 @@ func (x *SupervisorHello) String() string { func (*SupervisorHello) ProtoMessage() {} func (x *SupervisorHello) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[166] + mi := &file_openshell_proto_msgTypes[167] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -13419,7 +13503,7 @@ func (x *SupervisorHello) ProtoReflect() protoreflect.Message { // Deprecated: Use SupervisorHello.ProtoReflect.Descriptor instead. func (*SupervisorHello) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{166} + return file_openshell_proto_rawDescGZIP(), []int{167} } func (x *SupervisorHello) GetSandboxId() string { @@ -13463,7 +13547,7 @@ type SessionAccepted struct { func (x *SessionAccepted) Reset() { *x = SessionAccepted{} - mi := &file_openshell_proto_msgTypes[167] + mi := &file_openshell_proto_msgTypes[168] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -13475,7 +13559,7 @@ func (x *SessionAccepted) String() string { func (*SessionAccepted) ProtoMessage() {} func (x *SessionAccepted) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[167] + mi := &file_openshell_proto_msgTypes[168] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -13488,7 +13572,7 @@ func (x *SessionAccepted) ProtoReflect() protoreflect.Message { // Deprecated: Use SessionAccepted.ProtoReflect.Descriptor instead. func (*SessionAccepted) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{167} + return file_openshell_proto_rawDescGZIP(), []int{168} } func (x *SessionAccepted) GetSessionId() string { @@ -13516,7 +13600,7 @@ type SessionRejected struct { func (x *SessionRejected) Reset() { *x = SessionRejected{} - mi := &file_openshell_proto_msgTypes[168] + mi := &file_openshell_proto_msgTypes[169] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -13528,7 +13612,7 @@ func (x *SessionRejected) String() string { func (*SessionRejected) ProtoMessage() {} func (x *SessionRejected) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[168] + mi := &file_openshell_proto_msgTypes[169] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -13541,7 +13625,7 @@ func (x *SessionRejected) ProtoReflect() protoreflect.Message { // Deprecated: Use SessionRejected.ProtoReflect.Descriptor instead. func (*SessionRejected) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{168} + return file_openshell_proto_rawDescGZIP(), []int{169} } func (x *SessionRejected) GetReason() string { @@ -13560,7 +13644,7 @@ type SupervisorHeartbeat struct { func (x *SupervisorHeartbeat) Reset() { *x = SupervisorHeartbeat{} - mi := &file_openshell_proto_msgTypes[169] + mi := &file_openshell_proto_msgTypes[170] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -13572,7 +13656,7 @@ func (x *SupervisorHeartbeat) String() string { func (*SupervisorHeartbeat) ProtoMessage() {} func (x *SupervisorHeartbeat) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[169] + mi := &file_openshell_proto_msgTypes[170] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -13585,7 +13669,7 @@ func (x *SupervisorHeartbeat) ProtoReflect() protoreflect.Message { // Deprecated: Use SupervisorHeartbeat.ProtoReflect.Descriptor instead. func (*SupervisorHeartbeat) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{169} + return file_openshell_proto_rawDescGZIP(), []int{170} } // Gateway heartbeat. @@ -13597,7 +13681,7 @@ type GatewayHeartbeat struct { func (x *GatewayHeartbeat) Reset() { *x = GatewayHeartbeat{} - mi := &file_openshell_proto_msgTypes[170] + mi := &file_openshell_proto_msgTypes[171] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -13609,7 +13693,7 @@ func (x *GatewayHeartbeat) String() string { func (*GatewayHeartbeat) ProtoMessage() {} func (x *GatewayHeartbeat) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[170] + mi := &file_openshell_proto_msgTypes[171] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -13622,7 +13706,7 @@ func (x *GatewayHeartbeat) ProtoReflect() protoreflect.Message { // Deprecated: Use GatewayHeartbeat.ProtoReflect.Descriptor instead. func (*GatewayHeartbeat) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{170} + return file_openshell_proto_rawDescGZIP(), []int{171} } // Terminal result reported before the supervisor shuts down. A successful RPC @@ -13639,7 +13723,7 @@ type ReportMainProcessExitRequest struct { func (x *ReportMainProcessExitRequest) Reset() { *x = ReportMainProcessExitRequest{} - mi := &file_openshell_proto_msgTypes[171] + mi := &file_openshell_proto_msgTypes[172] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -13651,7 +13735,7 @@ func (x *ReportMainProcessExitRequest) String() string { func (*ReportMainProcessExitRequest) ProtoMessage() {} func (x *ReportMainProcessExitRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[171] + mi := &file_openshell_proto_msgTypes[172] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -13664,7 +13748,7 @@ func (x *ReportMainProcessExitRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use ReportMainProcessExitRequest.ProtoReflect.Descriptor instead. func (*ReportMainProcessExitRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{171} + return file_openshell_proto_rawDescGZIP(), []int{172} } func (x *ReportMainProcessExitRequest) GetSandboxId() string { @@ -13696,7 +13780,7 @@ type ReportMainProcessExitResponse struct { func (x *ReportMainProcessExitResponse) Reset() { *x = ReportMainProcessExitResponse{} - mi := &file_openshell_proto_msgTypes[172] + mi := &file_openshell_proto_msgTypes[173] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -13708,7 +13792,7 @@ func (x *ReportMainProcessExitResponse) String() string { func (*ReportMainProcessExitResponse) ProtoMessage() {} func (x *ReportMainProcessExitResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[172] + mi := &file_openshell_proto_msgTypes[173] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -13721,7 +13805,7 @@ func (x *ReportMainProcessExitResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use ReportMainProcessExitResponse.ProtoReflect.Descriptor instead. func (*ReportMainProcessExitResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{172} + return file_openshell_proto_rawDescGZIP(), []int{173} } // Terminal-delivery completion reported after all expected foreground SSH @@ -13736,7 +13820,7 @@ type FinalizeMainProcessExitRequest struct { func (x *FinalizeMainProcessExitRequest) Reset() { *x = FinalizeMainProcessExitRequest{} - mi := &file_openshell_proto_msgTypes[173] + mi := &file_openshell_proto_msgTypes[174] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -13748,7 +13832,7 @@ func (x *FinalizeMainProcessExitRequest) String() string { func (*FinalizeMainProcessExitRequest) ProtoMessage() {} func (x *FinalizeMainProcessExitRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[173] + mi := &file_openshell_proto_msgTypes[174] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -13761,7 +13845,7 @@ func (x *FinalizeMainProcessExitRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use FinalizeMainProcessExitRequest.ProtoReflect.Descriptor instead. func (*FinalizeMainProcessExitRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{173} + return file_openshell_proto_rawDescGZIP(), []int{174} } func (x *FinalizeMainProcessExitRequest) GetSandboxId() string { @@ -13786,7 +13870,7 @@ type FinalizeMainProcessExitResponse struct { func (x *FinalizeMainProcessExitResponse) Reset() { *x = FinalizeMainProcessExitResponse{} - mi := &file_openshell_proto_msgTypes[174] + mi := &file_openshell_proto_msgTypes[175] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -13798,7 +13882,7 @@ func (x *FinalizeMainProcessExitResponse) String() string { func (*FinalizeMainProcessExitResponse) ProtoMessage() {} func (x *FinalizeMainProcessExitResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[174] + mi := &file_openshell_proto_msgTypes[175] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -13811,7 +13895,7 @@ func (x *FinalizeMainProcessExitResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use FinalizeMainProcessExitResponse.ProtoReflect.Descriptor instead. func (*FinalizeMainProcessExitResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{174} + return file_openshell_proto_rawDescGZIP(), []int{175} } // Gateway requests the supervisor to open a relay channel. @@ -13840,7 +13924,7 @@ type RelayOpen struct { func (x *RelayOpen) Reset() { *x = RelayOpen{} - mi := &file_openshell_proto_msgTypes[175] + mi := &file_openshell_proto_msgTypes[176] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -13852,7 +13936,7 @@ func (x *RelayOpen) String() string { func (*RelayOpen) ProtoMessage() {} func (x *RelayOpen) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[175] + mi := &file_openshell_proto_msgTypes[176] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -13865,7 +13949,7 @@ func (x *RelayOpen) ProtoReflect() protoreflect.Message { // Deprecated: Use RelayOpen.ProtoReflect.Descriptor instead. func (*RelayOpen) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{175} + return file_openshell_proto_rawDescGZIP(), []int{176} } func (x *RelayOpen) GetChannelId() string { @@ -13932,7 +14016,7 @@ type SshRelayTarget struct { func (x *SshRelayTarget) Reset() { *x = SshRelayTarget{} - mi := &file_openshell_proto_msgTypes[176] + mi := &file_openshell_proto_msgTypes[177] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -13944,7 +14028,7 @@ func (x *SshRelayTarget) String() string { func (*SshRelayTarget) ProtoMessage() {} func (x *SshRelayTarget) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[176] + mi := &file_openshell_proto_msgTypes[177] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -13957,7 +14041,7 @@ func (x *SshRelayTarget) ProtoReflect() protoreflect.Message { // Deprecated: Use SshRelayTarget.ProtoReflect.Descriptor instead. func (*SshRelayTarget) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{176} + return file_openshell_proto_rawDescGZIP(), []int{177} } // TCP target dialed by the supervisor from inside the sandbox. @@ -13973,7 +14057,7 @@ type TcpRelayTarget struct { func (x *TcpRelayTarget) Reset() { *x = TcpRelayTarget{} - mi := &file_openshell_proto_msgTypes[177] + mi := &file_openshell_proto_msgTypes[178] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -13985,7 +14069,7 @@ func (x *TcpRelayTarget) String() string { func (*TcpRelayTarget) ProtoMessage() {} func (x *TcpRelayTarget) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[177] + mi := &file_openshell_proto_msgTypes[178] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -13998,7 +14082,7 @@ func (x *TcpRelayTarget) ProtoReflect() protoreflect.Message { // Deprecated: Use TcpRelayTarget.ProtoReflect.Descriptor instead. func (*TcpRelayTarget) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{177} + return file_openshell_proto_rawDescGZIP(), []int{178} } func (x *TcpRelayTarget) GetHost() string { @@ -14026,7 +14110,7 @@ type RelayInit struct { func (x *RelayInit) Reset() { *x = RelayInit{} - mi := &file_openshell_proto_msgTypes[178] + mi := &file_openshell_proto_msgTypes[179] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -14038,7 +14122,7 @@ func (x *RelayInit) String() string { func (*RelayInit) ProtoMessage() {} func (x *RelayInit) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[178] + mi := &file_openshell_proto_msgTypes[179] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -14051,7 +14135,7 @@ func (x *RelayInit) ProtoReflect() protoreflect.Message { // Deprecated: Use RelayInit.ProtoReflect.Descriptor instead. func (*RelayInit) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{178} + return file_openshell_proto_rawDescGZIP(), []int{179} } func (x *RelayInit) GetChannelId() string { @@ -14078,7 +14162,7 @@ type RelayFrame struct { func (x *RelayFrame) Reset() { *x = RelayFrame{} - mi := &file_openshell_proto_msgTypes[179] + mi := &file_openshell_proto_msgTypes[180] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -14090,7 +14174,7 @@ func (x *RelayFrame) String() string { func (*RelayFrame) ProtoMessage() {} func (x *RelayFrame) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[179] + mi := &file_openshell_proto_msgTypes[180] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -14103,7 +14187,7 @@ func (x *RelayFrame) ProtoReflect() protoreflect.Message { // Deprecated: Use RelayFrame.ProtoReflect.Descriptor instead. func (*RelayFrame) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{179} + return file_openshell_proto_rawDescGZIP(), []int{180} } func (x *RelayFrame) GetPayload() isRelayFrame_Payload { @@ -14163,7 +14247,7 @@ type PeerRelayInit struct { func (x *PeerRelayInit) Reset() { *x = PeerRelayInit{} - mi := &file_openshell_proto_msgTypes[180] + mi := &file_openshell_proto_msgTypes[181] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -14175,7 +14259,7 @@ func (x *PeerRelayInit) String() string { func (*PeerRelayInit) ProtoMessage() {} func (x *PeerRelayInit) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[180] + mi := &file_openshell_proto_msgTypes[181] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -14188,7 +14272,7 @@ func (x *PeerRelayInit) ProtoReflect() protoreflect.Message { // Deprecated: Use PeerRelayInit.ProtoReflect.Descriptor instead. func (*PeerRelayInit) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{180} + return file_openshell_proto_rawDescGZIP(), []int{181} } func (x *PeerRelayInit) GetSandboxId() string { @@ -14226,7 +14310,7 @@ type PeerRelayFrame struct { func (x *PeerRelayFrame) Reset() { *x = PeerRelayFrame{} - mi := &file_openshell_proto_msgTypes[181] + mi := &file_openshell_proto_msgTypes[182] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -14238,7 +14322,7 @@ func (x *PeerRelayFrame) String() string { func (*PeerRelayFrame) ProtoMessage() {} func (x *PeerRelayFrame) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[181] + mi := &file_openshell_proto_msgTypes[182] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -14251,7 +14335,7 @@ func (x *PeerRelayFrame) ProtoReflect() protoreflect.Message { // Deprecated: Use PeerRelayFrame.ProtoReflect.Descriptor instead. func (*PeerRelayFrame) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{181} + return file_openshell_proto_rawDescGZIP(), []int{182} } func (x *PeerRelayFrame) GetPayload() isPeerRelayFrame_Payload { @@ -14310,7 +14394,7 @@ type RelayOpenResult struct { func (x *RelayOpenResult) Reset() { *x = RelayOpenResult{} - mi := &file_openshell_proto_msgTypes[182] + mi := &file_openshell_proto_msgTypes[183] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -14322,7 +14406,7 @@ func (x *RelayOpenResult) String() string { func (*RelayOpenResult) ProtoMessage() {} func (x *RelayOpenResult) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[182] + mi := &file_openshell_proto_msgTypes[183] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -14335,7 +14419,7 @@ func (x *RelayOpenResult) ProtoReflect() protoreflect.Message { // Deprecated: Use RelayOpenResult.ProtoReflect.Descriptor instead. func (*RelayOpenResult) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{182} + return file_openshell_proto_rawDescGZIP(), []int{183} } func (x *RelayOpenResult) GetChannelId() string { @@ -14372,7 +14456,7 @@ type RelayClose struct { func (x *RelayClose) Reset() { *x = RelayClose{} - mi := &file_openshell_proto_msgTypes[183] + mi := &file_openshell_proto_msgTypes[184] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -14384,7 +14468,7 @@ func (x *RelayClose) String() string { func (*RelayClose) ProtoMessage() {} func (x *RelayClose) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[183] + mi := &file_openshell_proto_msgTypes[184] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -14397,7 +14481,7 @@ func (x *RelayClose) ProtoReflect() protoreflect.Message { // Deprecated: Use RelayClose.ProtoReflect.Descriptor instead. func (*RelayClose) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{183} + return file_openshell_proto_rawDescGZIP(), []int{184} } func (x *RelayClose) GetChannelId() string { @@ -14431,7 +14515,7 @@ type L7RequestSample struct { func (x *L7RequestSample) Reset() { *x = L7RequestSample{} - mi := &file_openshell_proto_msgTypes[184] + mi := &file_openshell_proto_msgTypes[185] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -14443,7 +14527,7 @@ func (x *L7RequestSample) String() string { func (*L7RequestSample) ProtoMessage() {} func (x *L7RequestSample) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[184] + mi := &file_openshell_proto_msgTypes[185] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -14456,7 +14540,7 @@ func (x *L7RequestSample) ProtoReflect() protoreflect.Message { // Deprecated: Use L7RequestSample.ProtoReflect.Descriptor instead. func (*L7RequestSample) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{184} + return file_openshell_proto_rawDescGZIP(), []int{185} } func (x *L7RequestSample) GetMethod() string { @@ -14530,7 +14614,7 @@ type DenialSummary struct { func (x *DenialSummary) Reset() { *x = DenialSummary{} - mi := &file_openshell_proto_msgTypes[185] + mi := &file_openshell_proto_msgTypes[186] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -14542,7 +14626,7 @@ func (x *DenialSummary) String() string { func (*DenialSummary) ProtoMessage() {} func (x *DenialSummary) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[185] + mi := &file_openshell_proto_msgTypes[186] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -14555,7 +14639,7 @@ func (x *DenialSummary) ProtoReflect() protoreflect.Message { // Deprecated: Use DenialSummary.ProtoReflect.Descriptor instead. func (*DenialSummary) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{185} + return file_openshell_proto_rawDescGZIP(), []int{186} } func (x *DenialSummary) GetSandboxId() string { @@ -14690,7 +14774,7 @@ type DenialGroupCount struct { func (x *DenialGroupCount) Reset() { *x = DenialGroupCount{} - mi := &file_openshell_proto_msgTypes[186] + mi := &file_openshell_proto_msgTypes[187] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -14702,7 +14786,7 @@ func (x *DenialGroupCount) String() string { func (*DenialGroupCount) ProtoMessage() {} func (x *DenialGroupCount) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[186] + mi := &file_openshell_proto_msgTypes[187] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -14715,7 +14799,7 @@ func (x *DenialGroupCount) ProtoReflect() protoreflect.Message { // Deprecated: Use DenialGroupCount.ProtoReflect.Descriptor instead. func (*DenialGroupCount) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{186} + return file_openshell_proto_rawDescGZIP(), []int{187} } func (x *DenialGroupCount) GetDenyGroup() string { @@ -14748,7 +14832,7 @@ type NetworkActivitySummary struct { func (x *NetworkActivitySummary) Reset() { *x = NetworkActivitySummary{} - mi := &file_openshell_proto_msgTypes[187] + mi := &file_openshell_proto_msgTypes[188] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -14760,7 +14844,7 @@ func (x *NetworkActivitySummary) String() string { func (*NetworkActivitySummary) ProtoMessage() {} func (x *NetworkActivitySummary) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[187] + mi := &file_openshell_proto_msgTypes[188] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -14773,7 +14857,7 @@ func (x *NetworkActivitySummary) ProtoReflect() protoreflect.Message { // Deprecated: Use NetworkActivitySummary.ProtoReflect.Descriptor instead. func (*NetworkActivitySummary) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{187} + return file_openshell_proto_rawDescGZIP(), []int{188} } func (x *NetworkActivitySummary) GetNetworkActivityCount() uint32 { @@ -14861,7 +14945,7 @@ type PolicyChunk struct { func (x *PolicyChunk) Reset() { *x = PolicyChunk{} - mi := &file_openshell_proto_msgTypes[188] + mi := &file_openshell_proto_msgTypes[189] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -14873,7 +14957,7 @@ func (x *PolicyChunk) String() string { func (*PolicyChunk) ProtoMessage() {} func (x *PolicyChunk) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[188] + mi := &file_openshell_proto_msgTypes[189] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -14886,7 +14970,7 @@ func (x *PolicyChunk) ProtoReflect() protoreflect.Message { // Deprecated: Use PolicyChunk.ProtoReflect.Descriptor instead. func (*PolicyChunk) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{188} + return file_openshell_proto_rawDescGZIP(), []int{189} } func (x *PolicyChunk) GetId() string { @@ -15074,7 +15158,7 @@ type DraftPolicyUpdate struct { func (x *DraftPolicyUpdate) Reset() { *x = DraftPolicyUpdate{} - mi := &file_openshell_proto_msgTypes[189] + mi := &file_openshell_proto_msgTypes[190] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -15086,7 +15170,7 @@ func (x *DraftPolicyUpdate) String() string { func (*DraftPolicyUpdate) ProtoMessage() {} func (x *DraftPolicyUpdate) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[189] + mi := &file_openshell_proto_msgTypes[190] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -15099,7 +15183,7 @@ func (x *DraftPolicyUpdate) ProtoReflect() protoreflect.Message { // Deprecated: Use DraftPolicyUpdate.ProtoReflect.Descriptor instead. func (*DraftPolicyUpdate) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{189} + return file_openshell_proto_rawDescGZIP(), []int{190} } func (x *DraftPolicyUpdate) GetDraftVersion() uint64 { @@ -15158,7 +15242,7 @@ type SubmitPolicyAnalysisRequest struct { func (x *SubmitPolicyAnalysisRequest) Reset() { *x = SubmitPolicyAnalysisRequest{} - mi := &file_openshell_proto_msgTypes[190] + mi := &file_openshell_proto_msgTypes[191] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -15170,7 +15254,7 @@ func (x *SubmitPolicyAnalysisRequest) String() string { func (*SubmitPolicyAnalysisRequest) ProtoMessage() {} func (x *SubmitPolicyAnalysisRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[190] + mi := &file_openshell_proto_msgTypes[191] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -15183,7 +15267,7 @@ func (x *SubmitPolicyAnalysisRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use SubmitPolicyAnalysisRequest.ProtoReflect.Descriptor instead. func (*SubmitPolicyAnalysisRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{190} + return file_openshell_proto_rawDescGZIP(), []int{191} } func (x *SubmitPolicyAnalysisRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -15246,7 +15330,7 @@ type SubmitPolicyAnalysisResponse struct { func (x *SubmitPolicyAnalysisResponse) Reset() { *x = SubmitPolicyAnalysisResponse{} - mi := &file_openshell_proto_msgTypes[191] + mi := &file_openshell_proto_msgTypes[192] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -15258,7 +15342,7 @@ func (x *SubmitPolicyAnalysisResponse) String() string { func (*SubmitPolicyAnalysisResponse) ProtoMessage() {} func (x *SubmitPolicyAnalysisResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[191] + mi := &file_openshell_proto_msgTypes[192] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -15271,7 +15355,7 @@ func (x *SubmitPolicyAnalysisResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use SubmitPolicyAnalysisResponse.ProtoReflect.Descriptor instead. func (*SubmitPolicyAnalysisResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{191} + return file_openshell_proto_rawDescGZIP(), []int{192} } func (x *SubmitPolicyAnalysisResponse) GetAcceptedChunks() uint32 { @@ -15316,7 +15400,7 @@ type GetDraftPolicyRequest struct { func (x *GetDraftPolicyRequest) Reset() { *x = GetDraftPolicyRequest{} - mi := &file_openshell_proto_msgTypes[192] + mi := &file_openshell_proto_msgTypes[193] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -15328,7 +15412,7 @@ func (x *GetDraftPolicyRequest) String() string { func (*GetDraftPolicyRequest) ProtoMessage() {} func (x *GetDraftPolicyRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[192] + mi := &file_openshell_proto_msgTypes[193] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -15341,7 +15425,7 @@ func (x *GetDraftPolicyRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use GetDraftPolicyRequest.ProtoReflect.Descriptor instead. func (*GetDraftPolicyRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{192} + return file_openshell_proto_rawDescGZIP(), []int{193} } func (x *GetDraftPolicyRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -15381,7 +15465,7 @@ type GetDraftPolicyResponse struct { func (x *GetDraftPolicyResponse) Reset() { *x = GetDraftPolicyResponse{} - mi := &file_openshell_proto_msgTypes[193] + mi := &file_openshell_proto_msgTypes[194] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -15393,7 +15477,7 @@ func (x *GetDraftPolicyResponse) String() string { func (*GetDraftPolicyResponse) ProtoMessage() {} func (x *GetDraftPolicyResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[193] + mi := &file_openshell_proto_msgTypes[194] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -15406,7 +15490,7 @@ func (x *GetDraftPolicyResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use GetDraftPolicyResponse.ProtoReflect.Descriptor instead. func (*GetDraftPolicyResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{193} + return file_openshell_proto_rawDescGZIP(), []int{194} } func (x *GetDraftPolicyResponse) GetChunks() []*PolicyChunk { @@ -15457,7 +15541,7 @@ type ApproveDraftChunkRequest struct { func (x *ApproveDraftChunkRequest) Reset() { *x = ApproveDraftChunkRequest{} - mi := &file_openshell_proto_msgTypes[194] + mi := &file_openshell_proto_msgTypes[195] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -15469,7 +15553,7 @@ func (x *ApproveDraftChunkRequest) String() string { func (*ApproveDraftChunkRequest) ProtoMessage() {} func (x *ApproveDraftChunkRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[194] + mi := &file_openshell_proto_msgTypes[195] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -15482,7 +15566,7 @@ func (x *ApproveDraftChunkRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use ApproveDraftChunkRequest.ProtoReflect.Descriptor instead. func (*ApproveDraftChunkRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{194} + return file_openshell_proto_rawDescGZIP(), []int{195} } func (x *ApproveDraftChunkRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -15532,7 +15616,7 @@ type ApproveDraftChunkResponse struct { func (x *ApproveDraftChunkResponse) Reset() { *x = ApproveDraftChunkResponse{} - mi := &file_openshell_proto_msgTypes[195] + mi := &file_openshell_proto_msgTypes[196] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -15544,7 +15628,7 @@ func (x *ApproveDraftChunkResponse) String() string { func (*ApproveDraftChunkResponse) ProtoMessage() {} func (x *ApproveDraftChunkResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[195] + mi := &file_openshell_proto_msgTypes[196] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -15557,7 +15641,7 @@ func (x *ApproveDraftChunkResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use ApproveDraftChunkResponse.ProtoReflect.Descriptor instead. func (*ApproveDraftChunkResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{195} + return file_openshell_proto_rawDescGZIP(), []int{196} } func (x *ApproveDraftChunkResponse) GetPolicyVersion() uint32 { @@ -15593,7 +15677,7 @@ type RejectDraftChunkRequest struct { func (x *RejectDraftChunkRequest) Reset() { *x = RejectDraftChunkRequest{} - mi := &file_openshell_proto_msgTypes[196] + mi := &file_openshell_proto_msgTypes[197] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -15605,7 +15689,7 @@ func (x *RejectDraftChunkRequest) String() string { func (*RejectDraftChunkRequest) ProtoMessage() {} func (x *RejectDraftChunkRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[196] + mi := &file_openshell_proto_msgTypes[197] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -15618,7 +15702,7 @@ func (x *RejectDraftChunkRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use RejectDraftChunkRequest.ProtoReflect.Descriptor instead. func (*RejectDraftChunkRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{196} + return file_openshell_proto_rawDescGZIP(), []int{197} } func (x *RejectDraftChunkRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -15664,7 +15748,7 @@ type RejectDraftChunkResponse struct { func (x *RejectDraftChunkResponse) Reset() { *x = RejectDraftChunkResponse{} - mi := &file_openshell_proto_msgTypes[197] + mi := &file_openshell_proto_msgTypes[198] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -15676,7 +15760,7 @@ func (x *RejectDraftChunkResponse) String() string { func (*RejectDraftChunkResponse) ProtoMessage() {} func (x *RejectDraftChunkResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[197] + mi := &file_openshell_proto_msgTypes[198] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -15689,7 +15773,7 @@ func (x *RejectDraftChunkResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use RejectDraftChunkResponse.ProtoReflect.Descriptor instead. func (*RejectDraftChunkResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{197} + return file_openshell_proto_rawDescGZIP(), []int{198} } // Approve all pending chunks. @@ -15703,7 +15787,7 @@ type DraftChunkApproval struct { func (x *DraftChunkApproval) Reset() { *x = DraftChunkApproval{} - mi := &file_openshell_proto_msgTypes[198] + mi := &file_openshell_proto_msgTypes[199] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -15715,7 +15799,7 @@ func (x *DraftChunkApproval) String() string { func (*DraftChunkApproval) ProtoMessage() {} func (x *DraftChunkApproval) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[198] + mi := &file_openshell_proto_msgTypes[199] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -15728,7 +15812,7 @@ func (x *DraftChunkApproval) ProtoReflect() protoreflect.Message { // Deprecated: Use DraftChunkApproval.ProtoReflect.Descriptor instead. func (*DraftChunkApproval) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{198} + return file_openshell_proto_rawDescGZIP(), []int{199} } func (x *DraftChunkApproval) GetChunkId() string { @@ -15764,7 +15848,7 @@ type ApproveAllDraftChunksRequest struct { func (x *ApproveAllDraftChunksRequest) Reset() { *x = ApproveAllDraftChunksRequest{} - mi := &file_openshell_proto_msgTypes[199] + mi := &file_openshell_proto_msgTypes[200] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -15776,7 +15860,7 @@ func (x *ApproveAllDraftChunksRequest) String() string { func (*ApproveAllDraftChunksRequest) ProtoMessage() {} func (x *ApproveAllDraftChunksRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[199] + mi := &file_openshell_proto_msgTypes[200] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -15789,7 +15873,7 @@ func (x *ApproveAllDraftChunksRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use ApproveAllDraftChunksRequest.ProtoReflect.Descriptor instead. func (*ApproveAllDraftChunksRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{199} + return file_openshell_proto_rawDescGZIP(), []int{200} } func (x *ApproveAllDraftChunksRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -15844,7 +15928,7 @@ type ApproveAllDraftChunksResponse struct { func (x *ApproveAllDraftChunksResponse) Reset() { *x = ApproveAllDraftChunksResponse{} - mi := &file_openshell_proto_msgTypes[200] + mi := &file_openshell_proto_msgTypes[201] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -15856,7 +15940,7 @@ func (x *ApproveAllDraftChunksResponse) String() string { func (*ApproveAllDraftChunksResponse) ProtoMessage() {} func (x *ApproveAllDraftChunksResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[200] + mi := &file_openshell_proto_msgTypes[201] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -15869,7 +15953,7 @@ func (x *ApproveAllDraftChunksResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use ApproveAllDraftChunksResponse.ProtoReflect.Descriptor instead. func (*ApproveAllDraftChunksResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{200} + return file_openshell_proto_rawDescGZIP(), []int{201} } func (x *ApproveAllDraftChunksResponse) GetPolicyVersion() uint32 { @@ -15919,7 +16003,7 @@ type EditDraftChunkRequest struct { func (x *EditDraftChunkRequest) Reset() { *x = EditDraftChunkRequest{} - mi := &file_openshell_proto_msgTypes[201] + mi := &file_openshell_proto_msgTypes[202] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -15931,7 +16015,7 @@ func (x *EditDraftChunkRequest) String() string { func (*EditDraftChunkRequest) ProtoMessage() {} func (x *EditDraftChunkRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[201] + mi := &file_openshell_proto_msgTypes[202] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -15944,7 +16028,7 @@ func (x *EditDraftChunkRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use EditDraftChunkRequest.ProtoReflect.Descriptor instead. func (*EditDraftChunkRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{201} + return file_openshell_proto_rawDescGZIP(), []int{202} } func (x *EditDraftChunkRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -15990,7 +16074,7 @@ type EditDraftChunkResponse struct { func (x *EditDraftChunkResponse) Reset() { *x = EditDraftChunkResponse{} - mi := &file_openshell_proto_msgTypes[202] + mi := &file_openshell_proto_msgTypes[203] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -16002,7 +16086,7 @@ func (x *EditDraftChunkResponse) String() string { func (*EditDraftChunkResponse) ProtoMessage() {} func (x *EditDraftChunkResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[202] + mi := &file_openshell_proto_msgTypes[203] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -16015,7 +16099,7 @@ func (x *EditDraftChunkResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use EditDraftChunkResponse.ProtoReflect.Descriptor instead. func (*EditDraftChunkResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{202} + return file_openshell_proto_rawDescGZIP(), []int{203} } // Reverse an approval (remove merged rule from active policy). @@ -16035,7 +16119,7 @@ type UndoDraftChunkRequest struct { func (x *UndoDraftChunkRequest) Reset() { *x = UndoDraftChunkRequest{} - mi := &file_openshell_proto_msgTypes[203] + mi := &file_openshell_proto_msgTypes[204] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -16047,7 +16131,7 @@ func (x *UndoDraftChunkRequest) String() string { func (*UndoDraftChunkRequest) ProtoMessage() {} func (x *UndoDraftChunkRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[203] + mi := &file_openshell_proto_msgTypes[204] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -16060,7 +16144,7 @@ func (x *UndoDraftChunkRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use UndoDraftChunkRequest.ProtoReflect.Descriptor instead. func (*UndoDraftChunkRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{203} + return file_openshell_proto_rawDescGZIP(), []int{204} } func (x *UndoDraftChunkRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -16103,7 +16187,7 @@ type UndoDraftChunkResponse struct { func (x *UndoDraftChunkResponse) Reset() { *x = UndoDraftChunkResponse{} - mi := &file_openshell_proto_msgTypes[204] + mi := &file_openshell_proto_msgTypes[205] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -16115,7 +16199,7 @@ func (x *UndoDraftChunkResponse) String() string { func (*UndoDraftChunkResponse) ProtoMessage() {} func (x *UndoDraftChunkResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[204] + mi := &file_openshell_proto_msgTypes[205] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -16128,7 +16212,7 @@ func (x *UndoDraftChunkResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use UndoDraftChunkResponse.ProtoReflect.Descriptor instead. func (*UndoDraftChunkResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{204} + return file_openshell_proto_rawDescGZIP(), []int{205} } func (x *UndoDraftChunkResponse) GetPolicyVersion() uint32 { @@ -16160,7 +16244,7 @@ type ClearDraftChunksRequest struct { func (x *ClearDraftChunksRequest) Reset() { *x = ClearDraftChunksRequest{} - mi := &file_openshell_proto_msgTypes[205] + mi := &file_openshell_proto_msgTypes[206] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -16172,7 +16256,7 @@ func (x *ClearDraftChunksRequest) String() string { func (*ClearDraftChunksRequest) ProtoMessage() {} func (x *ClearDraftChunksRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[205] + mi := &file_openshell_proto_msgTypes[206] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -16185,7 +16269,7 @@ func (x *ClearDraftChunksRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use ClearDraftChunksRequest.ProtoReflect.Descriptor instead. func (*ClearDraftChunksRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{205} + return file_openshell_proto_rawDescGZIP(), []int{206} } func (x *ClearDraftChunksRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -16219,7 +16303,7 @@ type ClearDraftChunksResponse struct { func (x *ClearDraftChunksResponse) Reset() { *x = ClearDraftChunksResponse{} - mi := &file_openshell_proto_msgTypes[206] + mi := &file_openshell_proto_msgTypes[207] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -16231,7 +16315,7 @@ func (x *ClearDraftChunksResponse) String() string { func (*ClearDraftChunksResponse) ProtoMessage() {} func (x *ClearDraftChunksResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[206] + mi := &file_openshell_proto_msgTypes[207] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -16244,7 +16328,7 @@ func (x *ClearDraftChunksResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use ClearDraftChunksResponse.ProtoReflect.Descriptor instead. func (*ClearDraftChunksResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{206} + return file_openshell_proto_rawDescGZIP(), []int{207} } func (x *ClearDraftChunksResponse) GetChunksCleared() uint32 { @@ -16266,7 +16350,7 @@ type GetDraftHistoryRequest struct { func (x *GetDraftHistoryRequest) Reset() { *x = GetDraftHistoryRequest{} - mi := &file_openshell_proto_msgTypes[207] + mi := &file_openshell_proto_msgTypes[208] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -16278,7 +16362,7 @@ func (x *GetDraftHistoryRequest) String() string { func (*GetDraftHistoryRequest) ProtoMessage() {} func (x *GetDraftHistoryRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[207] + mi := &file_openshell_proto_msgTypes[208] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -16291,7 +16375,7 @@ func (x *GetDraftHistoryRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use GetDraftHistoryRequest.ProtoReflect.Descriptor instead. func (*GetDraftHistoryRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{207} + return file_openshell_proto_rawDescGZIP(), []int{208} } func (x *GetDraftHistoryRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -16325,7 +16409,7 @@ type DraftHistoryEntry struct { func (x *DraftHistoryEntry) Reset() { *x = DraftHistoryEntry{} - mi := &file_openshell_proto_msgTypes[208] + mi := &file_openshell_proto_msgTypes[209] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -16337,7 +16421,7 @@ func (x *DraftHistoryEntry) String() string { func (*DraftHistoryEntry) ProtoMessage() {} func (x *DraftHistoryEntry) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[208] + mi := &file_openshell_proto_msgTypes[209] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -16350,7 +16434,7 @@ func (x *DraftHistoryEntry) ProtoReflect() protoreflect.Message { // Deprecated: Use DraftHistoryEntry.ProtoReflect.Descriptor instead. func (*DraftHistoryEntry) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{208} + return file_openshell_proto_rawDescGZIP(), []int{209} } func (x *DraftHistoryEntry) GetEventTime() *timestamppb.Timestamp { @@ -16391,7 +16475,7 @@ type GetDraftHistoryResponse struct { func (x *GetDraftHistoryResponse) Reset() { *x = GetDraftHistoryResponse{} - mi := &file_openshell_proto_msgTypes[209] + mi := &file_openshell_proto_msgTypes[210] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -16403,7 +16487,7 @@ func (x *GetDraftHistoryResponse) String() string { func (*GetDraftHistoryResponse) ProtoMessage() {} func (x *GetDraftHistoryResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[209] + mi := &file_openshell_proto_msgTypes[210] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -16416,7 +16500,7 @@ func (x *GetDraftHistoryResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use GetDraftHistoryResponse.ProtoReflect.Descriptor instead. func (*GetDraftHistoryResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{209} + return file_openshell_proto_rawDescGZIP(), []int{210} } func (x *GetDraftHistoryResponse) GetEntries() []*DraftHistoryEntry { @@ -16441,7 +16525,7 @@ type CreateWorkspaceRequest struct { func (x *CreateWorkspaceRequest) Reset() { *x = CreateWorkspaceRequest{} - mi := &file_openshell_proto_msgTypes[210] + mi := &file_openshell_proto_msgTypes[211] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -16453,7 +16537,7 @@ func (x *CreateWorkspaceRequest) String() string { func (*CreateWorkspaceRequest) ProtoMessage() {} func (x *CreateWorkspaceRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[210] + mi := &file_openshell_proto_msgTypes[211] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -16466,7 +16550,7 @@ func (x *CreateWorkspaceRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use CreateWorkspaceRequest.ProtoReflect.Descriptor instead. func (*CreateWorkspaceRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{210} + return file_openshell_proto_rawDescGZIP(), []int{211} } func (x *CreateWorkspaceRequest) GetName() string { @@ -16500,7 +16584,7 @@ type CreateWorkspaceResponse struct { func (x *CreateWorkspaceResponse) Reset() { *x = CreateWorkspaceResponse{} - mi := &file_openshell_proto_msgTypes[211] + mi := &file_openshell_proto_msgTypes[212] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -16512,7 +16596,7 @@ func (x *CreateWorkspaceResponse) String() string { func (*CreateWorkspaceResponse) ProtoMessage() {} func (x *CreateWorkspaceResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[211] + mi := &file_openshell_proto_msgTypes[212] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -16525,7 +16609,7 @@ func (x *CreateWorkspaceResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use CreateWorkspaceResponse.ProtoReflect.Descriptor instead. func (*CreateWorkspaceResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{211} + return file_openshell_proto_rawDescGZIP(), []int{212} } func (x *CreateWorkspaceResponse) GetWorkspace() *datamodelv1.Workspace { @@ -16546,7 +16630,7 @@ type GetWorkspaceRequest struct { func (x *GetWorkspaceRequest) Reset() { *x = GetWorkspaceRequest{} - mi := &file_openshell_proto_msgTypes[212] + mi := &file_openshell_proto_msgTypes[213] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -16558,7 +16642,7 @@ func (x *GetWorkspaceRequest) String() string { func (*GetWorkspaceRequest) ProtoMessage() {} func (x *GetWorkspaceRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[212] + mi := &file_openshell_proto_msgTypes[213] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -16571,7 +16655,7 @@ func (x *GetWorkspaceRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use GetWorkspaceRequest.ProtoReflect.Descriptor instead. func (*GetWorkspaceRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{212} + return file_openshell_proto_rawDescGZIP(), []int{213} } func (x *GetWorkspaceRequest) GetName() string { @@ -16591,7 +16675,7 @@ type GetWorkspaceResponse struct { func (x *GetWorkspaceResponse) Reset() { *x = GetWorkspaceResponse{} - mi := &file_openshell_proto_msgTypes[213] + mi := &file_openshell_proto_msgTypes[214] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -16603,7 +16687,7 @@ func (x *GetWorkspaceResponse) String() string { func (*GetWorkspaceResponse) ProtoMessage() {} func (x *GetWorkspaceResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[213] + mi := &file_openshell_proto_msgTypes[214] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -16616,7 +16700,7 @@ func (x *GetWorkspaceResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use GetWorkspaceResponse.ProtoReflect.Descriptor instead. func (*GetWorkspaceResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{213} + return file_openshell_proto_rawDescGZIP(), []int{214} } func (x *GetWorkspaceResponse) GetWorkspace() *datamodelv1.Workspace { @@ -16643,7 +16727,7 @@ type ListWorkspacesRequest struct { func (x *ListWorkspacesRequest) Reset() { *x = ListWorkspacesRequest{} - mi := &file_openshell_proto_msgTypes[214] + mi := &file_openshell_proto_msgTypes[215] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -16655,7 +16739,7 @@ func (x *ListWorkspacesRequest) String() string { func (*ListWorkspacesRequest) ProtoMessage() {} func (x *ListWorkspacesRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[214] + mi := &file_openshell_proto_msgTypes[215] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -16668,7 +16752,7 @@ func (x *ListWorkspacesRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use ListWorkspacesRequest.ProtoReflect.Descriptor instead. func (*ListWorkspacesRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{214} + return file_openshell_proto_rawDescGZIP(), []int{215} } func (x *ListWorkspacesRequest) GetPageSize() int32 { @@ -16704,7 +16788,7 @@ type ListWorkspacesResponse struct { func (x *ListWorkspacesResponse) Reset() { *x = ListWorkspacesResponse{} - mi := &file_openshell_proto_msgTypes[215] + mi := &file_openshell_proto_msgTypes[216] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -16716,7 +16800,7 @@ func (x *ListWorkspacesResponse) String() string { func (*ListWorkspacesResponse) ProtoMessage() {} func (x *ListWorkspacesResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[215] + mi := &file_openshell_proto_msgTypes[216] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -16729,7 +16813,7 @@ func (x *ListWorkspacesResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use ListWorkspacesResponse.ProtoReflect.Descriptor instead. func (*ListWorkspacesResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{215} + return file_openshell_proto_rawDescGZIP(), []int{216} } func (x *ListWorkspacesResponse) GetWorkspaces() []*datamodelv1.Workspace { @@ -16760,7 +16844,7 @@ type DeleteWorkspaceRequest struct { func (x *DeleteWorkspaceRequest) Reset() { *x = DeleteWorkspaceRequest{} - mi := &file_openshell_proto_msgTypes[216] + mi := &file_openshell_proto_msgTypes[217] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -16772,7 +16856,7 @@ func (x *DeleteWorkspaceRequest) String() string { func (*DeleteWorkspaceRequest) ProtoMessage() {} func (x *DeleteWorkspaceRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[216] + mi := &file_openshell_proto_msgTypes[217] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -16785,7 +16869,7 @@ func (x *DeleteWorkspaceRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use DeleteWorkspaceRequest.ProtoReflect.Descriptor instead. func (*DeleteWorkspaceRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{216} + return file_openshell_proto_rawDescGZIP(), []int{217} } func (x *DeleteWorkspaceRequest) GetName() string { @@ -16819,7 +16903,7 @@ type DeleteWorkspaceResponse struct { func (x *DeleteWorkspaceResponse) Reset() { *x = DeleteWorkspaceResponse{} - mi := &file_openshell_proto_msgTypes[217] + mi := &file_openshell_proto_msgTypes[218] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -16831,7 +16915,7 @@ func (x *DeleteWorkspaceResponse) String() string { func (*DeleteWorkspaceResponse) ProtoMessage() {} func (x *DeleteWorkspaceResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[217] + mi := &file_openshell_proto_msgTypes[218] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -16844,7 +16928,7 @@ func (x *DeleteWorkspaceResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use DeleteWorkspaceResponse.ProtoReflect.Descriptor instead. func (*DeleteWorkspaceResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{217} + return file_openshell_proto_rawDescGZIP(), []int{218} } func (x *DeleteWorkspaceResponse) GetOutcome() DeletionOutcome { @@ -16868,7 +16952,7 @@ type WorkspaceMember struct { func (x *WorkspaceMember) Reset() { *x = WorkspaceMember{} - mi := &file_openshell_proto_msgTypes[218] + mi := &file_openshell_proto_msgTypes[219] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -16880,7 +16964,7 @@ func (x *WorkspaceMember) String() string { func (*WorkspaceMember) ProtoMessage() {} func (x *WorkspaceMember) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[218] + mi := &file_openshell_proto_msgTypes[219] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -16893,7 +16977,7 @@ func (x *WorkspaceMember) ProtoReflect() protoreflect.Message { // Deprecated: Use WorkspaceMember.ProtoReflect.Descriptor instead. func (*WorkspaceMember) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{218} + return file_openshell_proto_rawDescGZIP(), []int{219} } func (x *WorkspaceMember) GetMetadata() *datamodelv1.ObjectMeta { @@ -16934,7 +17018,7 @@ type AddWorkspaceMemberRequest struct { func (x *AddWorkspaceMemberRequest) Reset() { *x = AddWorkspaceMemberRequest{} - mi := &file_openshell_proto_msgTypes[219] + mi := &file_openshell_proto_msgTypes[220] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -16946,7 +17030,7 @@ func (x *AddWorkspaceMemberRequest) String() string { func (*AddWorkspaceMemberRequest) ProtoMessage() {} func (x *AddWorkspaceMemberRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[219] + mi := &file_openshell_proto_msgTypes[220] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -16959,7 +17043,7 @@ func (x *AddWorkspaceMemberRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use AddWorkspaceMemberRequest.ProtoReflect.Descriptor instead. func (*AddWorkspaceMemberRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{219} + return file_openshell_proto_rawDescGZIP(), []int{220} } func (x *AddWorkspaceMemberRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -17000,7 +17084,7 @@ type AddWorkspaceMemberResponse struct { func (x *AddWorkspaceMemberResponse) Reset() { *x = AddWorkspaceMemberResponse{} - mi := &file_openshell_proto_msgTypes[220] + mi := &file_openshell_proto_msgTypes[221] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -17012,7 +17096,7 @@ func (x *AddWorkspaceMemberResponse) String() string { func (*AddWorkspaceMemberResponse) ProtoMessage() {} func (x *AddWorkspaceMemberResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[220] + mi := &file_openshell_proto_msgTypes[221] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -17025,7 +17109,7 @@ func (x *AddWorkspaceMemberResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use AddWorkspaceMemberResponse.ProtoReflect.Descriptor instead. func (*AddWorkspaceMemberResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{220} + return file_openshell_proto_rawDescGZIP(), []int{221} } func (x *AddWorkspaceMemberResponse) GetMember() *WorkspaceMember { @@ -17051,7 +17135,7 @@ type RemoveWorkspaceMemberRequest struct { func (x *RemoveWorkspaceMemberRequest) Reset() { *x = RemoveWorkspaceMemberRequest{} - mi := &file_openshell_proto_msgTypes[221] + mi := &file_openshell_proto_msgTypes[222] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -17063,7 +17147,7 @@ func (x *RemoveWorkspaceMemberRequest) String() string { func (*RemoveWorkspaceMemberRequest) ProtoMessage() {} func (x *RemoveWorkspaceMemberRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[221] + mi := &file_openshell_proto_msgTypes[222] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -17076,7 +17160,7 @@ func (x *RemoveWorkspaceMemberRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use RemoveWorkspaceMemberRequest.ProtoReflect.Descriptor instead. func (*RemoveWorkspaceMemberRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{221} + return file_openshell_proto_rawDescGZIP(), []int{222} } func (x *RemoveWorkspaceMemberRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -17117,7 +17201,7 @@ type RemoveWorkspaceMemberResponse struct { func (x *RemoveWorkspaceMemberResponse) Reset() { *x = RemoveWorkspaceMemberResponse{} - mi := &file_openshell_proto_msgTypes[222] + mi := &file_openshell_proto_msgTypes[223] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -17129,7 +17213,7 @@ func (x *RemoveWorkspaceMemberResponse) String() string { func (*RemoveWorkspaceMemberResponse) ProtoMessage() {} func (x *RemoveWorkspaceMemberResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[222] + mi := &file_openshell_proto_msgTypes[223] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -17142,7 +17226,7 @@ func (x *RemoveWorkspaceMemberResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use RemoveWorkspaceMemberResponse.ProtoReflect.Descriptor instead. func (*RemoveWorkspaceMemberResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{222} + return file_openshell_proto_rawDescGZIP(), []int{223} } func (x *RemoveWorkspaceMemberResponse) GetOutcome() DeletionOutcome { @@ -17169,7 +17253,7 @@ type ListWorkspaceMembersRequest struct { func (x *ListWorkspaceMembersRequest) Reset() { *x = ListWorkspaceMembersRequest{} - mi := &file_openshell_proto_msgTypes[223] + mi := &file_openshell_proto_msgTypes[224] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -17181,7 +17265,7 @@ func (x *ListWorkspaceMembersRequest) String() string { func (*ListWorkspaceMembersRequest) ProtoMessage() {} func (x *ListWorkspaceMembersRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[223] + mi := &file_openshell_proto_msgTypes[224] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -17194,7 +17278,7 @@ func (x *ListWorkspaceMembersRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use ListWorkspaceMembersRequest.ProtoReflect.Descriptor instead. func (*ListWorkspaceMembersRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{223} + return file_openshell_proto_rawDescGZIP(), []int{224} } func (x *ListWorkspaceMembersRequest) GetWorkspaceScope() *datamodelv1.WorkspaceSelector { @@ -17230,7 +17314,7 @@ type ListWorkspaceMembersResponse struct { func (x *ListWorkspaceMembersResponse) Reset() { *x = ListWorkspaceMembersResponse{} - mi := &file_openshell_proto_msgTypes[224] + mi := &file_openshell_proto_msgTypes[225] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -17242,7 +17326,7 @@ func (x *ListWorkspaceMembersResponse) String() string { func (*ListWorkspaceMembersResponse) ProtoMessage() {} func (x *ListWorkspaceMembersResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[224] + mi := &file_openshell_proto_msgTypes[225] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -17255,7 +17339,7 @@ func (x *ListWorkspaceMembersResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use ListWorkspaceMembersResponse.ProtoReflect.Descriptor instead. func (*ListWorkspaceMembersResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{224} + return file_openshell_proto_rawDescGZIP(), []int{225} } func (x *ListWorkspaceMembersResponse) GetMembers() []*WorkspaceMember { @@ -17290,7 +17374,7 @@ type ExtensionServiceCredential struct { func (x *ExtensionServiceCredential) Reset() { *x = ExtensionServiceCredential{} - mi := &file_openshell_proto_msgTypes[225] + mi := &file_openshell_proto_msgTypes[226] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -17302,7 +17386,7 @@ func (x *ExtensionServiceCredential) String() string { func (*ExtensionServiceCredential) ProtoMessage() {} func (x *ExtensionServiceCredential) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[225] + mi := &file_openshell_proto_msgTypes[226] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -17315,7 +17399,7 @@ func (x *ExtensionServiceCredential) ProtoReflect() protoreflect.Message { // Deprecated: Use ExtensionServiceCredential.ProtoReflect.Descriptor instead. func (*ExtensionServiceCredential) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{225} + return file_openshell_proto_rawDescGZIP(), []int{226} } func (x *ExtensionServiceCredential) GetServiceName() string { @@ -17352,7 +17436,7 @@ type EndpointObservation struct { func (x *EndpointObservation) Reset() { *x = EndpointObservation{} - mi := &file_openshell_proto_msgTypes[226] + mi := &file_openshell_proto_msgTypes[227] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -17364,7 +17448,7 @@ func (x *EndpointObservation) String() string { func (*EndpointObservation) ProtoMessage() {} func (x *EndpointObservation) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[226] + mi := &file_openshell_proto_msgTypes[227] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -17377,7 +17461,7 @@ func (x *EndpointObservation) ProtoReflect() protoreflect.Message { // Deprecated: Use EndpointObservation.ProtoReflect.Descriptor instead. func (*EndpointObservation) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{226} + return file_openshell_proto_rawDescGZIP(), []int{227} } func (x *EndpointObservation) GetEndpointId() string { @@ -17420,7 +17504,7 @@ type ReportEndpointStatusRequest struct { func (x *ReportEndpointStatusRequest) Reset() { *x = ReportEndpointStatusRequest{} - mi := &file_openshell_proto_msgTypes[227] + mi := &file_openshell_proto_msgTypes[228] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -17432,7 +17516,7 @@ func (x *ReportEndpointStatusRequest) String() string { func (*ReportEndpointStatusRequest) ProtoMessage() {} func (x *ReportEndpointStatusRequest) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[227] + mi := &file_openshell_proto_msgTypes[228] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -17445,7 +17529,7 @@ func (x *ReportEndpointStatusRequest) ProtoReflect() protoreflect.Message { // Deprecated: Use ReportEndpointStatusRequest.ProtoReflect.Descriptor instead. func (*ReportEndpointStatusRequest) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{227} + return file_openshell_proto_rawDescGZIP(), []int{228} } func (x *ReportEndpointStatusRequest) GetSandboxId() string { @@ -17506,7 +17590,7 @@ type ReportEndpointStatusResponse struct { func (x *ReportEndpointStatusResponse) Reset() { *x = ReportEndpointStatusResponse{} - mi := &file_openshell_proto_msgTypes[228] + mi := &file_openshell_proto_msgTypes[229] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -17518,7 +17602,7 @@ func (x *ReportEndpointStatusResponse) String() string { func (*ReportEndpointStatusResponse) ProtoMessage() {} func (x *ReportEndpointStatusResponse) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[228] + mi := &file_openshell_proto_msgTypes[229] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -17531,7 +17615,7 @@ func (x *ReportEndpointStatusResponse) ProtoReflect() protoreflect.Message { // Deprecated: Use ReportEndpointStatusResponse.ProtoReflect.Descriptor instead. func (*ReportEndpointStatusResponse) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{228} + return file_openshell_proto_rawDescGZIP(), []int{229} } // A configured endpoint and its last accepted network result in one record. @@ -17560,7 +17644,7 @@ type EndpointStatus struct { func (x *EndpointStatus) Reset() { *x = EndpointStatus{} - mi := &file_openshell_proto_msgTypes[229] + mi := &file_openshell_proto_msgTypes[230] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -17572,7 +17656,7 @@ func (x *EndpointStatus) String() string { func (*EndpointStatus) ProtoMessage() {} func (x *EndpointStatus) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[229] + mi := &file_openshell_proto_msgTypes[230] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -17585,7 +17669,7 @@ func (x *EndpointStatus) ProtoReflect() protoreflect.Message { // Deprecated: Use EndpointStatus.ProtoReflect.Descriptor instead. func (*EndpointStatus) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{229} + return file_openshell_proto_rawDescGZIP(), []int{230} } func (x *EndpointStatus) GetEndpointId() string { @@ -17655,7 +17739,7 @@ type SandboxProvisioning struct { func (x *SandboxProvisioning) Reset() { *x = SandboxProvisioning{} - mi := &file_openshell_proto_msgTypes[230] + mi := &file_openshell_proto_msgTypes[231] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -17667,7 +17751,7 @@ func (x *SandboxProvisioning) String() string { func (*SandboxProvisioning) ProtoMessage() {} func (x *SandboxProvisioning) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[230] + mi := &file_openshell_proto_msgTypes[231] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -17680,7 +17764,7 @@ func (x *SandboxProvisioning) ProtoReflect() protoreflect.Message { // Deprecated: Use SandboxProvisioning.ProtoReflect.Descriptor instead. func (*SandboxProvisioning) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{230} + return file_openshell_proto_rawDescGZIP(), []int{231} } func (x *SandboxProvisioning) GetAttemptId() string { @@ -17775,7 +17859,7 @@ type SandboxServiceExposure struct { func (x *SandboxServiceExposure) Reset() { *x = SandboxServiceExposure{} - mi := &file_openshell_proto_msgTypes[231] + mi := &file_openshell_proto_msgTypes[232] ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) ms.StoreMessageInfo(mi) } @@ -17787,7 +17871,7 @@ func (x *SandboxServiceExposure) String() string { func (*SandboxServiceExposure) ProtoMessage() {} func (x *SandboxServiceExposure) ProtoReflect() protoreflect.Message { - mi := &file_openshell_proto_msgTypes[231] + mi := &file_openshell_proto_msgTypes[232] if x != nil { ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) if ms.LoadMessageInfo() == nil { @@ -17800,7 +17884,7 @@ func (x *SandboxServiceExposure) ProtoReflect() protoreflect.Message { // Deprecated: Use SandboxServiceExposure.ProtoReflect.Descriptor instead. func (*SandboxServiceExposure) Descriptor() ([]byte, []int) { - return file_openshell_proto_rawDescGZIP(), []int{231} + return file_openshell_proto_rawDescGZIP(), []int{232} } func (x *SandboxServiceExposure) GetService() string { @@ -18507,9 +18591,20 @@ const file_openshell_proto_rawDesc = "" + " \x01(\x0e25.openshell.v1.ProviderCredentialRefreshRecoveryActionR\x0erecoveryAction\x12!\n" + "\ffailure_code\x18\v \x01(\tR\vfailureCode\x124\n" + "\x16provider_error_subtype\x18\f \x01(\tR\x14providerErrorSubtype\x12B\n" + - "\x0flast_error_time\x18q \x01(\v2\x1a.google.protobuf.TimestampR\rlastErrorTimeJ\x04\b\x06\x10\aJ\x04\b\a\x10\bJ\x04\b\b\x10\tJ\x04\b\r\x10\x0eR\rexpires_at_msR\x12next_refresh_at_msR\x12last_refresh_at_msR\x10last_error_at_ms\"<\n" + + "\x0flast_error_time\x18q \x01(\v2\x1a.google.protobuf.TimestampR\rlastErrorTimeJ\x04\b\x06\x10\aJ\x04\b\a\x10\bJ\x04\b\b\x10\tJ\x04\b\r\x10\x0eR\rexpires_at_msR\x12next_refresh_at_msR\x12last_refresh_at_msR\x10last_error_at_ms\"d\n" + "\x18ProviderProfileDiscovery\x12 \n" + - "\vcredentials\x18\x01 \x03(\tR\vcredentials\"\xb8\x01\n" + + "\vcredentials\x18\x01 \x03(\tR\vcredentials\x12&\n" + + "\x0fconfig_env_vars\x18\x02 \x03(\tR\rconfigEnvVars\"\xaa\x02\n" + + "\x1aProviderProfileEnvironment\x12L\n" + + "\x06config\x18\x01 \x03(\v24.openshell.v1.ProviderProfileEnvironment.ConfigEntryR\x06config\x12I\n" + + "\x05fixed\x18\x02 \x03(\v23.openshell.v1.ProviderProfileEnvironment.FixedEntryR\x05fixed\x1a9\n" + + "\vConfigEntry\x12\x10\n" + + "\x03key\x18\x01 \x01(\tR\x03key\x12\x14\n" + + "\x05value\x18\x02 \x01(\tR\x05value:\x028\x01\x1a8\n" + + "\n" + + "FixedEntry\x12\x10\n" + + "\x03key\x18\x01 \x01(\tR\x03key\x12\x14\n" + + "\x05value\x18\x02 \x01(\tR\x05value:\x028\x01\"\xb8\x01\n" + "\x1fGetProviderRefreshStatusRequest\x12R\n" + "\x0fworkspace_scope\x18\x03 \x01(\v2).openshell.datamodel.v1.WorkspaceSelectorR\x0eworkspaceScope\x12\x1a\n" + "\bprovider\x18\x01 \x01(\tR\bprovider\x12%\n" + @@ -18547,7 +18642,7 @@ const file_openshell_proto_rawDesc = "" + "\n" + "request_id\x18\x06 \x01(\tR\trequestId\"g\n" + "\x1dDeleteProviderRefreshResponse\x127\n" + - "\aoutcome\x18\x02 \x01(\x0e2\x1d.openshell.v1.DeletionOutcomeR\aoutcomeJ\x04\b\x01\x10\x02R\adeleted\"\x91\x06\n" + + "\aoutcome\x18\x02 \x01(\x0e2\x1d.openshell.v1.DeletionOutcomeR\aoutcomeJ\x04\b\x01\x10\x02R\adeleted\"\x99\a\n" + "\x0fProviderProfile\x12\x0e\n" + "\x02id\x18\x01 \x01(\tR\x02id\x12!\n" + "\fdisplay_name\x18\x02 \x01(\tR\vdisplayName\x12 \n" + @@ -18563,7 +18658,9 @@ const file_openshell_proto_rawDesc = "" + "\vannotations\x18\v \x03(\v2..openshell.v1.ProviderProfile.AnnotationsEntryR\vannotations\x12\x16\n" + "\x06source\x18\f \x01(\tR\x06source\x12\x14\n" + "\x05scope\x18\r \x01(\tR\x05scope\x127\n" + - "\x05files\x18\x0e \x03(\v2!.openshell.v1.ProviderProfileFileR\x05files\x1a>\n" + + "\x05files\x18\x0e \x03(\v2!.openshell.v1.ProviderProfileFileR\x05files\x12J\n" + + "\venvironment\x18\x0f \x01(\v2(.openshell.v1.ProviderProfileEnvironmentR\venvironment\x12:\n" + + "\x19required_platform_adapter\x18\x10 \x01(\tR\x17requiredPlatformAdapter\x1a>\n" + "\x10AnnotationsEntry\x12\x10\n" + "\x03key\x18\x01 \x01(\tR\x03key\x12\x14\n" + "\x05value\x18\x02 \x01(\tR\x05value:\x028\x01\"\\\n" + @@ -19491,7 +19588,7 @@ func file_openshell_proto_rawDescGZIP() []byte { } var file_openshell_proto_enumTypes = make([]protoimpl.EnumInfo, 20) -var file_openshell_proto_msgTypes = make([]protoimpl.MessageInfo, 255) +var file_openshell_proto_msgTypes = make([]protoimpl.MessageInfo, 258) var file_openshell_proto_goTypes = []any{ (ExtensionKind)(0), // 0: openshell.v1.ExtensionKind (SandboxPhase)(0), // 1: openshell.v1.SandboxPhase @@ -19626,173 +19723,176 @@ var file_openshell_proto_goTypes = []any{ (*ProviderCredentialRefresh)(nil), // 130: openshell.v1.ProviderCredentialRefresh (*ProviderCredentialRefreshStatus)(nil), // 131: openshell.v1.ProviderCredentialRefreshStatus (*ProviderProfileDiscovery)(nil), // 132: openshell.v1.ProviderProfileDiscovery - (*GetProviderRefreshStatusRequest)(nil), // 133: openshell.v1.GetProviderRefreshStatusRequest - (*GetProviderRefreshStatusResponse)(nil), // 134: openshell.v1.GetProviderRefreshStatusResponse - (*ConfigureProviderRefreshRequest)(nil), // 135: openshell.v1.ConfigureProviderRefreshRequest - (*ConfigureProviderRefreshResponse)(nil), // 136: openshell.v1.ConfigureProviderRefreshResponse - (*RotateProviderCredentialRequest)(nil), // 137: openshell.v1.RotateProviderCredentialRequest - (*RotateProviderCredentialResponse)(nil), // 138: openshell.v1.RotateProviderCredentialResponse - (*DeleteProviderRefreshRequest)(nil), // 139: openshell.v1.DeleteProviderRefreshRequest - (*DeleteProviderRefreshResponse)(nil), // 140: openshell.v1.DeleteProviderRefreshResponse - (*ProviderProfile)(nil), // 141: openshell.v1.ProviderProfile - (*ProviderProfileFile)(nil), // 142: openshell.v1.ProviderProfileFile - (*ProviderProfileResponse)(nil), // 143: openshell.v1.ProviderProfileResponse - (*ListProviderProfilesResponse)(nil), // 144: openshell.v1.ListProviderProfilesResponse - (*ImportProviderProfilesRequest)(nil), // 145: openshell.v1.ImportProviderProfilesRequest - (*ImportProviderProfilesResponse)(nil), // 146: openshell.v1.ImportProviderProfilesResponse - (*UpdateProviderProfilesRequest)(nil), // 147: openshell.v1.UpdateProviderProfilesRequest - (*UpdateProviderProfilesResponse)(nil), // 148: openshell.v1.UpdateProviderProfilesResponse - (*LintProviderProfilesRequest)(nil), // 149: openshell.v1.LintProviderProfilesRequest - (*LintProviderProfilesResponse)(nil), // 150: openshell.v1.LintProviderProfilesResponse - (*DeleteProviderResponse)(nil), // 151: openshell.v1.DeleteProviderResponse - (*DeleteProviderProfileRequest)(nil), // 152: openshell.v1.DeleteProviderProfileRequest - (*DeleteProviderProfileResponse)(nil), // 153: openshell.v1.DeleteProviderProfileResponse - (*GetSandboxProviderEnvironmentRequest)(nil), // 154: openshell.v1.GetSandboxProviderEnvironmentRequest - (*StaticCredentialEndpointBinding)(nil), // 155: openshell.v1.StaticCredentialEndpointBinding - (*StaticCredentialBinding)(nil), // 156: openshell.v1.StaticCredentialBinding - (*GetSandboxProviderEnvironmentResponse)(nil), // 157: openshell.v1.GetSandboxProviderEnvironmentResponse - (*ExchangeProviderSubjectTokenRequest)(nil), // 158: openshell.v1.ExchangeProviderSubjectTokenRequest - (*ExchangeProviderSubjectTokenResponse)(nil), // 159: openshell.v1.ExchangeProviderSubjectTokenResponse - (*UpdateConfigRequest)(nil), // 160: openshell.v1.UpdateConfigRequest - (*PolicyMergeOperation)(nil), // 161: openshell.v1.PolicyMergeOperation - (*AddNetworkRule)(nil), // 162: openshell.v1.AddNetworkRule - (*RemoveNetworkEndpoint)(nil), // 163: openshell.v1.RemoveNetworkEndpoint - (*RemoveNetworkRule)(nil), // 164: openshell.v1.RemoveNetworkRule - (*L7RuleTarget)(nil), // 165: openshell.v1.L7RuleTarget - (*AddDenyRules)(nil), // 166: openshell.v1.AddDenyRules - (*AddAllowRules)(nil), // 167: openshell.v1.AddAllowRules - (*RemoveNetworkBinary)(nil), // 168: openshell.v1.RemoveNetworkBinary - (*UpdateConfigResponse)(nil), // 169: openshell.v1.UpdateConfigResponse - (*GetSandboxPolicyStatusRequest)(nil), // 170: openshell.v1.GetSandboxPolicyStatusRequest - (*GetSandboxPolicyStatusResponse)(nil), // 171: openshell.v1.GetSandboxPolicyStatusResponse - (*ListSandboxPoliciesRequest)(nil), // 172: openshell.v1.ListSandboxPoliciesRequest - (*ListSandboxPoliciesResponse)(nil), // 173: openshell.v1.ListSandboxPoliciesResponse - (*ReportPolicyStatusRequest)(nil), // 174: openshell.v1.ReportPolicyStatusRequest - (*ReportPolicyStatusResponse)(nil), // 175: openshell.v1.ReportPolicyStatusResponse - (*SandboxConfigurationAdmission)(nil), // 176: openshell.v1.SandboxConfigurationAdmission - (*ReportSandboxConfigurationRequest)(nil), // 177: openshell.v1.ReportSandboxConfigurationRequest - (*ReportSandboxConfigurationResponse)(nil), // 178: openshell.v1.ReportSandboxConfigurationResponse - (*SandboxPolicyRevision)(nil), // 179: openshell.v1.SandboxPolicyRevision - (*GetSandboxLogsRequest)(nil), // 180: openshell.v1.GetSandboxLogsRequest - (*PushSandboxLogsRequest)(nil), // 181: openshell.v1.PushSandboxLogsRequest - (*PushSandboxLogsResponse)(nil), // 182: openshell.v1.PushSandboxLogsResponse - (*GetSandboxLogsResponse)(nil), // 183: openshell.v1.GetSandboxLogsResponse - (*SupervisorMessage)(nil), // 184: openshell.v1.SupervisorMessage - (*GatewayMessage)(nil), // 185: openshell.v1.GatewayMessage - (*SupervisorHello)(nil), // 186: openshell.v1.SupervisorHello - (*SessionAccepted)(nil), // 187: openshell.v1.SessionAccepted - (*SessionRejected)(nil), // 188: openshell.v1.SessionRejected - (*SupervisorHeartbeat)(nil), // 189: openshell.v1.SupervisorHeartbeat - (*GatewayHeartbeat)(nil), // 190: openshell.v1.GatewayHeartbeat - (*ReportMainProcessExitRequest)(nil), // 191: openshell.v1.ReportMainProcessExitRequest - (*ReportMainProcessExitResponse)(nil), // 192: openshell.v1.ReportMainProcessExitResponse - (*FinalizeMainProcessExitRequest)(nil), // 193: openshell.v1.FinalizeMainProcessExitRequest - (*FinalizeMainProcessExitResponse)(nil), // 194: openshell.v1.FinalizeMainProcessExitResponse - (*RelayOpen)(nil), // 195: openshell.v1.RelayOpen - (*SshRelayTarget)(nil), // 196: openshell.v1.SshRelayTarget - (*TcpRelayTarget)(nil), // 197: openshell.v1.TcpRelayTarget - (*RelayInit)(nil), // 198: openshell.v1.RelayInit - (*RelayFrame)(nil), // 199: openshell.v1.RelayFrame - (*PeerRelayInit)(nil), // 200: openshell.v1.PeerRelayInit - (*PeerRelayFrame)(nil), // 201: openshell.v1.PeerRelayFrame - (*RelayOpenResult)(nil), // 202: openshell.v1.RelayOpenResult - (*RelayClose)(nil), // 203: openshell.v1.RelayClose - (*L7RequestSample)(nil), // 204: openshell.v1.L7RequestSample - (*DenialSummary)(nil), // 205: openshell.v1.DenialSummary - (*DenialGroupCount)(nil), // 206: openshell.v1.DenialGroupCount - (*NetworkActivitySummary)(nil), // 207: openshell.v1.NetworkActivitySummary - (*PolicyChunk)(nil), // 208: openshell.v1.PolicyChunk - (*DraftPolicyUpdate)(nil), // 209: openshell.v1.DraftPolicyUpdate - (*SubmitPolicyAnalysisRequest)(nil), // 210: openshell.v1.SubmitPolicyAnalysisRequest - (*SubmitPolicyAnalysisResponse)(nil), // 211: openshell.v1.SubmitPolicyAnalysisResponse - (*GetDraftPolicyRequest)(nil), // 212: openshell.v1.GetDraftPolicyRequest - (*GetDraftPolicyResponse)(nil), // 213: openshell.v1.GetDraftPolicyResponse - (*ApproveDraftChunkRequest)(nil), // 214: openshell.v1.ApproveDraftChunkRequest - (*ApproveDraftChunkResponse)(nil), // 215: openshell.v1.ApproveDraftChunkResponse - (*RejectDraftChunkRequest)(nil), // 216: openshell.v1.RejectDraftChunkRequest - (*RejectDraftChunkResponse)(nil), // 217: openshell.v1.RejectDraftChunkResponse - (*DraftChunkApproval)(nil), // 218: openshell.v1.DraftChunkApproval - (*ApproveAllDraftChunksRequest)(nil), // 219: openshell.v1.ApproveAllDraftChunksRequest - (*ApproveAllDraftChunksResponse)(nil), // 220: openshell.v1.ApproveAllDraftChunksResponse - (*EditDraftChunkRequest)(nil), // 221: openshell.v1.EditDraftChunkRequest - (*EditDraftChunkResponse)(nil), // 222: openshell.v1.EditDraftChunkResponse - (*UndoDraftChunkRequest)(nil), // 223: openshell.v1.UndoDraftChunkRequest - (*UndoDraftChunkResponse)(nil), // 224: openshell.v1.UndoDraftChunkResponse - (*ClearDraftChunksRequest)(nil), // 225: openshell.v1.ClearDraftChunksRequest - (*ClearDraftChunksResponse)(nil), // 226: openshell.v1.ClearDraftChunksResponse - (*GetDraftHistoryRequest)(nil), // 227: openshell.v1.GetDraftHistoryRequest - (*DraftHistoryEntry)(nil), // 228: openshell.v1.DraftHistoryEntry - (*GetDraftHistoryResponse)(nil), // 229: openshell.v1.GetDraftHistoryResponse - (*CreateWorkspaceRequest)(nil), // 230: openshell.v1.CreateWorkspaceRequest - (*CreateWorkspaceResponse)(nil), // 231: openshell.v1.CreateWorkspaceResponse - (*GetWorkspaceRequest)(nil), // 232: openshell.v1.GetWorkspaceRequest - (*GetWorkspaceResponse)(nil), // 233: openshell.v1.GetWorkspaceResponse - (*ListWorkspacesRequest)(nil), // 234: openshell.v1.ListWorkspacesRequest - (*ListWorkspacesResponse)(nil), // 235: openshell.v1.ListWorkspacesResponse - (*DeleteWorkspaceRequest)(nil), // 236: openshell.v1.DeleteWorkspaceRequest - (*DeleteWorkspaceResponse)(nil), // 237: openshell.v1.DeleteWorkspaceResponse - (*WorkspaceMember)(nil), // 238: openshell.v1.WorkspaceMember - (*AddWorkspaceMemberRequest)(nil), // 239: openshell.v1.AddWorkspaceMemberRequest - (*AddWorkspaceMemberResponse)(nil), // 240: openshell.v1.AddWorkspaceMemberResponse - (*RemoveWorkspaceMemberRequest)(nil), // 241: openshell.v1.RemoveWorkspaceMemberRequest - (*RemoveWorkspaceMemberResponse)(nil), // 242: openshell.v1.RemoveWorkspaceMemberResponse - (*ListWorkspaceMembersRequest)(nil), // 243: openshell.v1.ListWorkspaceMembersRequest - (*ListWorkspaceMembersResponse)(nil), // 244: openshell.v1.ListWorkspaceMembersResponse - (*ExtensionServiceCredential)(nil), // 245: openshell.v1.ExtensionServiceCredential - (*EndpointObservation)(nil), // 246: openshell.v1.EndpointObservation - (*ReportEndpointStatusRequest)(nil), // 247: openshell.v1.ReportEndpointStatusRequest - (*ReportEndpointStatusResponse)(nil), // 248: openshell.v1.ReportEndpointStatusResponse - (*EndpointStatus)(nil), // 249: openshell.v1.EndpointStatus - (*SandboxProvisioning)(nil), // 250: openshell.v1.SandboxProvisioning - (*SandboxServiceExposure)(nil), // 251: openshell.v1.SandboxServiceExposure - nil, // 252: openshell.v1.SandboxSpec.EnvironmentEntry - nil, // 253: openshell.v1.SandboxTemplate.LabelsEntry - nil, // 254: openshell.v1.SandboxTemplate.AnnotationsEntry - nil, // 255: openshell.v1.SandboxTemplate.EnvironmentEntry - nil, // 256: openshell.v1.SandboxWorkloadConfig.EnvironmentEntry - nil, // 257: openshell.v1.PlatformEvent.MetadataEntry - nil, // 258: openshell.v1.CreateSandboxRequest.LabelsEntry - nil, // 259: openshell.v1.CreateSandboxRequest.AnnotationsEntry - nil, // 260: openshell.v1.SandboxResponse.ServiceUrlsEntry - nil, // 261: openshell.v1.ExecSandboxRequest.EnvironmentEntry - nil, // 262: openshell.v1.SandboxLogLine.FieldsEntry - nil, // 263: openshell.v1.UpdateProviderRequest.CredentialExpirationTimesEntry - nil, // 264: openshell.v1.ConfigureProviderRefreshRequest.MaterialEntry - nil, // 265: openshell.v1.ProviderProfile.AnnotationsEntry - nil, // 266: openshell.v1.GetSandboxProviderEnvironmentResponse.EnvironmentEntry - nil, // 267: openshell.v1.GetSandboxProviderEnvironmentResponse.CredentialExpirationTimesEntry - nil, // 268: openshell.v1.GetSandboxProviderEnvironmentResponse.DynamicCredentialsEntry - nil, // 269: openshell.v1.GetSandboxProviderEnvironmentResponse.StaticCredentialBindingsEntry - nil, // 270: openshell.v1.GetSandboxProviderEnvironmentResponse.FilesEntry - nil, // 271: openshell.v1.UpdateConfigRequest.AnnotationsEntry - nil, // 272: openshell.v1.UpdateConfigResponse.AnnotationsEntry - nil, // 273: openshell.v1.SandboxPolicyRevision.ProvenanceEntry - nil, // 274: openshell.v1.CreateWorkspaceRequest.LabelsEntry - (*timestamppb.Timestamp)(nil), // 275: google.protobuf.Timestamp - (*datamodelv1.ObjectMeta)(nil), // 276: openshell.datamodel.v1.ObjectMeta - (*sandboxv1.SandboxPolicy)(nil), // 277: openshell.sandbox.v1.SandboxPolicy - (*structpb.Struct)(nil), // 278: google.protobuf.Struct - (*durationpb.Duration)(nil), // 279: google.protobuf.Duration - (*datamodelv1.WorkspaceSelector)(nil), // 280: openshell.datamodel.v1.WorkspaceSelector - (*datamodelv1.Provider)(nil), // 281: openshell.datamodel.v1.Provider - (sandboxv1.PolicySource)(0), // 282: openshell.sandbox.v1.PolicySource - (*sandboxv1.NetworkEndpoint)(nil), // 283: openshell.sandbox.v1.NetworkEndpoint - (*sandboxv1.NetworkBinary)(nil), // 284: openshell.sandbox.v1.NetworkBinary - (*sandboxv1.SettingValue)(nil), // 285: openshell.sandbox.v1.SettingValue - (*sandboxv1.NetworkPolicyRule)(nil), // 286: openshell.sandbox.v1.NetworkPolicyRule - (*sandboxv1.L7DenyRule)(nil), // 287: openshell.sandbox.v1.L7DenyRule - (*sandboxv1.L7Rule)(nil), // 288: openshell.sandbox.v1.L7Rule - (*datamodelv1.Workspace)(nil), // 289: openshell.datamodel.v1.Workspace - (*sandboxv1.GetSandboxConfigRequest)(nil), // 290: openshell.sandbox.v1.GetSandboxConfigRequest - (*sandboxv1.GetGatewayConfigRequest)(nil), // 291: openshell.sandbox.v1.GetGatewayConfigRequest - (*sandboxv1.GetSandboxConfigResponse)(nil), // 292: openshell.sandbox.v1.GetSandboxConfigResponse - (*sandboxv1.GetGatewayConfigResponse)(nil), // 293: openshell.sandbox.v1.GetGatewayConfigResponse + (*ProviderProfileEnvironment)(nil), // 133: openshell.v1.ProviderProfileEnvironment + (*GetProviderRefreshStatusRequest)(nil), // 134: openshell.v1.GetProviderRefreshStatusRequest + (*GetProviderRefreshStatusResponse)(nil), // 135: openshell.v1.GetProviderRefreshStatusResponse + (*ConfigureProviderRefreshRequest)(nil), // 136: openshell.v1.ConfigureProviderRefreshRequest + (*ConfigureProviderRefreshResponse)(nil), // 137: openshell.v1.ConfigureProviderRefreshResponse + (*RotateProviderCredentialRequest)(nil), // 138: openshell.v1.RotateProviderCredentialRequest + (*RotateProviderCredentialResponse)(nil), // 139: openshell.v1.RotateProviderCredentialResponse + (*DeleteProviderRefreshRequest)(nil), // 140: openshell.v1.DeleteProviderRefreshRequest + (*DeleteProviderRefreshResponse)(nil), // 141: openshell.v1.DeleteProviderRefreshResponse + (*ProviderProfile)(nil), // 142: openshell.v1.ProviderProfile + (*ProviderProfileFile)(nil), // 143: openshell.v1.ProviderProfileFile + (*ProviderProfileResponse)(nil), // 144: openshell.v1.ProviderProfileResponse + (*ListProviderProfilesResponse)(nil), // 145: openshell.v1.ListProviderProfilesResponse + (*ImportProviderProfilesRequest)(nil), // 146: openshell.v1.ImportProviderProfilesRequest + (*ImportProviderProfilesResponse)(nil), // 147: openshell.v1.ImportProviderProfilesResponse + (*UpdateProviderProfilesRequest)(nil), // 148: openshell.v1.UpdateProviderProfilesRequest + (*UpdateProviderProfilesResponse)(nil), // 149: openshell.v1.UpdateProviderProfilesResponse + (*LintProviderProfilesRequest)(nil), // 150: openshell.v1.LintProviderProfilesRequest + (*LintProviderProfilesResponse)(nil), // 151: openshell.v1.LintProviderProfilesResponse + (*DeleteProviderResponse)(nil), // 152: openshell.v1.DeleteProviderResponse + (*DeleteProviderProfileRequest)(nil), // 153: openshell.v1.DeleteProviderProfileRequest + (*DeleteProviderProfileResponse)(nil), // 154: openshell.v1.DeleteProviderProfileResponse + (*GetSandboxProviderEnvironmentRequest)(nil), // 155: openshell.v1.GetSandboxProviderEnvironmentRequest + (*StaticCredentialEndpointBinding)(nil), // 156: openshell.v1.StaticCredentialEndpointBinding + (*StaticCredentialBinding)(nil), // 157: openshell.v1.StaticCredentialBinding + (*GetSandboxProviderEnvironmentResponse)(nil), // 158: openshell.v1.GetSandboxProviderEnvironmentResponse + (*ExchangeProviderSubjectTokenRequest)(nil), // 159: openshell.v1.ExchangeProviderSubjectTokenRequest + (*ExchangeProviderSubjectTokenResponse)(nil), // 160: openshell.v1.ExchangeProviderSubjectTokenResponse + (*UpdateConfigRequest)(nil), // 161: openshell.v1.UpdateConfigRequest + (*PolicyMergeOperation)(nil), // 162: openshell.v1.PolicyMergeOperation + (*AddNetworkRule)(nil), // 163: openshell.v1.AddNetworkRule + (*RemoveNetworkEndpoint)(nil), // 164: openshell.v1.RemoveNetworkEndpoint + (*RemoveNetworkRule)(nil), // 165: openshell.v1.RemoveNetworkRule + (*L7RuleTarget)(nil), // 166: openshell.v1.L7RuleTarget + (*AddDenyRules)(nil), // 167: openshell.v1.AddDenyRules + (*AddAllowRules)(nil), // 168: openshell.v1.AddAllowRules + (*RemoveNetworkBinary)(nil), // 169: openshell.v1.RemoveNetworkBinary + (*UpdateConfigResponse)(nil), // 170: openshell.v1.UpdateConfigResponse + (*GetSandboxPolicyStatusRequest)(nil), // 171: openshell.v1.GetSandboxPolicyStatusRequest + (*GetSandboxPolicyStatusResponse)(nil), // 172: openshell.v1.GetSandboxPolicyStatusResponse + (*ListSandboxPoliciesRequest)(nil), // 173: openshell.v1.ListSandboxPoliciesRequest + (*ListSandboxPoliciesResponse)(nil), // 174: openshell.v1.ListSandboxPoliciesResponse + (*ReportPolicyStatusRequest)(nil), // 175: openshell.v1.ReportPolicyStatusRequest + (*ReportPolicyStatusResponse)(nil), // 176: openshell.v1.ReportPolicyStatusResponse + (*SandboxConfigurationAdmission)(nil), // 177: openshell.v1.SandboxConfigurationAdmission + (*ReportSandboxConfigurationRequest)(nil), // 178: openshell.v1.ReportSandboxConfigurationRequest + (*ReportSandboxConfigurationResponse)(nil), // 179: openshell.v1.ReportSandboxConfigurationResponse + (*SandboxPolicyRevision)(nil), // 180: openshell.v1.SandboxPolicyRevision + (*GetSandboxLogsRequest)(nil), // 181: openshell.v1.GetSandboxLogsRequest + (*PushSandboxLogsRequest)(nil), // 182: openshell.v1.PushSandboxLogsRequest + (*PushSandboxLogsResponse)(nil), // 183: openshell.v1.PushSandboxLogsResponse + (*GetSandboxLogsResponse)(nil), // 184: openshell.v1.GetSandboxLogsResponse + (*SupervisorMessage)(nil), // 185: openshell.v1.SupervisorMessage + (*GatewayMessage)(nil), // 186: openshell.v1.GatewayMessage + (*SupervisorHello)(nil), // 187: openshell.v1.SupervisorHello + (*SessionAccepted)(nil), // 188: openshell.v1.SessionAccepted + (*SessionRejected)(nil), // 189: openshell.v1.SessionRejected + (*SupervisorHeartbeat)(nil), // 190: openshell.v1.SupervisorHeartbeat + (*GatewayHeartbeat)(nil), // 191: openshell.v1.GatewayHeartbeat + (*ReportMainProcessExitRequest)(nil), // 192: openshell.v1.ReportMainProcessExitRequest + (*ReportMainProcessExitResponse)(nil), // 193: openshell.v1.ReportMainProcessExitResponse + (*FinalizeMainProcessExitRequest)(nil), // 194: openshell.v1.FinalizeMainProcessExitRequest + (*FinalizeMainProcessExitResponse)(nil), // 195: openshell.v1.FinalizeMainProcessExitResponse + (*RelayOpen)(nil), // 196: openshell.v1.RelayOpen + (*SshRelayTarget)(nil), // 197: openshell.v1.SshRelayTarget + (*TcpRelayTarget)(nil), // 198: openshell.v1.TcpRelayTarget + (*RelayInit)(nil), // 199: openshell.v1.RelayInit + (*RelayFrame)(nil), // 200: openshell.v1.RelayFrame + (*PeerRelayInit)(nil), // 201: openshell.v1.PeerRelayInit + (*PeerRelayFrame)(nil), // 202: openshell.v1.PeerRelayFrame + (*RelayOpenResult)(nil), // 203: openshell.v1.RelayOpenResult + (*RelayClose)(nil), // 204: openshell.v1.RelayClose + (*L7RequestSample)(nil), // 205: openshell.v1.L7RequestSample + (*DenialSummary)(nil), // 206: openshell.v1.DenialSummary + (*DenialGroupCount)(nil), // 207: openshell.v1.DenialGroupCount + (*NetworkActivitySummary)(nil), // 208: openshell.v1.NetworkActivitySummary + (*PolicyChunk)(nil), // 209: openshell.v1.PolicyChunk + (*DraftPolicyUpdate)(nil), // 210: openshell.v1.DraftPolicyUpdate + (*SubmitPolicyAnalysisRequest)(nil), // 211: openshell.v1.SubmitPolicyAnalysisRequest + (*SubmitPolicyAnalysisResponse)(nil), // 212: openshell.v1.SubmitPolicyAnalysisResponse + (*GetDraftPolicyRequest)(nil), // 213: openshell.v1.GetDraftPolicyRequest + (*GetDraftPolicyResponse)(nil), // 214: openshell.v1.GetDraftPolicyResponse + (*ApproveDraftChunkRequest)(nil), // 215: openshell.v1.ApproveDraftChunkRequest + (*ApproveDraftChunkResponse)(nil), // 216: openshell.v1.ApproveDraftChunkResponse + (*RejectDraftChunkRequest)(nil), // 217: openshell.v1.RejectDraftChunkRequest + (*RejectDraftChunkResponse)(nil), // 218: openshell.v1.RejectDraftChunkResponse + (*DraftChunkApproval)(nil), // 219: openshell.v1.DraftChunkApproval + (*ApproveAllDraftChunksRequest)(nil), // 220: openshell.v1.ApproveAllDraftChunksRequest + (*ApproveAllDraftChunksResponse)(nil), // 221: openshell.v1.ApproveAllDraftChunksResponse + (*EditDraftChunkRequest)(nil), // 222: openshell.v1.EditDraftChunkRequest + (*EditDraftChunkResponse)(nil), // 223: openshell.v1.EditDraftChunkResponse + (*UndoDraftChunkRequest)(nil), // 224: openshell.v1.UndoDraftChunkRequest + (*UndoDraftChunkResponse)(nil), // 225: openshell.v1.UndoDraftChunkResponse + (*ClearDraftChunksRequest)(nil), // 226: openshell.v1.ClearDraftChunksRequest + (*ClearDraftChunksResponse)(nil), // 227: openshell.v1.ClearDraftChunksResponse + (*GetDraftHistoryRequest)(nil), // 228: openshell.v1.GetDraftHistoryRequest + (*DraftHistoryEntry)(nil), // 229: openshell.v1.DraftHistoryEntry + (*GetDraftHistoryResponse)(nil), // 230: openshell.v1.GetDraftHistoryResponse + (*CreateWorkspaceRequest)(nil), // 231: openshell.v1.CreateWorkspaceRequest + (*CreateWorkspaceResponse)(nil), // 232: openshell.v1.CreateWorkspaceResponse + (*GetWorkspaceRequest)(nil), // 233: openshell.v1.GetWorkspaceRequest + (*GetWorkspaceResponse)(nil), // 234: openshell.v1.GetWorkspaceResponse + (*ListWorkspacesRequest)(nil), // 235: openshell.v1.ListWorkspacesRequest + (*ListWorkspacesResponse)(nil), // 236: openshell.v1.ListWorkspacesResponse + (*DeleteWorkspaceRequest)(nil), // 237: openshell.v1.DeleteWorkspaceRequest + (*DeleteWorkspaceResponse)(nil), // 238: openshell.v1.DeleteWorkspaceResponse + (*WorkspaceMember)(nil), // 239: openshell.v1.WorkspaceMember + (*AddWorkspaceMemberRequest)(nil), // 240: openshell.v1.AddWorkspaceMemberRequest + (*AddWorkspaceMemberResponse)(nil), // 241: openshell.v1.AddWorkspaceMemberResponse + (*RemoveWorkspaceMemberRequest)(nil), // 242: openshell.v1.RemoveWorkspaceMemberRequest + (*RemoveWorkspaceMemberResponse)(nil), // 243: openshell.v1.RemoveWorkspaceMemberResponse + (*ListWorkspaceMembersRequest)(nil), // 244: openshell.v1.ListWorkspaceMembersRequest + (*ListWorkspaceMembersResponse)(nil), // 245: openshell.v1.ListWorkspaceMembersResponse + (*ExtensionServiceCredential)(nil), // 246: openshell.v1.ExtensionServiceCredential + (*EndpointObservation)(nil), // 247: openshell.v1.EndpointObservation + (*ReportEndpointStatusRequest)(nil), // 248: openshell.v1.ReportEndpointStatusRequest + (*ReportEndpointStatusResponse)(nil), // 249: openshell.v1.ReportEndpointStatusResponse + (*EndpointStatus)(nil), // 250: openshell.v1.EndpointStatus + (*SandboxProvisioning)(nil), // 251: openshell.v1.SandboxProvisioning + (*SandboxServiceExposure)(nil), // 252: openshell.v1.SandboxServiceExposure + nil, // 253: openshell.v1.SandboxSpec.EnvironmentEntry + nil, // 254: openshell.v1.SandboxTemplate.LabelsEntry + nil, // 255: openshell.v1.SandboxTemplate.AnnotationsEntry + nil, // 256: openshell.v1.SandboxTemplate.EnvironmentEntry + nil, // 257: openshell.v1.SandboxWorkloadConfig.EnvironmentEntry + nil, // 258: openshell.v1.PlatformEvent.MetadataEntry + nil, // 259: openshell.v1.CreateSandboxRequest.LabelsEntry + nil, // 260: openshell.v1.CreateSandboxRequest.AnnotationsEntry + nil, // 261: openshell.v1.SandboxResponse.ServiceUrlsEntry + nil, // 262: openshell.v1.ExecSandboxRequest.EnvironmentEntry + nil, // 263: openshell.v1.SandboxLogLine.FieldsEntry + nil, // 264: openshell.v1.UpdateProviderRequest.CredentialExpirationTimesEntry + nil, // 265: openshell.v1.ProviderProfileEnvironment.ConfigEntry + nil, // 266: openshell.v1.ProviderProfileEnvironment.FixedEntry + nil, // 267: openshell.v1.ConfigureProviderRefreshRequest.MaterialEntry + nil, // 268: openshell.v1.ProviderProfile.AnnotationsEntry + nil, // 269: openshell.v1.GetSandboxProviderEnvironmentResponse.EnvironmentEntry + nil, // 270: openshell.v1.GetSandboxProviderEnvironmentResponse.CredentialExpirationTimesEntry + nil, // 271: openshell.v1.GetSandboxProviderEnvironmentResponse.DynamicCredentialsEntry + nil, // 272: openshell.v1.GetSandboxProviderEnvironmentResponse.StaticCredentialBindingsEntry + nil, // 273: openshell.v1.GetSandboxProviderEnvironmentResponse.FilesEntry + nil, // 274: openshell.v1.UpdateConfigRequest.AnnotationsEntry + nil, // 275: openshell.v1.UpdateConfigResponse.AnnotationsEntry + nil, // 276: openshell.v1.SandboxPolicyRevision.ProvenanceEntry + nil, // 277: openshell.v1.CreateWorkspaceRequest.LabelsEntry + (*timestamppb.Timestamp)(nil), // 278: google.protobuf.Timestamp + (*datamodelv1.ObjectMeta)(nil), // 279: openshell.datamodel.v1.ObjectMeta + (*sandboxv1.SandboxPolicy)(nil), // 280: openshell.sandbox.v1.SandboxPolicy + (*structpb.Struct)(nil), // 281: google.protobuf.Struct + (*durationpb.Duration)(nil), // 282: google.protobuf.Duration + (*datamodelv1.WorkspaceSelector)(nil), // 283: openshell.datamodel.v1.WorkspaceSelector + (*datamodelv1.Provider)(nil), // 284: openshell.datamodel.v1.Provider + (sandboxv1.PolicySource)(0), // 285: openshell.sandbox.v1.PolicySource + (*sandboxv1.NetworkEndpoint)(nil), // 286: openshell.sandbox.v1.NetworkEndpoint + (*sandboxv1.NetworkBinary)(nil), // 287: openshell.sandbox.v1.NetworkBinary + (*sandboxv1.SettingValue)(nil), // 288: openshell.sandbox.v1.SettingValue + (*sandboxv1.NetworkPolicyRule)(nil), // 289: openshell.sandbox.v1.NetworkPolicyRule + (*sandboxv1.L7DenyRule)(nil), // 290: openshell.sandbox.v1.L7DenyRule + (*sandboxv1.L7Rule)(nil), // 291: openshell.sandbox.v1.L7Rule + (*datamodelv1.Workspace)(nil), // 292: openshell.datamodel.v1.Workspace + (*sandboxv1.GetSandboxConfigRequest)(nil), // 293: openshell.sandbox.v1.GetSandboxConfigRequest + (*sandboxv1.GetGatewayConfigRequest)(nil), // 294: openshell.sandbox.v1.GetGatewayConfigRequest + (*sandboxv1.GetSandboxConfigResponse)(nil), // 295: openshell.sandbox.v1.GetSandboxConfigResponse + (*sandboxv1.GetGatewayConfigResponse)(nil), // 296: openshell.sandbox.v1.GetGatewayConfigResponse } var file_openshell_proto_depIdxs = []int32{ - 275, // 0: openshell.v1.IssueSandboxTokenResponse.expiration_time:type_name -> google.protobuf.Timestamp - 275, // 1: openshell.v1.RefreshSandboxTokenResponse.expiration_time:type_name -> google.protobuf.Timestamp - 245, // 2: openshell.v1.RefreshSandboxTokenResponse.extension_credentials:type_name -> openshell.v1.ExtensionServiceCredential - 275, // 3: openshell.v1.RefreshSandboxTokenResponse.sandbox_expiration_time:type_name -> google.protobuf.Timestamp + 278, // 0: openshell.v1.IssueSandboxTokenResponse.expiration_time:type_name -> google.protobuf.Timestamp + 278, // 1: openshell.v1.RefreshSandboxTokenResponse.expiration_time:type_name -> google.protobuf.Timestamp + 246, // 2: openshell.v1.RefreshSandboxTokenResponse.extension_credentials:type_name -> openshell.v1.ExtensionServiceCredential + 278, // 3: openshell.v1.RefreshSandboxTokenResponse.sandbox_expiration_time:type_name -> google.protobuf.Timestamp 13, // 4: openshell.v1.HealthResponse.status:type_name -> openshell.v1.ServiceStatus 13, // 5: openshell.v1.GetGatewayInfoResponse.status:type_name -> openshell.v1.ServiceStatus 31, // 6: openshell.v1.GetGatewayInfoResponse.compute_drivers:type_name -> openshell.v1.ComputeDriverInfo @@ -19803,485 +19903,488 @@ var file_openshell_proto_depIdxs = []int32{ 34, // 11: openshell.v1.ResourceCapabilities.cpu:type_name -> openshell.v1.CpuResourceCapabilities 35, // 12: openshell.v1.ResourceCapabilities.memory:type_name -> openshell.v1.MemoryResourceCapabilities 36, // 13: openshell.v1.ResourceCapabilities.gpu:type_name -> openshell.v1.GpuResourceCapabilities - 276, // 14: openshell.v1.Sandbox.metadata:type_name -> openshell.datamodel.v1.ObjectMeta + 279, // 14: openshell.v1.Sandbox.metadata:type_name -> openshell.datamodel.v1.ObjectMeta 38, // 15: openshell.v1.Sandbox.spec:type_name -> openshell.v1.SandboxSpec 49, // 16: openshell.v1.Sandbox.status:type_name -> openshell.v1.SandboxStatus 48, // 17: openshell.v1.Sandbox.created_from_workload_template:type_name -> openshell.v1.SandboxWorkloadTemplateProvenance - 252, // 18: openshell.v1.SandboxSpec.environment:type_name -> openshell.v1.SandboxSpec.EnvironmentEntry + 253, // 18: openshell.v1.SandboxSpec.environment:type_name -> openshell.v1.SandboxSpec.EnvironmentEntry 41, // 19: openshell.v1.SandboxSpec.template:type_name -> openshell.v1.SandboxTemplate - 277, // 20: openshell.v1.SandboxSpec.policy:type_name -> openshell.sandbox.v1.SandboxPolicy + 280, // 20: openshell.v1.SandboxSpec.policy:type_name -> openshell.sandbox.v1.SandboxPolicy 39, // 21: openshell.v1.SandboxSpec.resource_requirements:type_name -> openshell.v1.ResourceRequirements 16, // 22: openshell.v1.SandboxSpec.restart_policy:type_name -> openshell.v1.SandboxRestartPolicy 40, // 23: openshell.v1.ResourceRequirements.gpu:type_name -> openshell.v1.GpuResourceRequirements - 253, // 24: openshell.v1.SandboxTemplate.labels:type_name -> openshell.v1.SandboxTemplate.LabelsEntry - 254, // 25: openshell.v1.SandboxTemplate.annotations:type_name -> openshell.v1.SandboxTemplate.AnnotationsEntry - 255, // 26: openshell.v1.SandboxTemplate.environment:type_name -> openshell.v1.SandboxTemplate.EnvironmentEntry - 278, // 27: openshell.v1.SandboxTemplate.resources:type_name -> google.protobuf.Struct - 278, // 28: openshell.v1.SandboxTemplate.driver_config:type_name -> google.protobuf.Struct - 276, // 29: openshell.v1.SandboxWorkloadTemplate.metadata:type_name -> openshell.datamodel.v1.ObjectMeta + 254, // 24: openshell.v1.SandboxTemplate.labels:type_name -> openshell.v1.SandboxTemplate.LabelsEntry + 255, // 25: openshell.v1.SandboxTemplate.annotations:type_name -> openshell.v1.SandboxTemplate.AnnotationsEntry + 256, // 26: openshell.v1.SandboxTemplate.environment:type_name -> openshell.v1.SandboxTemplate.EnvironmentEntry + 281, // 27: openshell.v1.SandboxTemplate.resources:type_name -> google.protobuf.Struct + 281, // 28: openshell.v1.SandboxTemplate.driver_config:type_name -> google.protobuf.Struct + 279, // 29: openshell.v1.SandboxWorkloadTemplate.metadata:type_name -> openshell.datamodel.v1.ObjectMeta 43, // 30: openshell.v1.SandboxWorkloadTemplate.spec:type_name -> openshell.v1.SandboxWorkloadTemplateSpec 44, // 31: openshell.v1.SandboxWorkloadTemplateSpec.workload:type_name -> openshell.v1.SandboxWorkloadConfig - 278, // 32: openshell.v1.SandboxWorkloadTemplateSpec.driver_config:type_name -> google.protobuf.Struct + 281, // 32: openshell.v1.SandboxWorkloadTemplateSpec.driver_config:type_name -> google.protobuf.Struct 46, // 33: openshell.v1.SandboxWorkloadTemplateSpec.desired_service_level:type_name -> openshell.v1.SandboxServiceLevel - 256, // 34: openshell.v1.SandboxWorkloadConfig.environment:type_name -> openshell.v1.SandboxWorkloadConfig.EnvironmentEntry + 257, // 34: openshell.v1.SandboxWorkloadConfig.environment:type_name -> openshell.v1.SandboxWorkloadConfig.EnvironmentEntry 45, // 35: openshell.v1.SandboxWorkloadConfig.resources:type_name -> openshell.v1.SandboxResources 40, // 36: openshell.v1.SandboxResources.gpu:type_name -> openshell.v1.GpuResourceRequirements 47, // 37: openshell.v1.SandboxServiceLevel.startup:type_name -> openshell.v1.SandboxStartup - 279, // 38: openshell.v1.SandboxStartup.ready_within:type_name -> google.protobuf.Duration + 282, // 38: openshell.v1.SandboxStartup.ready_within:type_name -> google.protobuf.Duration 50, // 39: openshell.v1.SandboxStatus.conditions:type_name -> openshell.v1.SandboxCondition 1, // 40: openshell.v1.SandboxStatus.phase:type_name -> openshell.v1.SandboxPhase - 249, // 41: openshell.v1.SandboxStatus.endpoint_statuses:type_name -> openshell.v1.EndpointStatus - 176, // 42: openshell.v1.SandboxStatus.configuration_admission:type_name -> openshell.v1.SandboxConfigurationAdmission - 250, // 43: openshell.v1.SandboxStatus.provisioning:type_name -> openshell.v1.SandboxProvisioning - 275, // 44: openshell.v1.SandboxStatus.next_restart_time:type_name -> google.protobuf.Timestamp - 275, // 45: openshell.v1.SandboxStatus.main_process_started_time:type_name -> google.protobuf.Timestamp - 275, // 46: openshell.v1.SandboxCondition.transition_time:type_name -> google.protobuf.Timestamp - 275, // 47: openshell.v1.PlatformEvent.event_time:type_name -> google.protobuf.Timestamp - 257, // 48: openshell.v1.PlatformEvent.metadata:type_name -> openshell.v1.PlatformEvent.MetadataEntry - 280, // 49: openshell.v1.CreateSandboxRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 250, // 41: openshell.v1.SandboxStatus.endpoint_statuses:type_name -> openshell.v1.EndpointStatus + 177, // 42: openshell.v1.SandboxStatus.configuration_admission:type_name -> openshell.v1.SandboxConfigurationAdmission + 251, // 43: openshell.v1.SandboxStatus.provisioning:type_name -> openshell.v1.SandboxProvisioning + 278, // 44: openshell.v1.SandboxStatus.next_restart_time:type_name -> google.protobuf.Timestamp + 278, // 45: openshell.v1.SandboxStatus.main_process_started_time:type_name -> google.protobuf.Timestamp + 278, // 46: openshell.v1.SandboxCondition.transition_time:type_name -> google.protobuf.Timestamp + 278, // 47: openshell.v1.PlatformEvent.event_time:type_name -> google.protobuf.Timestamp + 258, // 48: openshell.v1.PlatformEvent.metadata:type_name -> openshell.v1.PlatformEvent.MetadataEntry + 283, // 49: openshell.v1.CreateSandboxRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector 38, // 50: openshell.v1.CreateSandboxRequest.spec:type_name -> openshell.v1.SandboxSpec - 258, // 51: openshell.v1.CreateSandboxRequest.labels:type_name -> openshell.v1.CreateSandboxRequest.LabelsEntry - 259, // 52: openshell.v1.CreateSandboxRequest.annotations:type_name -> openshell.v1.CreateSandboxRequest.AnnotationsEntry - 251, // 53: openshell.v1.CreateSandboxRequest.service_exposures:type_name -> openshell.v1.SandboxServiceExposure - 280, // 54: openshell.v1.CreateSandboxTemplateRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 259, // 51: openshell.v1.CreateSandboxRequest.labels:type_name -> openshell.v1.CreateSandboxRequest.LabelsEntry + 260, // 52: openshell.v1.CreateSandboxRequest.annotations:type_name -> openshell.v1.CreateSandboxRequest.AnnotationsEntry + 252, // 53: openshell.v1.CreateSandboxRequest.service_exposures:type_name -> openshell.v1.SandboxServiceExposure + 283, // 54: openshell.v1.CreateSandboxTemplateRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector 42, // 55: openshell.v1.CreateSandboxTemplateRequest.template:type_name -> openshell.v1.SandboxWorkloadTemplate - 280, // 56: openshell.v1.GetSandboxTemplateRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 280, // 57: openshell.v1.ListSandboxTemplatesRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 280, // 58: openshell.v1.DeleteSandboxTemplateRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 56: openshell.v1.GetSandboxTemplateRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 57: openshell.v1.ListSandboxTemplatesRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 58: openshell.v1.DeleteSandboxTemplateRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector 42, // 59: openshell.v1.SandboxTemplateResponse.template:type_name -> openshell.v1.SandboxWorkloadTemplate 42, // 60: openshell.v1.ListSandboxTemplatesResponse.templates:type_name -> openshell.v1.SandboxWorkloadTemplate 17, // 61: openshell.v1.DeleteSandboxTemplateResponse.outcome:type_name -> openshell.v1.DeletionOutcome - 280, // 62: openshell.v1.BeginRootfsTarStagingRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 275, // 63: openshell.v1.BeginRootfsTarStagingResponse.expiration_time:type_name -> google.protobuf.Timestamp - 280, // 64: openshell.v1.GetSandboxRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 280, // 65: openshell.v1.ListSandboxesRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 280, // 66: openshell.v1.ListSandboxProvidersRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 280, // 67: openshell.v1.AttachSandboxProviderRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 280, // 68: openshell.v1.DetachSandboxProviderRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 280, // 69: openshell.v1.DeleteSandboxRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 280, // 70: openshell.v1.StopSandboxRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 280, // 71: openshell.v1.StartSandboxRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 62: openshell.v1.BeginRootfsTarStagingRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 278, // 63: openshell.v1.BeginRootfsTarStagingResponse.expiration_time:type_name -> google.protobuf.Timestamp + 283, // 64: openshell.v1.GetSandboxRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 65: openshell.v1.ListSandboxesRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 66: openshell.v1.ListSandboxProvidersRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 67: openshell.v1.AttachSandboxProviderRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 68: openshell.v1.DetachSandboxProviderRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 69: openshell.v1.DeleteSandboxRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 70: openshell.v1.StopSandboxRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 71: openshell.v1.StartSandboxRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector 37, // 72: openshell.v1.SandboxResponse.sandbox:type_name -> openshell.v1.Sandbox - 260, // 73: openshell.v1.SandboxResponse.service_urls:type_name -> openshell.v1.SandboxResponse.ServiceUrlsEntry + 261, // 73: openshell.v1.SandboxResponse.service_urls:type_name -> openshell.v1.SandboxResponse.ServiceUrlsEntry 37, // 74: openshell.v1.ListSandboxesResponse.sandboxes:type_name -> openshell.v1.Sandbox - 281, // 75: openshell.v1.ListSandboxProvidersResponse.providers:type_name -> openshell.datamodel.v1.Provider + 284, // 75: openshell.v1.ListSandboxProvidersResponse.providers:type_name -> openshell.datamodel.v1.Provider 37, // 76: openshell.v1.AttachSandboxProviderResponse.sandbox:type_name -> openshell.v1.Sandbox 79, // 77: openshell.v1.AttachSandboxProviderResponse.receipt:type_name -> openshell.v1.ProviderMutationReceipt 37, // 78: openshell.v1.DetachSandboxProviderResponse.sandbox:type_name -> openshell.v1.Sandbox 79, // 79: openshell.v1.DetachSandboxProviderResponse.receipt:type_name -> openshell.v1.ProviderMutationReceipt 77, // 80: openshell.v1.ConfigSnapshotRevision.sandbox_config:type_name -> openshell.v1.SandboxConfigRevision 75, // 81: openshell.v1.ConfigSnapshotRevision.provider_target:type_name -> openshell.v1.ProviderDesiredIdentity - 282, // 82: openshell.v1.SandboxConfigRevision.policy_source:type_name -> openshell.sandbox.v1.PolicySource + 285, // 82: openshell.v1.SandboxConfigRevision.policy_source:type_name -> openshell.sandbox.v1.PolicySource 5, // 83: openshell.v1.ConfigUpdateOperation.component:type_name -> openshell.v1.ConfigComponent 76, // 84: openshell.v1.ConfigUpdateOperation.target_revision:type_name -> openshell.v1.ConfigSnapshotRevision 7, // 85: openshell.v1.ConfigUpdateOperation.state:type_name -> openshell.v1.ConfigUpdateOperationState 6, // 86: openshell.v1.ConfigUpdateOperation.outcome:type_name -> openshell.v1.ConfigApplyOutcome - 275, // 87: openshell.v1.ConfigUpdateOperation.created_time:type_name -> google.protobuf.Timestamp - 275, // 88: openshell.v1.ConfigUpdateOperation.updated_time:type_name -> google.protobuf.Timestamp - 275, // 89: openshell.v1.ConfigUpdateOperation.completed_time:type_name -> google.protobuf.Timestamp + 278, // 87: openshell.v1.ConfigUpdateOperation.created_time:type_name -> google.protobuf.Timestamp + 278, // 88: openshell.v1.ConfigUpdateOperation.updated_time:type_name -> google.protobuf.Timestamp + 278, // 89: openshell.v1.ConfigUpdateOperation.completed_time:type_name -> google.protobuf.Timestamp 2, // 90: openshell.v1.ProviderMutationReceipt.kind:type_name -> openshell.v1.ProviderMutationKind 75, // 91: openshell.v1.ProviderMutationReceipt.desired:type_name -> openshell.v1.ProviderDesiredIdentity - 275, // 92: openshell.v1.ProviderMutationReceipt.persisted_time:type_name -> google.protobuf.Timestamp + 278, // 92: openshell.v1.ProviderMutationReceipt.persisted_time:type_name -> google.protobuf.Timestamp 4, // 93: openshell.v1.ProviderReadinessObservation.reason:type_name -> openshell.v1.ProviderReadinessReason 79, // 94: openshell.v1.ProviderReadinessStatus.receipt:type_name -> openshell.v1.ProviderMutationReceipt 3, // 95: openshell.v1.ProviderReadinessStatus.state:type_name -> openshell.v1.ProviderReadinessState 4, // 96: openshell.v1.ProviderReadinessStatus.reason:type_name -> openshell.v1.ProviderReadinessReason 80, // 97: openshell.v1.ProviderReadinessStatus.observed:type_name -> openshell.v1.ProviderReadinessObservation - 275, // 98: openshell.v1.ProviderReadinessStatus.observed_time:type_name -> google.protobuf.Timestamp - 275, // 99: openshell.v1.ProviderReadinessStatus.evaluated_time:type_name -> google.protobuf.Timestamp + 278, // 98: openshell.v1.ProviderReadinessStatus.observed_time:type_name -> google.protobuf.Timestamp + 278, // 99: openshell.v1.ProviderReadinessStatus.evaluated_time:type_name -> google.protobuf.Timestamp 78, // 100: openshell.v1.ProviderReadinessStatus.operation:type_name -> openshell.v1.ConfigUpdateOperation - 280, // 101: openshell.v1.GetSandboxProviderStatusRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 101: openshell.v1.GetSandboxProviderStatusRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector 81, // 102: openshell.v1.GetSandboxProviderStatusResponse.status:type_name -> openshell.v1.ProviderReadinessStatus 80, // 103: openshell.v1.ReportProviderReadinessRequest.observation:type_name -> openshell.v1.ProviderReadinessObservation - 279, // 104: openshell.v1.ReportProviderReadinessResponse.report_interval:type_name -> google.protobuf.Duration - 279, // 105: openshell.v1.ReportProviderReadinessResponse.observation_ttl:type_name -> google.protobuf.Duration + 282, // 104: openshell.v1.ReportProviderReadinessResponse.report_interval:type_name -> google.protobuf.Duration + 282, // 105: openshell.v1.ReportProviderReadinessResponse.observation_ttl:type_name -> google.protobuf.Duration 17, // 106: openshell.v1.DeleteSandboxResponse.outcome:type_name -> openshell.v1.DeletionOutcome - 280, // 107: openshell.v1.CreateSshSessionRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 275, // 108: openshell.v1.CreateSshSessionResponse.expiration_time:type_name -> google.protobuf.Timestamp - 280, // 109: openshell.v1.ExposeServiceRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 107: openshell.v1.CreateSshSessionRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 278, // 108: openshell.v1.CreateSshSessionResponse.expiration_time:type_name -> google.protobuf.Timestamp + 283, // 109: openshell.v1.ExposeServiceRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector 19, // 110: openshell.v1.ExposeServiceRequest.authorization_mode:type_name -> openshell.v1.ServiceAuthorizationMode - 280, // 111: openshell.v1.GetServiceRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 280, // 112: openshell.v1.ListServicesRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 111: openshell.v1.GetServiceRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 112: openshell.v1.ListServicesRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector 96, // 113: openshell.v1.ListServicesResponse.services:type_name -> openshell.v1.ServiceEndpointResponse - 280, // 114: openshell.v1.DeleteServiceRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 114: openshell.v1.DeleteServiceRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector 17, // 115: openshell.v1.DeleteServiceResponse.outcome:type_name -> openshell.v1.DeletionOutcome - 276, // 116: openshell.v1.ServiceEndpoint.metadata:type_name -> openshell.datamodel.v1.ObjectMeta + 279, // 116: openshell.v1.ServiceEndpoint.metadata:type_name -> openshell.datamodel.v1.ObjectMeta 19, // 117: openshell.v1.ServiceEndpoint.authorization_mode:type_name -> openshell.v1.ServiceAuthorizationMode 95, // 118: openshell.v1.ServiceEndpointResponse.endpoint:type_name -> openshell.v1.ServiceEndpoint 17, // 119: openshell.v1.RevokeSshSessionResponse.outcome:type_name -> openshell.v1.DeletionOutcome - 280, // 120: openshell.v1.ExecSandboxRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 261, // 121: openshell.v1.ExecSandboxRequest.environment:type_name -> openshell.v1.ExecSandboxRequest.EnvironmentEntry - 279, // 122: openshell.v1.ExecSandboxRequest.execution_timeout:type_name -> google.protobuf.Duration + 283, // 120: openshell.v1.ExecSandboxRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 262, // 121: openshell.v1.ExecSandboxRequest.environment:type_name -> openshell.v1.ExecSandboxRequest.EnvironmentEntry + 282, // 122: openshell.v1.ExecSandboxRequest.execution_timeout:type_name -> google.protobuf.Duration 100, // 123: openshell.v1.ExecSandboxEvent.stdout:type_name -> openshell.v1.ExecSandboxStdout 101, // 124: openshell.v1.ExecSandboxEvent.stderr:type_name -> openshell.v1.ExecSandboxStderr 102, // 125: openshell.v1.ExecSandboxEvent.exit:type_name -> openshell.v1.ExecSandboxExit - 196, // 126: openshell.v1.TcpForwardInit.ssh:type_name -> openshell.v1.SshRelayTarget - 197, // 127: openshell.v1.TcpForwardInit.tcp:type_name -> openshell.v1.TcpRelayTarget + 197, // 126: openshell.v1.TcpForwardInit.ssh:type_name -> openshell.v1.SshRelayTarget + 198, // 127: openshell.v1.TcpForwardInit.tcp:type_name -> openshell.v1.TcpRelayTarget 104, // 128: openshell.v1.TcpForwardFrame.init:type_name -> openshell.v1.TcpForwardInit 99, // 129: openshell.v1.ExecSandboxInput.start:type_name -> openshell.v1.ExecSandboxRequest 107, // 130: openshell.v1.ExecSandboxInput.resize:type_name -> openshell.v1.ExecSandboxWindowResize - 276, // 131: openshell.v1.SshSession.metadata:type_name -> openshell.datamodel.v1.ObjectMeta - 275, // 132: openshell.v1.SshSession.expiration_time:type_name -> google.protobuf.Timestamp - 280, // 133: openshell.v1.WatchSandboxRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 275, // 134: openshell.v1.WatchSandboxRequest.since_time:type_name -> google.protobuf.Timestamp + 279, // 131: openshell.v1.SshSession.metadata:type_name -> openshell.datamodel.v1.ObjectMeta + 278, // 132: openshell.v1.SshSession.expiration_time:type_name -> google.protobuf.Timestamp + 283, // 133: openshell.v1.WatchSandboxRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 278, // 134: openshell.v1.WatchSandboxRequest.since_time:type_name -> google.protobuf.Timestamp 37, // 135: openshell.v1.SandboxStreamEvent.sandbox:type_name -> openshell.v1.Sandbox 111, // 136: openshell.v1.SandboxStreamEvent.log:type_name -> openshell.v1.SandboxLogLine 51, // 137: openshell.v1.SandboxStreamEvent.event:type_name -> openshell.v1.PlatformEvent 112, // 138: openshell.v1.SandboxStreamEvent.warning:type_name -> openshell.v1.SandboxStreamWarning - 209, // 139: openshell.v1.SandboxStreamEvent.draft_policy_update:type_name -> openshell.v1.DraftPolicyUpdate - 275, // 140: openshell.v1.SandboxLogLine.event_time:type_name -> google.protobuf.Timestamp - 262, // 141: openshell.v1.SandboxLogLine.fields:type_name -> openshell.v1.SandboxLogLine.FieldsEntry - 280, // 142: openshell.v1.CreateProviderRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 281, // 143: openshell.v1.CreateProviderRequest.provider:type_name -> openshell.datamodel.v1.Provider - 280, // 144: openshell.v1.GetProviderRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 280, // 145: openshell.v1.ListProvidersRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 280, // 146: openshell.v1.UpdateProviderRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 281, // 147: openshell.v1.UpdateProviderRequest.provider:type_name -> openshell.datamodel.v1.Provider - 263, // 148: openshell.v1.UpdateProviderRequest.credential_expiration_times:type_name -> openshell.v1.UpdateProviderRequest.CredentialExpirationTimesEntry - 280, // 149: openshell.v1.DeleteProviderRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 281, // 150: openshell.v1.ProviderResponse.provider:type_name -> openshell.datamodel.v1.Provider + 210, // 139: openshell.v1.SandboxStreamEvent.draft_policy_update:type_name -> openshell.v1.DraftPolicyUpdate + 278, // 140: openshell.v1.SandboxLogLine.event_time:type_name -> google.protobuf.Timestamp + 263, // 141: openshell.v1.SandboxLogLine.fields:type_name -> openshell.v1.SandboxLogLine.FieldsEntry + 283, // 142: openshell.v1.CreateProviderRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 284, // 143: openshell.v1.CreateProviderRequest.provider:type_name -> openshell.datamodel.v1.Provider + 283, // 144: openshell.v1.GetProviderRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 145: openshell.v1.ListProvidersRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 146: openshell.v1.UpdateProviderRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 284, // 147: openshell.v1.UpdateProviderRequest.provider:type_name -> openshell.datamodel.v1.Provider + 264, // 148: openshell.v1.UpdateProviderRequest.credential_expiration_times:type_name -> openshell.v1.UpdateProviderRequest.CredentialExpirationTimesEntry + 283, // 149: openshell.v1.DeleteProviderRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 284, // 150: openshell.v1.ProviderResponse.provider:type_name -> openshell.datamodel.v1.Provider 79, // 151: openshell.v1.ProviderResponse.target_receipts:type_name -> openshell.v1.ProviderMutationReceipt - 281, // 152: openshell.v1.ListProvidersResponse.providers:type_name -> openshell.datamodel.v1.Provider - 280, // 153: openshell.v1.ListProviderProfilesRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 280, // 154: openshell.v1.GetProviderProfileRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 141, // 155: openshell.v1.ProviderProfileImportItem.profile:type_name -> openshell.v1.ProviderProfile - 279, // 156: openshell.v1.ProviderCredentialTokenGrant.cache_ttl:type_name -> google.protobuf.Duration + 284, // 152: openshell.v1.ListProvidersResponse.providers:type_name -> openshell.datamodel.v1.Provider + 283, // 153: openshell.v1.ListProviderProfilesRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 154: openshell.v1.GetProviderProfileRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 142, // 155: openshell.v1.ProviderProfileImportItem.profile:type_name -> openshell.v1.ProviderProfile + 282, // 156: openshell.v1.ProviderCredentialTokenGrant.cache_ttl:type_name -> google.protobuf.Duration 124, // 157: openshell.v1.ProviderCredentialTokenGrant.audience_overrides:type_name -> openshell.v1.ProviderCredentialTokenGrantAudienceOverride 8, // 158: openshell.v1.ProviderCredentialTokenGrant.grant_type:type_name -> openshell.v1.ProviderCredentialTokenGrantType 125, // 159: openshell.v1.ProviderCredentialTokenGrant.subject_token:type_name -> openshell.v1.ProviderCredentialTokenGrantSubjectToken 130, // 160: openshell.v1.ProviderProfileCredential.refresh:type_name -> openshell.v1.ProviderCredentialRefresh 126, // 161: openshell.v1.ProviderProfileCredential.token_grant:type_name -> openshell.v1.ProviderCredentialTokenGrant 9, // 162: openshell.v1.ProviderCredentialRefresh.strategy:type_name -> openshell.v1.ProviderCredentialRefreshStrategy - 279, // 163: openshell.v1.ProviderCredentialRefresh.refresh_before:type_name -> google.protobuf.Duration - 279, // 164: openshell.v1.ProviderCredentialRefresh.max_lifetime:type_name -> google.protobuf.Duration + 282, // 163: openshell.v1.ProviderCredentialRefresh.refresh_before:type_name -> google.protobuf.Duration + 282, // 164: openshell.v1.ProviderCredentialRefresh.max_lifetime:type_name -> google.protobuf.Duration 128, // 165: openshell.v1.ProviderCredentialRefresh.material:type_name -> openshell.v1.ProviderCredentialRefreshMaterial 129, // 166: openshell.v1.ProviderCredentialRefresh.additional_outputs:type_name -> openshell.v1.ProviderCredentialRefreshOutput 9, // 167: openshell.v1.ProviderCredentialRefreshStatus.strategy:type_name -> openshell.v1.ProviderCredentialRefreshStrategy - 275, // 168: openshell.v1.ProviderCredentialRefreshStatus.expiration_time:type_name -> google.protobuf.Timestamp - 275, // 169: openshell.v1.ProviderCredentialRefreshStatus.next_refresh_time:type_name -> google.protobuf.Timestamp - 275, // 170: openshell.v1.ProviderCredentialRefreshStatus.last_refresh_time:type_name -> google.protobuf.Timestamp + 278, // 168: openshell.v1.ProviderCredentialRefreshStatus.expiration_time:type_name -> google.protobuf.Timestamp + 278, // 169: openshell.v1.ProviderCredentialRefreshStatus.next_refresh_time:type_name -> google.protobuf.Timestamp + 278, // 170: openshell.v1.ProviderCredentialRefreshStatus.last_refresh_time:type_name -> google.protobuf.Timestamp 15, // 171: openshell.v1.ProviderCredentialRefreshStatus.recovery_action:type_name -> openshell.v1.ProviderCredentialRefreshRecoveryAction - 275, // 172: openshell.v1.ProviderCredentialRefreshStatus.last_error_time:type_name -> google.protobuf.Timestamp - 280, // 173: openshell.v1.GetProviderRefreshStatusRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 131, // 174: openshell.v1.GetProviderRefreshStatusResponse.credentials:type_name -> openshell.v1.ProviderCredentialRefreshStatus - 280, // 175: openshell.v1.ConfigureProviderRefreshRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 9, // 176: openshell.v1.ConfigureProviderRefreshRequest.strategy:type_name -> openshell.v1.ProviderCredentialRefreshStrategy - 264, // 177: openshell.v1.ConfigureProviderRefreshRequest.material:type_name -> openshell.v1.ConfigureProviderRefreshRequest.MaterialEntry - 275, // 178: openshell.v1.ConfigureProviderRefreshRequest.expiration_time:type_name -> google.protobuf.Timestamp - 131, // 179: openshell.v1.ConfigureProviderRefreshResponse.status:type_name -> openshell.v1.ProviderCredentialRefreshStatus - 280, // 180: openshell.v1.RotateProviderCredentialRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 131, // 181: openshell.v1.RotateProviderCredentialResponse.status:type_name -> openshell.v1.ProviderCredentialRefreshStatus - 280, // 182: openshell.v1.DeleteProviderRefreshRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 17, // 183: openshell.v1.DeleteProviderRefreshResponse.outcome:type_name -> openshell.v1.DeletionOutcome - 10, // 184: openshell.v1.ProviderProfile.category:type_name -> openshell.v1.ProviderProfileCategory - 127, // 185: openshell.v1.ProviderProfile.credentials:type_name -> openshell.v1.ProviderProfileCredential - 283, // 186: openshell.v1.ProviderProfile.endpoints:type_name -> openshell.sandbox.v1.NetworkEndpoint - 284, // 187: openshell.v1.ProviderProfile.binaries:type_name -> openshell.sandbox.v1.NetworkBinary - 132, // 188: openshell.v1.ProviderProfile.discovery:type_name -> openshell.v1.ProviderProfileDiscovery - 265, // 189: openshell.v1.ProviderProfile.annotations:type_name -> openshell.v1.ProviderProfile.AnnotationsEntry - 142, // 190: openshell.v1.ProviderProfile.files:type_name -> openshell.v1.ProviderProfileFile - 141, // 191: openshell.v1.ProviderProfileResponse.profile:type_name -> openshell.v1.ProviderProfile - 141, // 192: openshell.v1.ListProviderProfilesResponse.profiles:type_name -> openshell.v1.ProviderProfile - 280, // 193: openshell.v1.ImportProviderProfilesRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 122, // 194: openshell.v1.ImportProviderProfilesRequest.profiles:type_name -> openshell.v1.ProviderProfileImportItem - 123, // 195: openshell.v1.ImportProviderProfilesResponse.diagnostics:type_name -> openshell.v1.ProviderProfileDiagnostic - 141, // 196: openshell.v1.ImportProviderProfilesResponse.profiles:type_name -> openshell.v1.ProviderProfile - 280, // 197: openshell.v1.UpdateProviderProfilesRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 122, // 198: openshell.v1.UpdateProviderProfilesRequest.profile:type_name -> openshell.v1.ProviderProfileImportItem - 123, // 199: openshell.v1.UpdateProviderProfilesResponse.diagnostics:type_name -> openshell.v1.ProviderProfileDiagnostic - 141, // 200: openshell.v1.UpdateProviderProfilesResponse.profile:type_name -> openshell.v1.ProviderProfile - 280, // 201: openshell.v1.LintProviderProfilesRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 122, // 202: openshell.v1.LintProviderProfilesRequest.profiles:type_name -> openshell.v1.ProviderProfileImportItem - 123, // 203: openshell.v1.LintProviderProfilesResponse.diagnostics:type_name -> openshell.v1.ProviderProfileDiagnostic - 17, // 204: openshell.v1.DeleteProviderResponse.outcome:type_name -> openshell.v1.DeletionOutcome - 280, // 205: openshell.v1.DeleteProviderProfileRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 17, // 206: openshell.v1.DeleteProviderProfileResponse.outcome:type_name -> openshell.v1.DeletionOutcome - 155, // 207: openshell.v1.StaticCredentialBinding.endpoints:type_name -> openshell.v1.StaticCredentialEndpointBinding - 266, // 208: openshell.v1.GetSandboxProviderEnvironmentResponse.environment:type_name -> openshell.v1.GetSandboxProviderEnvironmentResponse.EnvironmentEntry - 267, // 209: openshell.v1.GetSandboxProviderEnvironmentResponse.credential_expiration_times:type_name -> openshell.v1.GetSandboxProviderEnvironmentResponse.CredentialExpirationTimesEntry - 268, // 210: openshell.v1.GetSandboxProviderEnvironmentResponse.dynamic_credentials:type_name -> openshell.v1.GetSandboxProviderEnvironmentResponse.DynamicCredentialsEntry - 269, // 211: openshell.v1.GetSandboxProviderEnvironmentResponse.static_credential_bindings:type_name -> openshell.v1.GetSandboxProviderEnvironmentResponse.StaticCredentialBindingsEntry - 4, // 212: openshell.v1.GetSandboxProviderEnvironmentResponse.readiness_reason:type_name -> openshell.v1.ProviderReadinessReason - 270, // 213: openshell.v1.GetSandboxProviderEnvironmentResponse.files:type_name -> openshell.v1.GetSandboxProviderEnvironmentResponse.FilesEntry - 279, // 214: openshell.v1.ExchangeProviderSubjectTokenResponse.expires_after:type_name -> google.protobuf.Duration - 280, // 215: openshell.v1.UpdateConfigRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 277, // 216: openshell.v1.UpdateConfigRequest.policy:type_name -> openshell.sandbox.v1.SandboxPolicy - 285, // 217: openshell.v1.UpdateConfigRequest.setting_value:type_name -> openshell.sandbox.v1.SettingValue - 161, // 218: openshell.v1.UpdateConfigRequest.merge_operations:type_name -> openshell.v1.PolicyMergeOperation - 271, // 219: openshell.v1.UpdateConfigRequest.annotations:type_name -> openshell.v1.UpdateConfigRequest.AnnotationsEntry - 162, // 220: openshell.v1.PolicyMergeOperation.add_rule:type_name -> openshell.v1.AddNetworkRule - 163, // 221: openshell.v1.PolicyMergeOperation.remove_endpoint:type_name -> openshell.v1.RemoveNetworkEndpoint - 164, // 222: openshell.v1.PolicyMergeOperation.remove_rule:type_name -> openshell.v1.RemoveNetworkRule - 166, // 223: openshell.v1.PolicyMergeOperation.add_deny_rules:type_name -> openshell.v1.AddDenyRules - 167, // 224: openshell.v1.PolicyMergeOperation.add_allow_rules:type_name -> openshell.v1.AddAllowRules - 168, // 225: openshell.v1.PolicyMergeOperation.remove_binary:type_name -> openshell.v1.RemoveNetworkBinary - 286, // 226: openshell.v1.AddNetworkRule.rule:type_name -> openshell.sandbox.v1.NetworkPolicyRule - 284, // 227: openshell.v1.L7RuleTarget.binaries:type_name -> openshell.sandbox.v1.NetworkBinary - 287, // 228: openshell.v1.AddDenyRules.deny_rules:type_name -> openshell.sandbox.v1.L7DenyRule - 165, // 229: openshell.v1.AddDenyRules.target:type_name -> openshell.v1.L7RuleTarget - 288, // 230: openshell.v1.AddAllowRules.rules:type_name -> openshell.sandbox.v1.L7Rule - 165, // 231: openshell.v1.AddAllowRules.target:type_name -> openshell.v1.L7RuleTarget - 272, // 232: openshell.v1.UpdateConfigResponse.annotations:type_name -> openshell.v1.UpdateConfigResponse.AnnotationsEntry - 280, // 233: openshell.v1.GetSandboxPolicyStatusRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 179, // 234: openshell.v1.GetSandboxPolicyStatusResponse.revision:type_name -> openshell.v1.SandboxPolicyRevision - 280, // 235: openshell.v1.ListSandboxPoliciesRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 179, // 236: openshell.v1.ListSandboxPoliciesResponse.revisions:type_name -> openshell.v1.SandboxPolicyRevision - 12, // 237: openshell.v1.ReportPolicyStatusRequest.status:type_name -> openshell.v1.PolicyStatus - 11, // 238: openshell.v1.SandboxConfigurationAdmission.state:type_name -> openshell.v1.ConfigurationAdmissionState - 176, // 239: openshell.v1.ReportSandboxConfigurationRequest.admission:type_name -> openshell.v1.SandboxConfigurationAdmission - 12, // 240: openshell.v1.SandboxPolicyRevision.status:type_name -> openshell.v1.PolicyStatus - 275, // 241: openshell.v1.SandboxPolicyRevision.created_time:type_name -> google.protobuf.Timestamp - 275, // 242: openshell.v1.SandboxPolicyRevision.loaded_time:type_name -> google.protobuf.Timestamp - 277, // 243: openshell.v1.SandboxPolicyRevision.policy:type_name -> openshell.sandbox.v1.SandboxPolicy - 273, // 244: openshell.v1.SandboxPolicyRevision.provenance:type_name -> openshell.v1.SandboxPolicyRevision.ProvenanceEntry - 280, // 245: openshell.v1.GetSandboxLogsRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 275, // 246: openshell.v1.GetSandboxLogsRequest.since_time:type_name -> google.protobuf.Timestamp - 111, // 247: openshell.v1.PushSandboxLogsRequest.logs:type_name -> openshell.v1.SandboxLogLine - 111, // 248: openshell.v1.GetSandboxLogsResponse.logs:type_name -> openshell.v1.SandboxLogLine - 186, // 249: openshell.v1.SupervisorMessage.hello:type_name -> openshell.v1.SupervisorHello - 189, // 250: openshell.v1.SupervisorMessage.heartbeat:type_name -> openshell.v1.SupervisorHeartbeat - 202, // 251: openshell.v1.SupervisorMessage.relay_open_result:type_name -> openshell.v1.RelayOpenResult - 203, // 252: openshell.v1.SupervisorMessage.relay_close:type_name -> openshell.v1.RelayClose - 187, // 253: openshell.v1.GatewayMessage.session_accepted:type_name -> openshell.v1.SessionAccepted - 188, // 254: openshell.v1.GatewayMessage.session_rejected:type_name -> openshell.v1.SessionRejected - 190, // 255: openshell.v1.GatewayMessage.heartbeat:type_name -> openshell.v1.GatewayHeartbeat - 195, // 256: openshell.v1.GatewayMessage.relay_open:type_name -> openshell.v1.RelayOpen - 203, // 257: openshell.v1.GatewayMessage.relay_close:type_name -> openshell.v1.RelayClose - 279, // 258: openshell.v1.SessionAccepted.heartbeat_interval:type_name -> google.protobuf.Duration - 196, // 259: openshell.v1.RelayOpen.ssh:type_name -> openshell.v1.SshRelayTarget - 197, // 260: openshell.v1.RelayOpen.tcp:type_name -> openshell.v1.TcpRelayTarget - 198, // 261: openshell.v1.RelayFrame.init:type_name -> openshell.v1.RelayInit - 195, // 262: openshell.v1.PeerRelayInit.relay_open:type_name -> openshell.v1.RelayOpen - 200, // 263: openshell.v1.PeerRelayFrame.init:type_name -> openshell.v1.PeerRelayInit - 275, // 264: openshell.v1.DenialSummary.first_seen_time:type_name -> google.protobuf.Timestamp - 275, // 265: openshell.v1.DenialSummary.last_seen_time:type_name -> google.protobuf.Timestamp - 204, // 266: openshell.v1.DenialSummary.l7_request_samples:type_name -> openshell.v1.L7RequestSample - 206, // 267: openshell.v1.NetworkActivitySummary.denials_by_group:type_name -> openshell.v1.DenialGroupCount - 286, // 268: openshell.v1.PolicyChunk.proposed_rule:type_name -> openshell.sandbox.v1.NetworkPolicyRule - 275, // 269: openshell.v1.PolicyChunk.created_time:type_name -> google.protobuf.Timestamp - 275, // 270: openshell.v1.PolicyChunk.decided_time:type_name -> google.protobuf.Timestamp - 275, // 271: openshell.v1.PolicyChunk.first_seen_time:type_name -> google.protobuf.Timestamp - 275, // 272: openshell.v1.PolicyChunk.last_seen_time:type_name -> google.protobuf.Timestamp - 277, // 273: openshell.v1.PolicyChunk.current_effective_policy:type_name -> openshell.sandbox.v1.SandboxPolicy - 277, // 274: openshell.v1.PolicyChunk.candidate_effective_policy:type_name -> openshell.sandbox.v1.SandboxPolicy - 280, // 275: openshell.v1.SubmitPolicyAnalysisRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 205, // 276: openshell.v1.SubmitPolicyAnalysisRequest.summaries:type_name -> openshell.v1.DenialSummary - 208, // 277: openshell.v1.SubmitPolicyAnalysisRequest.proposed_chunks:type_name -> openshell.v1.PolicyChunk - 207, // 278: openshell.v1.SubmitPolicyAnalysisRequest.network_activity_summaries:type_name -> openshell.v1.NetworkActivitySummary - 280, // 279: openshell.v1.GetDraftPolicyRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 208, // 280: openshell.v1.GetDraftPolicyResponse.chunks:type_name -> openshell.v1.PolicyChunk - 275, // 281: openshell.v1.GetDraftPolicyResponse.last_analyzed_time:type_name -> google.protobuf.Timestamp - 280, // 282: openshell.v1.ApproveDraftChunkRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 280, // 283: openshell.v1.RejectDraftChunkRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 280, // 284: openshell.v1.ApproveAllDraftChunksRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 218, // 285: openshell.v1.ApproveAllDraftChunksRequest.approvals:type_name -> openshell.v1.DraftChunkApproval - 280, // 286: openshell.v1.EditDraftChunkRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 286, // 287: openshell.v1.EditDraftChunkRequest.proposed_rule:type_name -> openshell.sandbox.v1.NetworkPolicyRule - 280, // 288: openshell.v1.UndoDraftChunkRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 280, // 289: openshell.v1.ClearDraftChunksRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 280, // 290: openshell.v1.GetDraftHistoryRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 275, // 291: openshell.v1.DraftHistoryEntry.event_time:type_name -> google.protobuf.Timestamp - 228, // 292: openshell.v1.GetDraftHistoryResponse.entries:type_name -> openshell.v1.DraftHistoryEntry - 274, // 293: openshell.v1.CreateWorkspaceRequest.labels:type_name -> openshell.v1.CreateWorkspaceRequest.LabelsEntry - 289, // 294: openshell.v1.CreateWorkspaceResponse.workspace:type_name -> openshell.datamodel.v1.Workspace - 289, // 295: openshell.v1.GetWorkspaceResponse.workspace:type_name -> openshell.datamodel.v1.Workspace - 289, // 296: openshell.v1.ListWorkspacesResponse.workspaces:type_name -> openshell.datamodel.v1.Workspace - 17, // 297: openshell.v1.DeleteWorkspaceResponse.outcome:type_name -> openshell.v1.DeletionOutcome - 276, // 298: openshell.v1.WorkspaceMember.metadata:type_name -> openshell.datamodel.v1.ObjectMeta - 14, // 299: openshell.v1.WorkspaceMember.role:type_name -> openshell.v1.WorkspaceRole - 280, // 300: openshell.v1.AddWorkspaceMemberRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 14, // 301: openshell.v1.AddWorkspaceMemberRequest.role:type_name -> openshell.v1.WorkspaceRole - 238, // 302: openshell.v1.AddWorkspaceMemberResponse.member:type_name -> openshell.v1.WorkspaceMember - 280, // 303: openshell.v1.RemoveWorkspaceMemberRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 17, // 304: openshell.v1.RemoveWorkspaceMemberResponse.outcome:type_name -> openshell.v1.DeletionOutcome - 280, // 305: openshell.v1.ListWorkspaceMembersRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector - 238, // 306: openshell.v1.ListWorkspaceMembersResponse.members:type_name -> openshell.v1.WorkspaceMember - 275, // 307: openshell.v1.ExtensionServiceCredential.expiration_time:type_name -> google.protobuf.Timestamp - 18, // 308: openshell.v1.EndpointObservation.result:type_name -> openshell.v1.EndpointResult - 246, // 309: openshell.v1.ReportEndpointStatusRequest.observations:type_name -> openshell.v1.EndpointObservation - 18, // 310: openshell.v1.EndpointStatus.last_result:type_name -> openshell.v1.EndpointResult - 275, // 311: openshell.v1.EndpointStatus.last_reported_time:type_name -> google.protobuf.Timestamp - 275, // 312: openshell.v1.SandboxProvisioning.configuration_change_time:type_name -> google.protobuf.Timestamp - 275, // 313: openshell.v1.SandboxProvisioning.first_rejection_time:type_name -> google.protobuf.Timestamp - 275, // 314: openshell.v1.SandboxProvisioning.deadline:type_name -> google.protobuf.Timestamp - 275, // 315: openshell.v1.SandboxProvisioning.timeout_time:type_name -> google.protobuf.Timestamp - 275, // 316: openshell.v1.SandboxProvisioning.cleanup_completed_time:type_name -> google.protobuf.Timestamp - 275, // 317: openshell.v1.SandboxProvisioning.cleanup_retry_time:type_name -> google.protobuf.Timestamp - 275, // 318: openshell.v1.SandboxProvisioning.attachment_change_time:type_name -> google.protobuf.Timestamp - 19, // 319: openshell.v1.SandboxServiceExposure.authorization_mode:type_name -> openshell.v1.ServiceAuthorizationMode - 275, // 320: openshell.v1.UpdateProviderRequest.CredentialExpirationTimesEntry.value:type_name -> google.protobuf.Timestamp - 275, // 321: openshell.v1.GetSandboxProviderEnvironmentResponse.CredentialExpirationTimesEntry.value:type_name -> google.protobuf.Timestamp - 127, // 322: openshell.v1.GetSandboxProviderEnvironmentResponse.DynamicCredentialsEntry.value:type_name -> openshell.v1.ProviderProfileCredential - 156, // 323: openshell.v1.GetSandboxProviderEnvironmentResponse.StaticCredentialBindingsEntry.value:type_name -> openshell.v1.StaticCredentialBinding - 24, // 324: openshell.v1.OpenShell.Health:input_type -> openshell.v1.HealthRequest - 26, // 325: openshell.v1.OpenShell.GetCurrentUser:input_type -> openshell.v1.GetCurrentUserRequest - 28, // 326: openshell.v1.OpenShell.GetGatewayInfo:input_type -> openshell.v1.GetGatewayInfoRequest - 52, // 327: openshell.v1.OpenShell.CreateSandbox:input_type -> openshell.v1.CreateSandboxRequest - 60, // 328: openshell.v1.OpenShell.BeginRootfsTarStaging:input_type -> openshell.v1.BeginRootfsTarStagingRequest - 62, // 329: openshell.v1.OpenShell.GetSandbox:input_type -> openshell.v1.GetSandboxRequest - 63, // 330: openshell.v1.OpenShell.ListSandboxes:input_type -> openshell.v1.ListSandboxesRequest - 53, // 331: openshell.v1.OpenShell.CreateSandboxTemplate:input_type -> openshell.v1.CreateSandboxTemplateRequest - 54, // 332: openshell.v1.OpenShell.GetSandboxTemplate:input_type -> openshell.v1.GetSandboxTemplateRequest - 55, // 333: openshell.v1.OpenShell.ListSandboxTemplates:input_type -> openshell.v1.ListSandboxTemplatesRequest - 56, // 334: openshell.v1.OpenShell.DeleteSandboxTemplate:input_type -> openshell.v1.DeleteSandboxTemplateRequest - 64, // 335: openshell.v1.OpenShell.ListSandboxProviders:input_type -> openshell.v1.ListSandboxProvidersRequest - 65, // 336: openshell.v1.OpenShell.AttachSandboxProvider:input_type -> openshell.v1.AttachSandboxProviderRequest - 66, // 337: openshell.v1.OpenShell.DetachSandboxProvider:input_type -> openshell.v1.DetachSandboxProviderRequest - 82, // 338: openshell.v1.OpenShell.GetSandboxProviderStatus:input_type -> openshell.v1.GetSandboxProviderStatusRequest - 67, // 339: openshell.v1.OpenShell.DeleteSandbox:input_type -> openshell.v1.DeleteSandboxRequest - 68, // 340: openshell.v1.OpenShell.StopSandbox:input_type -> openshell.v1.StopSandboxRequest - 69, // 341: openshell.v1.OpenShell.StartSandbox:input_type -> openshell.v1.StartSandboxRequest - 87, // 342: openshell.v1.OpenShell.CreateSshSession:input_type -> openshell.v1.CreateSshSessionRequest - 89, // 343: openshell.v1.OpenShell.ExposeService:input_type -> openshell.v1.ExposeServiceRequest - 90, // 344: openshell.v1.OpenShell.GetService:input_type -> openshell.v1.GetServiceRequest - 91, // 345: openshell.v1.OpenShell.ListServices:input_type -> openshell.v1.ListServicesRequest - 93, // 346: openshell.v1.OpenShell.DeleteService:input_type -> openshell.v1.DeleteServiceRequest - 97, // 347: openshell.v1.OpenShell.RevokeSshSession:input_type -> openshell.v1.RevokeSshSessionRequest - 99, // 348: openshell.v1.OpenShell.ExecSandbox:input_type -> openshell.v1.ExecSandboxRequest - 105, // 349: openshell.v1.OpenShell.ForwardTcp:input_type -> openshell.v1.TcpForwardFrame - 106, // 350: openshell.v1.OpenShell.ExecSandboxInteractive:input_type -> openshell.v1.ExecSandboxInput - 113, // 351: openshell.v1.OpenShell.CreateProvider:input_type -> openshell.v1.CreateProviderRequest - 114, // 352: openshell.v1.OpenShell.GetProvider:input_type -> openshell.v1.GetProviderRequest - 115, // 353: openshell.v1.OpenShell.ListProviders:input_type -> openshell.v1.ListProvidersRequest - 120, // 354: openshell.v1.OpenShell.ListProviderProfiles:input_type -> openshell.v1.ListProviderProfilesRequest - 121, // 355: openshell.v1.OpenShell.GetProviderProfile:input_type -> openshell.v1.GetProviderProfileRequest - 145, // 356: openshell.v1.OpenShell.ImportProviderProfiles:input_type -> openshell.v1.ImportProviderProfilesRequest - 147, // 357: openshell.v1.OpenShell.UpdateProviderProfiles:input_type -> openshell.v1.UpdateProviderProfilesRequest - 149, // 358: openshell.v1.OpenShell.LintProviderProfiles:input_type -> openshell.v1.LintProviderProfilesRequest - 116, // 359: openshell.v1.OpenShell.UpdateProvider:input_type -> openshell.v1.UpdateProviderRequest - 133, // 360: openshell.v1.OpenShell.GetProviderRefreshStatus:input_type -> openshell.v1.GetProviderRefreshStatusRequest - 135, // 361: openshell.v1.OpenShell.ConfigureProviderRefresh:input_type -> openshell.v1.ConfigureProviderRefreshRequest - 137, // 362: openshell.v1.OpenShell.RotateProviderCredential:input_type -> openshell.v1.RotateProviderCredentialRequest - 139, // 363: openshell.v1.OpenShell.DeleteProviderRefresh:input_type -> openshell.v1.DeleteProviderRefreshRequest - 117, // 364: openshell.v1.OpenShell.DeleteProvider:input_type -> openshell.v1.DeleteProviderRequest - 152, // 365: openshell.v1.OpenShell.DeleteProviderProfile:input_type -> openshell.v1.DeleteProviderProfileRequest - 290, // 366: openshell.v1.OpenShell.GetSandboxConfig:input_type -> openshell.sandbox.v1.GetSandboxConfigRequest - 291, // 367: openshell.v1.OpenShell.GetGatewayConfig:input_type -> openshell.sandbox.v1.GetGatewayConfigRequest - 160, // 368: openshell.v1.OpenShell.UpdateConfig:input_type -> openshell.v1.UpdateConfigRequest - 170, // 369: openshell.v1.OpenShell.GetSandboxPolicyStatus:input_type -> openshell.v1.GetSandboxPolicyStatusRequest - 172, // 370: openshell.v1.OpenShell.ListSandboxPolicies:input_type -> openshell.v1.ListSandboxPoliciesRequest - 174, // 371: openshell.v1.OpenShell.ReportPolicyStatus:input_type -> openshell.v1.ReportPolicyStatusRequest - 247, // 372: openshell.v1.OpenShell.ReportEndpointStatus:input_type -> openshell.v1.ReportEndpointStatusRequest - 84, // 373: openshell.v1.OpenShell.ReportProviderReadiness:input_type -> openshell.v1.ReportProviderReadinessRequest - 177, // 374: openshell.v1.OpenShell.ReportSandboxConfiguration:input_type -> openshell.v1.ReportSandboxConfigurationRequest - 154, // 375: openshell.v1.OpenShell.GetSandboxProviderEnvironment:input_type -> openshell.v1.GetSandboxProviderEnvironmentRequest - 158, // 376: openshell.v1.OpenShell.ExchangeProviderSubjectToken:input_type -> openshell.v1.ExchangeProviderSubjectTokenRequest - 180, // 377: openshell.v1.OpenShell.GetSandboxLogs:input_type -> openshell.v1.GetSandboxLogsRequest - 181, // 378: openshell.v1.OpenShell.PushSandboxLogs:input_type -> openshell.v1.PushSandboxLogsRequest - 184, // 379: openshell.v1.OpenShell.ConnectSupervisor:input_type -> openshell.v1.SupervisorMessage - 191, // 380: openshell.v1.OpenShell.ReportMainProcessExit:input_type -> openshell.v1.ReportMainProcessExitRequest - 193, // 381: openshell.v1.OpenShell.FinalizeMainProcessExit:input_type -> openshell.v1.FinalizeMainProcessExitRequest - 199, // 382: openshell.v1.OpenShell.RelayStream:input_type -> openshell.v1.RelayFrame - 201, // 383: openshell.v1.OpenShell.PeerRelay:input_type -> openshell.v1.PeerRelayFrame - 84, // 384: openshell.v1.OpenShell.PeerReportProviderReadiness:input_type -> openshell.v1.ReportProviderReadinessRequest - 247, // 385: openshell.v1.OpenShell.PeerReportEndpointStatus:input_type -> openshell.v1.ReportEndpointStatusRequest - 82, // 386: openshell.v1.OpenShell.PeerGetSandboxProviderStatus:input_type -> openshell.v1.GetSandboxProviderStatusRequest - 109, // 387: openshell.v1.OpenShell.WatchSandbox:input_type -> openshell.v1.WatchSandboxRequest - 210, // 388: openshell.v1.OpenShell.SubmitPolicyAnalysis:input_type -> openshell.v1.SubmitPolicyAnalysisRequest - 212, // 389: openshell.v1.OpenShell.GetDraftPolicy:input_type -> openshell.v1.GetDraftPolicyRequest - 214, // 390: openshell.v1.OpenShell.ApproveDraftChunk:input_type -> openshell.v1.ApproveDraftChunkRequest - 216, // 391: openshell.v1.OpenShell.RejectDraftChunk:input_type -> openshell.v1.RejectDraftChunkRequest - 219, // 392: openshell.v1.OpenShell.ApproveAllDraftChunks:input_type -> openshell.v1.ApproveAllDraftChunksRequest - 221, // 393: openshell.v1.OpenShell.EditDraftChunk:input_type -> openshell.v1.EditDraftChunkRequest - 223, // 394: openshell.v1.OpenShell.UndoDraftChunk:input_type -> openshell.v1.UndoDraftChunkRequest - 225, // 395: openshell.v1.OpenShell.ClearDraftChunks:input_type -> openshell.v1.ClearDraftChunksRequest - 227, // 396: openshell.v1.OpenShell.GetDraftHistory:input_type -> openshell.v1.GetDraftHistoryRequest - 20, // 397: openshell.v1.OpenShell.IssueSandboxToken:input_type -> openshell.v1.IssueSandboxTokenRequest - 22, // 398: openshell.v1.OpenShell.RefreshSandboxToken:input_type -> openshell.v1.RefreshSandboxTokenRequest - 230, // 399: openshell.v1.OpenShell.CreateWorkspace:input_type -> openshell.v1.CreateWorkspaceRequest - 232, // 400: openshell.v1.OpenShell.GetWorkspace:input_type -> openshell.v1.GetWorkspaceRequest - 234, // 401: openshell.v1.OpenShell.ListWorkspaces:input_type -> openshell.v1.ListWorkspacesRequest - 236, // 402: openshell.v1.OpenShell.DeleteWorkspace:input_type -> openshell.v1.DeleteWorkspaceRequest - 239, // 403: openshell.v1.OpenShell.AddWorkspaceMember:input_type -> openshell.v1.AddWorkspaceMemberRequest - 241, // 404: openshell.v1.OpenShell.RemoveWorkspaceMember:input_type -> openshell.v1.RemoveWorkspaceMemberRequest - 243, // 405: openshell.v1.OpenShell.ListWorkspaceMembers:input_type -> openshell.v1.ListWorkspaceMembersRequest - 25, // 406: openshell.v1.OpenShell.Health:output_type -> openshell.v1.HealthResponse - 27, // 407: openshell.v1.OpenShell.GetCurrentUser:output_type -> openshell.v1.GetCurrentUserResponse - 29, // 408: openshell.v1.OpenShell.GetGatewayInfo:output_type -> openshell.v1.GetGatewayInfoResponse - 70, // 409: openshell.v1.OpenShell.CreateSandbox:output_type -> openshell.v1.SandboxResponse - 61, // 410: openshell.v1.OpenShell.BeginRootfsTarStaging:output_type -> openshell.v1.BeginRootfsTarStagingResponse - 70, // 411: openshell.v1.OpenShell.GetSandbox:output_type -> openshell.v1.SandboxResponse - 71, // 412: openshell.v1.OpenShell.ListSandboxes:output_type -> openshell.v1.ListSandboxesResponse - 57, // 413: openshell.v1.OpenShell.CreateSandboxTemplate:output_type -> openshell.v1.SandboxTemplateResponse - 57, // 414: openshell.v1.OpenShell.GetSandboxTemplate:output_type -> openshell.v1.SandboxTemplateResponse - 58, // 415: openshell.v1.OpenShell.ListSandboxTemplates:output_type -> openshell.v1.ListSandboxTemplatesResponse - 59, // 416: openshell.v1.OpenShell.DeleteSandboxTemplate:output_type -> openshell.v1.DeleteSandboxTemplateResponse - 72, // 417: openshell.v1.OpenShell.ListSandboxProviders:output_type -> openshell.v1.ListSandboxProvidersResponse - 73, // 418: openshell.v1.OpenShell.AttachSandboxProvider:output_type -> openshell.v1.AttachSandboxProviderResponse - 74, // 419: openshell.v1.OpenShell.DetachSandboxProvider:output_type -> openshell.v1.DetachSandboxProviderResponse - 83, // 420: openshell.v1.OpenShell.GetSandboxProviderStatus:output_type -> openshell.v1.GetSandboxProviderStatusResponse - 86, // 421: openshell.v1.OpenShell.DeleteSandbox:output_type -> openshell.v1.DeleteSandboxResponse - 70, // 422: openshell.v1.OpenShell.StopSandbox:output_type -> openshell.v1.SandboxResponse - 70, // 423: openshell.v1.OpenShell.StartSandbox:output_type -> openshell.v1.SandboxResponse - 88, // 424: openshell.v1.OpenShell.CreateSshSession:output_type -> openshell.v1.CreateSshSessionResponse - 96, // 425: openshell.v1.OpenShell.ExposeService:output_type -> openshell.v1.ServiceEndpointResponse - 96, // 426: openshell.v1.OpenShell.GetService:output_type -> openshell.v1.ServiceEndpointResponse - 92, // 427: openshell.v1.OpenShell.ListServices:output_type -> openshell.v1.ListServicesResponse - 94, // 428: openshell.v1.OpenShell.DeleteService:output_type -> openshell.v1.DeleteServiceResponse - 98, // 429: openshell.v1.OpenShell.RevokeSshSession:output_type -> openshell.v1.RevokeSshSessionResponse - 103, // 430: openshell.v1.OpenShell.ExecSandbox:output_type -> openshell.v1.ExecSandboxEvent - 105, // 431: openshell.v1.OpenShell.ForwardTcp:output_type -> openshell.v1.TcpForwardFrame - 103, // 432: openshell.v1.OpenShell.ExecSandboxInteractive:output_type -> openshell.v1.ExecSandboxEvent - 118, // 433: openshell.v1.OpenShell.CreateProvider:output_type -> openshell.v1.ProviderResponse - 118, // 434: openshell.v1.OpenShell.GetProvider:output_type -> openshell.v1.ProviderResponse - 119, // 435: openshell.v1.OpenShell.ListProviders:output_type -> openshell.v1.ListProvidersResponse - 144, // 436: openshell.v1.OpenShell.ListProviderProfiles:output_type -> openshell.v1.ListProviderProfilesResponse - 143, // 437: openshell.v1.OpenShell.GetProviderProfile:output_type -> openshell.v1.ProviderProfileResponse - 146, // 438: openshell.v1.OpenShell.ImportProviderProfiles:output_type -> openshell.v1.ImportProviderProfilesResponse - 148, // 439: openshell.v1.OpenShell.UpdateProviderProfiles:output_type -> openshell.v1.UpdateProviderProfilesResponse - 150, // 440: openshell.v1.OpenShell.LintProviderProfiles:output_type -> openshell.v1.LintProviderProfilesResponse - 118, // 441: openshell.v1.OpenShell.UpdateProvider:output_type -> openshell.v1.ProviderResponse - 134, // 442: openshell.v1.OpenShell.GetProviderRefreshStatus:output_type -> openshell.v1.GetProviderRefreshStatusResponse - 136, // 443: openshell.v1.OpenShell.ConfigureProviderRefresh:output_type -> openshell.v1.ConfigureProviderRefreshResponse - 138, // 444: openshell.v1.OpenShell.RotateProviderCredential:output_type -> openshell.v1.RotateProviderCredentialResponse - 140, // 445: openshell.v1.OpenShell.DeleteProviderRefresh:output_type -> openshell.v1.DeleteProviderRefreshResponse - 151, // 446: openshell.v1.OpenShell.DeleteProvider:output_type -> openshell.v1.DeleteProviderResponse - 153, // 447: openshell.v1.OpenShell.DeleteProviderProfile:output_type -> openshell.v1.DeleteProviderProfileResponse - 292, // 448: openshell.v1.OpenShell.GetSandboxConfig:output_type -> openshell.sandbox.v1.GetSandboxConfigResponse - 293, // 449: openshell.v1.OpenShell.GetGatewayConfig:output_type -> openshell.sandbox.v1.GetGatewayConfigResponse - 169, // 450: openshell.v1.OpenShell.UpdateConfig:output_type -> openshell.v1.UpdateConfigResponse - 171, // 451: openshell.v1.OpenShell.GetSandboxPolicyStatus:output_type -> openshell.v1.GetSandboxPolicyStatusResponse - 173, // 452: openshell.v1.OpenShell.ListSandboxPolicies:output_type -> openshell.v1.ListSandboxPoliciesResponse - 175, // 453: openshell.v1.OpenShell.ReportPolicyStatus:output_type -> openshell.v1.ReportPolicyStatusResponse - 248, // 454: openshell.v1.OpenShell.ReportEndpointStatus:output_type -> openshell.v1.ReportEndpointStatusResponse - 85, // 455: openshell.v1.OpenShell.ReportProviderReadiness:output_type -> openshell.v1.ReportProviderReadinessResponse - 178, // 456: openshell.v1.OpenShell.ReportSandboxConfiguration:output_type -> openshell.v1.ReportSandboxConfigurationResponse - 157, // 457: openshell.v1.OpenShell.GetSandboxProviderEnvironment:output_type -> openshell.v1.GetSandboxProviderEnvironmentResponse - 159, // 458: openshell.v1.OpenShell.ExchangeProviderSubjectToken:output_type -> openshell.v1.ExchangeProviderSubjectTokenResponse - 183, // 459: openshell.v1.OpenShell.GetSandboxLogs:output_type -> openshell.v1.GetSandboxLogsResponse - 182, // 460: openshell.v1.OpenShell.PushSandboxLogs:output_type -> openshell.v1.PushSandboxLogsResponse - 185, // 461: openshell.v1.OpenShell.ConnectSupervisor:output_type -> openshell.v1.GatewayMessage - 192, // 462: openshell.v1.OpenShell.ReportMainProcessExit:output_type -> openshell.v1.ReportMainProcessExitResponse - 194, // 463: openshell.v1.OpenShell.FinalizeMainProcessExit:output_type -> openshell.v1.FinalizeMainProcessExitResponse - 199, // 464: openshell.v1.OpenShell.RelayStream:output_type -> openshell.v1.RelayFrame - 201, // 465: openshell.v1.OpenShell.PeerRelay:output_type -> openshell.v1.PeerRelayFrame - 85, // 466: openshell.v1.OpenShell.PeerReportProviderReadiness:output_type -> openshell.v1.ReportProviderReadinessResponse - 248, // 467: openshell.v1.OpenShell.PeerReportEndpointStatus:output_type -> openshell.v1.ReportEndpointStatusResponse - 83, // 468: openshell.v1.OpenShell.PeerGetSandboxProviderStatus:output_type -> openshell.v1.GetSandboxProviderStatusResponse - 110, // 469: openshell.v1.OpenShell.WatchSandbox:output_type -> openshell.v1.SandboxStreamEvent - 211, // 470: openshell.v1.OpenShell.SubmitPolicyAnalysis:output_type -> openshell.v1.SubmitPolicyAnalysisResponse - 213, // 471: openshell.v1.OpenShell.GetDraftPolicy:output_type -> openshell.v1.GetDraftPolicyResponse - 215, // 472: openshell.v1.OpenShell.ApproveDraftChunk:output_type -> openshell.v1.ApproveDraftChunkResponse - 217, // 473: openshell.v1.OpenShell.RejectDraftChunk:output_type -> openshell.v1.RejectDraftChunkResponse - 220, // 474: openshell.v1.OpenShell.ApproveAllDraftChunks:output_type -> openshell.v1.ApproveAllDraftChunksResponse - 222, // 475: openshell.v1.OpenShell.EditDraftChunk:output_type -> openshell.v1.EditDraftChunkResponse - 224, // 476: openshell.v1.OpenShell.UndoDraftChunk:output_type -> openshell.v1.UndoDraftChunkResponse - 226, // 477: openshell.v1.OpenShell.ClearDraftChunks:output_type -> openshell.v1.ClearDraftChunksResponse - 229, // 478: openshell.v1.OpenShell.GetDraftHistory:output_type -> openshell.v1.GetDraftHistoryResponse - 21, // 479: openshell.v1.OpenShell.IssueSandboxToken:output_type -> openshell.v1.IssueSandboxTokenResponse - 23, // 480: openshell.v1.OpenShell.RefreshSandboxToken:output_type -> openshell.v1.RefreshSandboxTokenResponse - 231, // 481: openshell.v1.OpenShell.CreateWorkspace:output_type -> openshell.v1.CreateWorkspaceResponse - 233, // 482: openshell.v1.OpenShell.GetWorkspace:output_type -> openshell.v1.GetWorkspaceResponse - 235, // 483: openshell.v1.OpenShell.ListWorkspaces:output_type -> openshell.v1.ListWorkspacesResponse - 237, // 484: openshell.v1.OpenShell.DeleteWorkspace:output_type -> openshell.v1.DeleteWorkspaceResponse - 240, // 485: openshell.v1.OpenShell.AddWorkspaceMember:output_type -> openshell.v1.AddWorkspaceMemberResponse - 242, // 486: openshell.v1.OpenShell.RemoveWorkspaceMember:output_type -> openshell.v1.RemoveWorkspaceMemberResponse - 244, // 487: openshell.v1.OpenShell.ListWorkspaceMembers:output_type -> openshell.v1.ListWorkspaceMembersResponse - 406, // [406:488] is the sub-list for method output_type - 324, // [324:406] is the sub-list for method input_type - 324, // [324:324] is the sub-list for extension type_name - 324, // [324:324] is the sub-list for extension extendee - 0, // [0:324] is the sub-list for field type_name + 278, // 172: openshell.v1.ProviderCredentialRefreshStatus.last_error_time:type_name -> google.protobuf.Timestamp + 265, // 173: openshell.v1.ProviderProfileEnvironment.config:type_name -> openshell.v1.ProviderProfileEnvironment.ConfigEntry + 266, // 174: openshell.v1.ProviderProfileEnvironment.fixed:type_name -> openshell.v1.ProviderProfileEnvironment.FixedEntry + 283, // 175: openshell.v1.GetProviderRefreshStatusRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 131, // 176: openshell.v1.GetProviderRefreshStatusResponse.credentials:type_name -> openshell.v1.ProviderCredentialRefreshStatus + 283, // 177: openshell.v1.ConfigureProviderRefreshRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 9, // 178: openshell.v1.ConfigureProviderRefreshRequest.strategy:type_name -> openshell.v1.ProviderCredentialRefreshStrategy + 267, // 179: openshell.v1.ConfigureProviderRefreshRequest.material:type_name -> openshell.v1.ConfigureProviderRefreshRequest.MaterialEntry + 278, // 180: openshell.v1.ConfigureProviderRefreshRequest.expiration_time:type_name -> google.protobuf.Timestamp + 131, // 181: openshell.v1.ConfigureProviderRefreshResponse.status:type_name -> openshell.v1.ProviderCredentialRefreshStatus + 283, // 182: openshell.v1.RotateProviderCredentialRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 131, // 183: openshell.v1.RotateProviderCredentialResponse.status:type_name -> openshell.v1.ProviderCredentialRefreshStatus + 283, // 184: openshell.v1.DeleteProviderRefreshRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 17, // 185: openshell.v1.DeleteProviderRefreshResponse.outcome:type_name -> openshell.v1.DeletionOutcome + 10, // 186: openshell.v1.ProviderProfile.category:type_name -> openshell.v1.ProviderProfileCategory + 127, // 187: openshell.v1.ProviderProfile.credentials:type_name -> openshell.v1.ProviderProfileCredential + 286, // 188: openshell.v1.ProviderProfile.endpoints:type_name -> openshell.sandbox.v1.NetworkEndpoint + 287, // 189: openshell.v1.ProviderProfile.binaries:type_name -> openshell.sandbox.v1.NetworkBinary + 132, // 190: openshell.v1.ProviderProfile.discovery:type_name -> openshell.v1.ProviderProfileDiscovery + 268, // 191: openshell.v1.ProviderProfile.annotations:type_name -> openshell.v1.ProviderProfile.AnnotationsEntry + 143, // 192: openshell.v1.ProviderProfile.files:type_name -> openshell.v1.ProviderProfileFile + 133, // 193: openshell.v1.ProviderProfile.environment:type_name -> openshell.v1.ProviderProfileEnvironment + 142, // 194: openshell.v1.ProviderProfileResponse.profile:type_name -> openshell.v1.ProviderProfile + 142, // 195: openshell.v1.ListProviderProfilesResponse.profiles:type_name -> openshell.v1.ProviderProfile + 283, // 196: openshell.v1.ImportProviderProfilesRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 122, // 197: openshell.v1.ImportProviderProfilesRequest.profiles:type_name -> openshell.v1.ProviderProfileImportItem + 123, // 198: openshell.v1.ImportProviderProfilesResponse.diagnostics:type_name -> openshell.v1.ProviderProfileDiagnostic + 142, // 199: openshell.v1.ImportProviderProfilesResponse.profiles:type_name -> openshell.v1.ProviderProfile + 283, // 200: openshell.v1.UpdateProviderProfilesRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 122, // 201: openshell.v1.UpdateProviderProfilesRequest.profile:type_name -> openshell.v1.ProviderProfileImportItem + 123, // 202: openshell.v1.UpdateProviderProfilesResponse.diagnostics:type_name -> openshell.v1.ProviderProfileDiagnostic + 142, // 203: openshell.v1.UpdateProviderProfilesResponse.profile:type_name -> openshell.v1.ProviderProfile + 283, // 204: openshell.v1.LintProviderProfilesRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 122, // 205: openshell.v1.LintProviderProfilesRequest.profiles:type_name -> openshell.v1.ProviderProfileImportItem + 123, // 206: openshell.v1.LintProviderProfilesResponse.diagnostics:type_name -> openshell.v1.ProviderProfileDiagnostic + 17, // 207: openshell.v1.DeleteProviderResponse.outcome:type_name -> openshell.v1.DeletionOutcome + 283, // 208: openshell.v1.DeleteProviderProfileRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 17, // 209: openshell.v1.DeleteProviderProfileResponse.outcome:type_name -> openshell.v1.DeletionOutcome + 156, // 210: openshell.v1.StaticCredentialBinding.endpoints:type_name -> openshell.v1.StaticCredentialEndpointBinding + 269, // 211: openshell.v1.GetSandboxProviderEnvironmentResponse.environment:type_name -> openshell.v1.GetSandboxProviderEnvironmentResponse.EnvironmentEntry + 270, // 212: openshell.v1.GetSandboxProviderEnvironmentResponse.credential_expiration_times:type_name -> openshell.v1.GetSandboxProviderEnvironmentResponse.CredentialExpirationTimesEntry + 271, // 213: openshell.v1.GetSandboxProviderEnvironmentResponse.dynamic_credentials:type_name -> openshell.v1.GetSandboxProviderEnvironmentResponse.DynamicCredentialsEntry + 272, // 214: openshell.v1.GetSandboxProviderEnvironmentResponse.static_credential_bindings:type_name -> openshell.v1.GetSandboxProviderEnvironmentResponse.StaticCredentialBindingsEntry + 4, // 215: openshell.v1.GetSandboxProviderEnvironmentResponse.readiness_reason:type_name -> openshell.v1.ProviderReadinessReason + 273, // 216: openshell.v1.GetSandboxProviderEnvironmentResponse.files:type_name -> openshell.v1.GetSandboxProviderEnvironmentResponse.FilesEntry + 282, // 217: openshell.v1.ExchangeProviderSubjectTokenResponse.expires_after:type_name -> google.protobuf.Duration + 283, // 218: openshell.v1.UpdateConfigRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 280, // 219: openshell.v1.UpdateConfigRequest.policy:type_name -> openshell.sandbox.v1.SandboxPolicy + 288, // 220: openshell.v1.UpdateConfigRequest.setting_value:type_name -> openshell.sandbox.v1.SettingValue + 162, // 221: openshell.v1.UpdateConfigRequest.merge_operations:type_name -> openshell.v1.PolicyMergeOperation + 274, // 222: openshell.v1.UpdateConfigRequest.annotations:type_name -> openshell.v1.UpdateConfigRequest.AnnotationsEntry + 163, // 223: openshell.v1.PolicyMergeOperation.add_rule:type_name -> openshell.v1.AddNetworkRule + 164, // 224: openshell.v1.PolicyMergeOperation.remove_endpoint:type_name -> openshell.v1.RemoveNetworkEndpoint + 165, // 225: openshell.v1.PolicyMergeOperation.remove_rule:type_name -> openshell.v1.RemoveNetworkRule + 167, // 226: openshell.v1.PolicyMergeOperation.add_deny_rules:type_name -> openshell.v1.AddDenyRules + 168, // 227: openshell.v1.PolicyMergeOperation.add_allow_rules:type_name -> openshell.v1.AddAllowRules + 169, // 228: openshell.v1.PolicyMergeOperation.remove_binary:type_name -> openshell.v1.RemoveNetworkBinary + 289, // 229: openshell.v1.AddNetworkRule.rule:type_name -> openshell.sandbox.v1.NetworkPolicyRule + 287, // 230: openshell.v1.L7RuleTarget.binaries:type_name -> openshell.sandbox.v1.NetworkBinary + 290, // 231: openshell.v1.AddDenyRules.deny_rules:type_name -> openshell.sandbox.v1.L7DenyRule + 166, // 232: openshell.v1.AddDenyRules.target:type_name -> openshell.v1.L7RuleTarget + 291, // 233: openshell.v1.AddAllowRules.rules:type_name -> openshell.sandbox.v1.L7Rule + 166, // 234: openshell.v1.AddAllowRules.target:type_name -> openshell.v1.L7RuleTarget + 275, // 235: openshell.v1.UpdateConfigResponse.annotations:type_name -> openshell.v1.UpdateConfigResponse.AnnotationsEntry + 283, // 236: openshell.v1.GetSandboxPolicyStatusRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 180, // 237: openshell.v1.GetSandboxPolicyStatusResponse.revision:type_name -> openshell.v1.SandboxPolicyRevision + 283, // 238: openshell.v1.ListSandboxPoliciesRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 180, // 239: openshell.v1.ListSandboxPoliciesResponse.revisions:type_name -> openshell.v1.SandboxPolicyRevision + 12, // 240: openshell.v1.ReportPolicyStatusRequest.status:type_name -> openshell.v1.PolicyStatus + 11, // 241: openshell.v1.SandboxConfigurationAdmission.state:type_name -> openshell.v1.ConfigurationAdmissionState + 177, // 242: openshell.v1.ReportSandboxConfigurationRequest.admission:type_name -> openshell.v1.SandboxConfigurationAdmission + 12, // 243: openshell.v1.SandboxPolicyRevision.status:type_name -> openshell.v1.PolicyStatus + 278, // 244: openshell.v1.SandboxPolicyRevision.created_time:type_name -> google.protobuf.Timestamp + 278, // 245: openshell.v1.SandboxPolicyRevision.loaded_time:type_name -> google.protobuf.Timestamp + 280, // 246: openshell.v1.SandboxPolicyRevision.policy:type_name -> openshell.sandbox.v1.SandboxPolicy + 276, // 247: openshell.v1.SandboxPolicyRevision.provenance:type_name -> openshell.v1.SandboxPolicyRevision.ProvenanceEntry + 283, // 248: openshell.v1.GetSandboxLogsRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 278, // 249: openshell.v1.GetSandboxLogsRequest.since_time:type_name -> google.protobuf.Timestamp + 111, // 250: openshell.v1.PushSandboxLogsRequest.logs:type_name -> openshell.v1.SandboxLogLine + 111, // 251: openshell.v1.GetSandboxLogsResponse.logs:type_name -> openshell.v1.SandboxLogLine + 187, // 252: openshell.v1.SupervisorMessage.hello:type_name -> openshell.v1.SupervisorHello + 190, // 253: openshell.v1.SupervisorMessage.heartbeat:type_name -> openshell.v1.SupervisorHeartbeat + 203, // 254: openshell.v1.SupervisorMessage.relay_open_result:type_name -> openshell.v1.RelayOpenResult + 204, // 255: openshell.v1.SupervisorMessage.relay_close:type_name -> openshell.v1.RelayClose + 188, // 256: openshell.v1.GatewayMessage.session_accepted:type_name -> openshell.v1.SessionAccepted + 189, // 257: openshell.v1.GatewayMessage.session_rejected:type_name -> openshell.v1.SessionRejected + 191, // 258: openshell.v1.GatewayMessage.heartbeat:type_name -> openshell.v1.GatewayHeartbeat + 196, // 259: openshell.v1.GatewayMessage.relay_open:type_name -> openshell.v1.RelayOpen + 204, // 260: openshell.v1.GatewayMessage.relay_close:type_name -> openshell.v1.RelayClose + 282, // 261: openshell.v1.SessionAccepted.heartbeat_interval:type_name -> google.protobuf.Duration + 197, // 262: openshell.v1.RelayOpen.ssh:type_name -> openshell.v1.SshRelayTarget + 198, // 263: openshell.v1.RelayOpen.tcp:type_name -> openshell.v1.TcpRelayTarget + 199, // 264: openshell.v1.RelayFrame.init:type_name -> openshell.v1.RelayInit + 196, // 265: openshell.v1.PeerRelayInit.relay_open:type_name -> openshell.v1.RelayOpen + 201, // 266: openshell.v1.PeerRelayFrame.init:type_name -> openshell.v1.PeerRelayInit + 278, // 267: openshell.v1.DenialSummary.first_seen_time:type_name -> google.protobuf.Timestamp + 278, // 268: openshell.v1.DenialSummary.last_seen_time:type_name -> google.protobuf.Timestamp + 205, // 269: openshell.v1.DenialSummary.l7_request_samples:type_name -> openshell.v1.L7RequestSample + 207, // 270: openshell.v1.NetworkActivitySummary.denials_by_group:type_name -> openshell.v1.DenialGroupCount + 289, // 271: openshell.v1.PolicyChunk.proposed_rule:type_name -> openshell.sandbox.v1.NetworkPolicyRule + 278, // 272: openshell.v1.PolicyChunk.created_time:type_name -> google.protobuf.Timestamp + 278, // 273: openshell.v1.PolicyChunk.decided_time:type_name -> google.protobuf.Timestamp + 278, // 274: openshell.v1.PolicyChunk.first_seen_time:type_name -> google.protobuf.Timestamp + 278, // 275: openshell.v1.PolicyChunk.last_seen_time:type_name -> google.protobuf.Timestamp + 280, // 276: openshell.v1.PolicyChunk.current_effective_policy:type_name -> openshell.sandbox.v1.SandboxPolicy + 280, // 277: openshell.v1.PolicyChunk.candidate_effective_policy:type_name -> openshell.sandbox.v1.SandboxPolicy + 283, // 278: openshell.v1.SubmitPolicyAnalysisRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 206, // 279: openshell.v1.SubmitPolicyAnalysisRequest.summaries:type_name -> openshell.v1.DenialSummary + 209, // 280: openshell.v1.SubmitPolicyAnalysisRequest.proposed_chunks:type_name -> openshell.v1.PolicyChunk + 208, // 281: openshell.v1.SubmitPolicyAnalysisRequest.network_activity_summaries:type_name -> openshell.v1.NetworkActivitySummary + 283, // 282: openshell.v1.GetDraftPolicyRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 209, // 283: openshell.v1.GetDraftPolicyResponse.chunks:type_name -> openshell.v1.PolicyChunk + 278, // 284: openshell.v1.GetDraftPolicyResponse.last_analyzed_time:type_name -> google.protobuf.Timestamp + 283, // 285: openshell.v1.ApproveDraftChunkRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 286: openshell.v1.RejectDraftChunkRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 287: openshell.v1.ApproveAllDraftChunksRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 219, // 288: openshell.v1.ApproveAllDraftChunksRequest.approvals:type_name -> openshell.v1.DraftChunkApproval + 283, // 289: openshell.v1.EditDraftChunkRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 289, // 290: openshell.v1.EditDraftChunkRequest.proposed_rule:type_name -> openshell.sandbox.v1.NetworkPolicyRule + 283, // 291: openshell.v1.UndoDraftChunkRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 292: openshell.v1.ClearDraftChunksRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 283, // 293: openshell.v1.GetDraftHistoryRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 278, // 294: openshell.v1.DraftHistoryEntry.event_time:type_name -> google.protobuf.Timestamp + 229, // 295: openshell.v1.GetDraftHistoryResponse.entries:type_name -> openshell.v1.DraftHistoryEntry + 277, // 296: openshell.v1.CreateWorkspaceRequest.labels:type_name -> openshell.v1.CreateWorkspaceRequest.LabelsEntry + 292, // 297: openshell.v1.CreateWorkspaceResponse.workspace:type_name -> openshell.datamodel.v1.Workspace + 292, // 298: openshell.v1.GetWorkspaceResponse.workspace:type_name -> openshell.datamodel.v1.Workspace + 292, // 299: openshell.v1.ListWorkspacesResponse.workspaces:type_name -> openshell.datamodel.v1.Workspace + 17, // 300: openshell.v1.DeleteWorkspaceResponse.outcome:type_name -> openshell.v1.DeletionOutcome + 279, // 301: openshell.v1.WorkspaceMember.metadata:type_name -> openshell.datamodel.v1.ObjectMeta + 14, // 302: openshell.v1.WorkspaceMember.role:type_name -> openshell.v1.WorkspaceRole + 283, // 303: openshell.v1.AddWorkspaceMemberRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 14, // 304: openshell.v1.AddWorkspaceMemberRequest.role:type_name -> openshell.v1.WorkspaceRole + 239, // 305: openshell.v1.AddWorkspaceMemberResponse.member:type_name -> openshell.v1.WorkspaceMember + 283, // 306: openshell.v1.RemoveWorkspaceMemberRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 17, // 307: openshell.v1.RemoveWorkspaceMemberResponse.outcome:type_name -> openshell.v1.DeletionOutcome + 283, // 308: openshell.v1.ListWorkspaceMembersRequest.workspace_scope:type_name -> openshell.datamodel.v1.WorkspaceSelector + 239, // 309: openshell.v1.ListWorkspaceMembersResponse.members:type_name -> openshell.v1.WorkspaceMember + 278, // 310: openshell.v1.ExtensionServiceCredential.expiration_time:type_name -> google.protobuf.Timestamp + 18, // 311: openshell.v1.EndpointObservation.result:type_name -> openshell.v1.EndpointResult + 247, // 312: openshell.v1.ReportEndpointStatusRequest.observations:type_name -> openshell.v1.EndpointObservation + 18, // 313: openshell.v1.EndpointStatus.last_result:type_name -> openshell.v1.EndpointResult + 278, // 314: openshell.v1.EndpointStatus.last_reported_time:type_name -> google.protobuf.Timestamp + 278, // 315: openshell.v1.SandboxProvisioning.configuration_change_time:type_name -> google.protobuf.Timestamp + 278, // 316: openshell.v1.SandboxProvisioning.first_rejection_time:type_name -> google.protobuf.Timestamp + 278, // 317: openshell.v1.SandboxProvisioning.deadline:type_name -> google.protobuf.Timestamp + 278, // 318: openshell.v1.SandboxProvisioning.timeout_time:type_name -> google.protobuf.Timestamp + 278, // 319: openshell.v1.SandboxProvisioning.cleanup_completed_time:type_name -> google.protobuf.Timestamp + 278, // 320: openshell.v1.SandboxProvisioning.cleanup_retry_time:type_name -> google.protobuf.Timestamp + 278, // 321: openshell.v1.SandboxProvisioning.attachment_change_time:type_name -> google.protobuf.Timestamp + 19, // 322: openshell.v1.SandboxServiceExposure.authorization_mode:type_name -> openshell.v1.ServiceAuthorizationMode + 278, // 323: openshell.v1.UpdateProviderRequest.CredentialExpirationTimesEntry.value:type_name -> google.protobuf.Timestamp + 278, // 324: openshell.v1.GetSandboxProviderEnvironmentResponse.CredentialExpirationTimesEntry.value:type_name -> google.protobuf.Timestamp + 127, // 325: openshell.v1.GetSandboxProviderEnvironmentResponse.DynamicCredentialsEntry.value:type_name -> openshell.v1.ProviderProfileCredential + 157, // 326: openshell.v1.GetSandboxProviderEnvironmentResponse.StaticCredentialBindingsEntry.value:type_name -> openshell.v1.StaticCredentialBinding + 24, // 327: openshell.v1.OpenShell.Health:input_type -> openshell.v1.HealthRequest + 26, // 328: openshell.v1.OpenShell.GetCurrentUser:input_type -> openshell.v1.GetCurrentUserRequest + 28, // 329: openshell.v1.OpenShell.GetGatewayInfo:input_type -> openshell.v1.GetGatewayInfoRequest + 52, // 330: openshell.v1.OpenShell.CreateSandbox:input_type -> openshell.v1.CreateSandboxRequest + 60, // 331: openshell.v1.OpenShell.BeginRootfsTarStaging:input_type -> openshell.v1.BeginRootfsTarStagingRequest + 62, // 332: openshell.v1.OpenShell.GetSandbox:input_type -> openshell.v1.GetSandboxRequest + 63, // 333: openshell.v1.OpenShell.ListSandboxes:input_type -> openshell.v1.ListSandboxesRequest + 53, // 334: openshell.v1.OpenShell.CreateSandboxTemplate:input_type -> openshell.v1.CreateSandboxTemplateRequest + 54, // 335: openshell.v1.OpenShell.GetSandboxTemplate:input_type -> openshell.v1.GetSandboxTemplateRequest + 55, // 336: openshell.v1.OpenShell.ListSandboxTemplates:input_type -> openshell.v1.ListSandboxTemplatesRequest + 56, // 337: openshell.v1.OpenShell.DeleteSandboxTemplate:input_type -> openshell.v1.DeleteSandboxTemplateRequest + 64, // 338: openshell.v1.OpenShell.ListSandboxProviders:input_type -> openshell.v1.ListSandboxProvidersRequest + 65, // 339: openshell.v1.OpenShell.AttachSandboxProvider:input_type -> openshell.v1.AttachSandboxProviderRequest + 66, // 340: openshell.v1.OpenShell.DetachSandboxProvider:input_type -> openshell.v1.DetachSandboxProviderRequest + 82, // 341: openshell.v1.OpenShell.GetSandboxProviderStatus:input_type -> openshell.v1.GetSandboxProviderStatusRequest + 67, // 342: openshell.v1.OpenShell.DeleteSandbox:input_type -> openshell.v1.DeleteSandboxRequest + 68, // 343: openshell.v1.OpenShell.StopSandbox:input_type -> openshell.v1.StopSandboxRequest + 69, // 344: openshell.v1.OpenShell.StartSandbox:input_type -> openshell.v1.StartSandboxRequest + 87, // 345: openshell.v1.OpenShell.CreateSshSession:input_type -> openshell.v1.CreateSshSessionRequest + 89, // 346: openshell.v1.OpenShell.ExposeService:input_type -> openshell.v1.ExposeServiceRequest + 90, // 347: openshell.v1.OpenShell.GetService:input_type -> openshell.v1.GetServiceRequest + 91, // 348: openshell.v1.OpenShell.ListServices:input_type -> openshell.v1.ListServicesRequest + 93, // 349: openshell.v1.OpenShell.DeleteService:input_type -> openshell.v1.DeleteServiceRequest + 97, // 350: openshell.v1.OpenShell.RevokeSshSession:input_type -> openshell.v1.RevokeSshSessionRequest + 99, // 351: openshell.v1.OpenShell.ExecSandbox:input_type -> openshell.v1.ExecSandboxRequest + 105, // 352: openshell.v1.OpenShell.ForwardTcp:input_type -> openshell.v1.TcpForwardFrame + 106, // 353: openshell.v1.OpenShell.ExecSandboxInteractive:input_type -> openshell.v1.ExecSandboxInput + 113, // 354: openshell.v1.OpenShell.CreateProvider:input_type -> openshell.v1.CreateProviderRequest + 114, // 355: openshell.v1.OpenShell.GetProvider:input_type -> openshell.v1.GetProviderRequest + 115, // 356: openshell.v1.OpenShell.ListProviders:input_type -> openshell.v1.ListProvidersRequest + 120, // 357: openshell.v1.OpenShell.ListProviderProfiles:input_type -> openshell.v1.ListProviderProfilesRequest + 121, // 358: openshell.v1.OpenShell.GetProviderProfile:input_type -> openshell.v1.GetProviderProfileRequest + 146, // 359: openshell.v1.OpenShell.ImportProviderProfiles:input_type -> openshell.v1.ImportProviderProfilesRequest + 148, // 360: openshell.v1.OpenShell.UpdateProviderProfiles:input_type -> openshell.v1.UpdateProviderProfilesRequest + 150, // 361: openshell.v1.OpenShell.LintProviderProfiles:input_type -> openshell.v1.LintProviderProfilesRequest + 116, // 362: openshell.v1.OpenShell.UpdateProvider:input_type -> openshell.v1.UpdateProviderRequest + 134, // 363: openshell.v1.OpenShell.GetProviderRefreshStatus:input_type -> openshell.v1.GetProviderRefreshStatusRequest + 136, // 364: openshell.v1.OpenShell.ConfigureProviderRefresh:input_type -> openshell.v1.ConfigureProviderRefreshRequest + 138, // 365: openshell.v1.OpenShell.RotateProviderCredential:input_type -> openshell.v1.RotateProviderCredentialRequest + 140, // 366: openshell.v1.OpenShell.DeleteProviderRefresh:input_type -> openshell.v1.DeleteProviderRefreshRequest + 117, // 367: openshell.v1.OpenShell.DeleteProvider:input_type -> openshell.v1.DeleteProviderRequest + 153, // 368: openshell.v1.OpenShell.DeleteProviderProfile:input_type -> openshell.v1.DeleteProviderProfileRequest + 293, // 369: openshell.v1.OpenShell.GetSandboxConfig:input_type -> openshell.sandbox.v1.GetSandboxConfigRequest + 294, // 370: openshell.v1.OpenShell.GetGatewayConfig:input_type -> openshell.sandbox.v1.GetGatewayConfigRequest + 161, // 371: openshell.v1.OpenShell.UpdateConfig:input_type -> openshell.v1.UpdateConfigRequest + 171, // 372: openshell.v1.OpenShell.GetSandboxPolicyStatus:input_type -> openshell.v1.GetSandboxPolicyStatusRequest + 173, // 373: openshell.v1.OpenShell.ListSandboxPolicies:input_type -> openshell.v1.ListSandboxPoliciesRequest + 175, // 374: openshell.v1.OpenShell.ReportPolicyStatus:input_type -> openshell.v1.ReportPolicyStatusRequest + 248, // 375: openshell.v1.OpenShell.ReportEndpointStatus:input_type -> openshell.v1.ReportEndpointStatusRequest + 84, // 376: openshell.v1.OpenShell.ReportProviderReadiness:input_type -> openshell.v1.ReportProviderReadinessRequest + 178, // 377: openshell.v1.OpenShell.ReportSandboxConfiguration:input_type -> openshell.v1.ReportSandboxConfigurationRequest + 155, // 378: openshell.v1.OpenShell.GetSandboxProviderEnvironment:input_type -> openshell.v1.GetSandboxProviderEnvironmentRequest + 159, // 379: openshell.v1.OpenShell.ExchangeProviderSubjectToken:input_type -> openshell.v1.ExchangeProviderSubjectTokenRequest + 181, // 380: openshell.v1.OpenShell.GetSandboxLogs:input_type -> openshell.v1.GetSandboxLogsRequest + 182, // 381: openshell.v1.OpenShell.PushSandboxLogs:input_type -> openshell.v1.PushSandboxLogsRequest + 185, // 382: openshell.v1.OpenShell.ConnectSupervisor:input_type -> openshell.v1.SupervisorMessage + 192, // 383: openshell.v1.OpenShell.ReportMainProcessExit:input_type -> openshell.v1.ReportMainProcessExitRequest + 194, // 384: openshell.v1.OpenShell.FinalizeMainProcessExit:input_type -> openshell.v1.FinalizeMainProcessExitRequest + 200, // 385: openshell.v1.OpenShell.RelayStream:input_type -> openshell.v1.RelayFrame + 202, // 386: openshell.v1.OpenShell.PeerRelay:input_type -> openshell.v1.PeerRelayFrame + 84, // 387: openshell.v1.OpenShell.PeerReportProviderReadiness:input_type -> openshell.v1.ReportProviderReadinessRequest + 248, // 388: openshell.v1.OpenShell.PeerReportEndpointStatus:input_type -> openshell.v1.ReportEndpointStatusRequest + 82, // 389: openshell.v1.OpenShell.PeerGetSandboxProviderStatus:input_type -> openshell.v1.GetSandboxProviderStatusRequest + 109, // 390: openshell.v1.OpenShell.WatchSandbox:input_type -> openshell.v1.WatchSandboxRequest + 211, // 391: openshell.v1.OpenShell.SubmitPolicyAnalysis:input_type -> openshell.v1.SubmitPolicyAnalysisRequest + 213, // 392: openshell.v1.OpenShell.GetDraftPolicy:input_type -> openshell.v1.GetDraftPolicyRequest + 215, // 393: openshell.v1.OpenShell.ApproveDraftChunk:input_type -> openshell.v1.ApproveDraftChunkRequest + 217, // 394: openshell.v1.OpenShell.RejectDraftChunk:input_type -> openshell.v1.RejectDraftChunkRequest + 220, // 395: openshell.v1.OpenShell.ApproveAllDraftChunks:input_type -> openshell.v1.ApproveAllDraftChunksRequest + 222, // 396: openshell.v1.OpenShell.EditDraftChunk:input_type -> openshell.v1.EditDraftChunkRequest + 224, // 397: openshell.v1.OpenShell.UndoDraftChunk:input_type -> openshell.v1.UndoDraftChunkRequest + 226, // 398: openshell.v1.OpenShell.ClearDraftChunks:input_type -> openshell.v1.ClearDraftChunksRequest + 228, // 399: openshell.v1.OpenShell.GetDraftHistory:input_type -> openshell.v1.GetDraftHistoryRequest + 20, // 400: openshell.v1.OpenShell.IssueSandboxToken:input_type -> openshell.v1.IssueSandboxTokenRequest + 22, // 401: openshell.v1.OpenShell.RefreshSandboxToken:input_type -> openshell.v1.RefreshSandboxTokenRequest + 231, // 402: openshell.v1.OpenShell.CreateWorkspace:input_type -> openshell.v1.CreateWorkspaceRequest + 233, // 403: openshell.v1.OpenShell.GetWorkspace:input_type -> openshell.v1.GetWorkspaceRequest + 235, // 404: openshell.v1.OpenShell.ListWorkspaces:input_type -> openshell.v1.ListWorkspacesRequest + 237, // 405: openshell.v1.OpenShell.DeleteWorkspace:input_type -> openshell.v1.DeleteWorkspaceRequest + 240, // 406: openshell.v1.OpenShell.AddWorkspaceMember:input_type -> openshell.v1.AddWorkspaceMemberRequest + 242, // 407: openshell.v1.OpenShell.RemoveWorkspaceMember:input_type -> openshell.v1.RemoveWorkspaceMemberRequest + 244, // 408: openshell.v1.OpenShell.ListWorkspaceMembers:input_type -> openshell.v1.ListWorkspaceMembersRequest + 25, // 409: openshell.v1.OpenShell.Health:output_type -> openshell.v1.HealthResponse + 27, // 410: openshell.v1.OpenShell.GetCurrentUser:output_type -> openshell.v1.GetCurrentUserResponse + 29, // 411: openshell.v1.OpenShell.GetGatewayInfo:output_type -> openshell.v1.GetGatewayInfoResponse + 70, // 412: openshell.v1.OpenShell.CreateSandbox:output_type -> openshell.v1.SandboxResponse + 61, // 413: openshell.v1.OpenShell.BeginRootfsTarStaging:output_type -> openshell.v1.BeginRootfsTarStagingResponse + 70, // 414: openshell.v1.OpenShell.GetSandbox:output_type -> openshell.v1.SandboxResponse + 71, // 415: openshell.v1.OpenShell.ListSandboxes:output_type -> openshell.v1.ListSandboxesResponse + 57, // 416: openshell.v1.OpenShell.CreateSandboxTemplate:output_type -> openshell.v1.SandboxTemplateResponse + 57, // 417: openshell.v1.OpenShell.GetSandboxTemplate:output_type -> openshell.v1.SandboxTemplateResponse + 58, // 418: openshell.v1.OpenShell.ListSandboxTemplates:output_type -> openshell.v1.ListSandboxTemplatesResponse + 59, // 419: openshell.v1.OpenShell.DeleteSandboxTemplate:output_type -> openshell.v1.DeleteSandboxTemplateResponse + 72, // 420: openshell.v1.OpenShell.ListSandboxProviders:output_type -> openshell.v1.ListSandboxProvidersResponse + 73, // 421: openshell.v1.OpenShell.AttachSandboxProvider:output_type -> openshell.v1.AttachSandboxProviderResponse + 74, // 422: openshell.v1.OpenShell.DetachSandboxProvider:output_type -> openshell.v1.DetachSandboxProviderResponse + 83, // 423: openshell.v1.OpenShell.GetSandboxProviderStatus:output_type -> openshell.v1.GetSandboxProviderStatusResponse + 86, // 424: openshell.v1.OpenShell.DeleteSandbox:output_type -> openshell.v1.DeleteSandboxResponse + 70, // 425: openshell.v1.OpenShell.StopSandbox:output_type -> openshell.v1.SandboxResponse + 70, // 426: openshell.v1.OpenShell.StartSandbox:output_type -> openshell.v1.SandboxResponse + 88, // 427: openshell.v1.OpenShell.CreateSshSession:output_type -> openshell.v1.CreateSshSessionResponse + 96, // 428: openshell.v1.OpenShell.ExposeService:output_type -> openshell.v1.ServiceEndpointResponse + 96, // 429: openshell.v1.OpenShell.GetService:output_type -> openshell.v1.ServiceEndpointResponse + 92, // 430: openshell.v1.OpenShell.ListServices:output_type -> openshell.v1.ListServicesResponse + 94, // 431: openshell.v1.OpenShell.DeleteService:output_type -> openshell.v1.DeleteServiceResponse + 98, // 432: openshell.v1.OpenShell.RevokeSshSession:output_type -> openshell.v1.RevokeSshSessionResponse + 103, // 433: openshell.v1.OpenShell.ExecSandbox:output_type -> openshell.v1.ExecSandboxEvent + 105, // 434: openshell.v1.OpenShell.ForwardTcp:output_type -> openshell.v1.TcpForwardFrame + 103, // 435: openshell.v1.OpenShell.ExecSandboxInteractive:output_type -> openshell.v1.ExecSandboxEvent + 118, // 436: openshell.v1.OpenShell.CreateProvider:output_type -> openshell.v1.ProviderResponse + 118, // 437: openshell.v1.OpenShell.GetProvider:output_type -> openshell.v1.ProviderResponse + 119, // 438: openshell.v1.OpenShell.ListProviders:output_type -> openshell.v1.ListProvidersResponse + 145, // 439: openshell.v1.OpenShell.ListProviderProfiles:output_type -> openshell.v1.ListProviderProfilesResponse + 144, // 440: openshell.v1.OpenShell.GetProviderProfile:output_type -> openshell.v1.ProviderProfileResponse + 147, // 441: openshell.v1.OpenShell.ImportProviderProfiles:output_type -> openshell.v1.ImportProviderProfilesResponse + 149, // 442: openshell.v1.OpenShell.UpdateProviderProfiles:output_type -> openshell.v1.UpdateProviderProfilesResponse + 151, // 443: openshell.v1.OpenShell.LintProviderProfiles:output_type -> openshell.v1.LintProviderProfilesResponse + 118, // 444: openshell.v1.OpenShell.UpdateProvider:output_type -> openshell.v1.ProviderResponse + 135, // 445: openshell.v1.OpenShell.GetProviderRefreshStatus:output_type -> openshell.v1.GetProviderRefreshStatusResponse + 137, // 446: openshell.v1.OpenShell.ConfigureProviderRefresh:output_type -> openshell.v1.ConfigureProviderRefreshResponse + 139, // 447: openshell.v1.OpenShell.RotateProviderCredential:output_type -> openshell.v1.RotateProviderCredentialResponse + 141, // 448: openshell.v1.OpenShell.DeleteProviderRefresh:output_type -> openshell.v1.DeleteProviderRefreshResponse + 152, // 449: openshell.v1.OpenShell.DeleteProvider:output_type -> openshell.v1.DeleteProviderResponse + 154, // 450: openshell.v1.OpenShell.DeleteProviderProfile:output_type -> openshell.v1.DeleteProviderProfileResponse + 295, // 451: openshell.v1.OpenShell.GetSandboxConfig:output_type -> openshell.sandbox.v1.GetSandboxConfigResponse + 296, // 452: openshell.v1.OpenShell.GetGatewayConfig:output_type -> openshell.sandbox.v1.GetGatewayConfigResponse + 170, // 453: openshell.v1.OpenShell.UpdateConfig:output_type -> openshell.v1.UpdateConfigResponse + 172, // 454: openshell.v1.OpenShell.GetSandboxPolicyStatus:output_type -> openshell.v1.GetSandboxPolicyStatusResponse + 174, // 455: openshell.v1.OpenShell.ListSandboxPolicies:output_type -> openshell.v1.ListSandboxPoliciesResponse + 176, // 456: openshell.v1.OpenShell.ReportPolicyStatus:output_type -> openshell.v1.ReportPolicyStatusResponse + 249, // 457: openshell.v1.OpenShell.ReportEndpointStatus:output_type -> openshell.v1.ReportEndpointStatusResponse + 85, // 458: openshell.v1.OpenShell.ReportProviderReadiness:output_type -> openshell.v1.ReportProviderReadinessResponse + 179, // 459: openshell.v1.OpenShell.ReportSandboxConfiguration:output_type -> openshell.v1.ReportSandboxConfigurationResponse + 158, // 460: openshell.v1.OpenShell.GetSandboxProviderEnvironment:output_type -> openshell.v1.GetSandboxProviderEnvironmentResponse + 160, // 461: openshell.v1.OpenShell.ExchangeProviderSubjectToken:output_type -> openshell.v1.ExchangeProviderSubjectTokenResponse + 184, // 462: openshell.v1.OpenShell.GetSandboxLogs:output_type -> openshell.v1.GetSandboxLogsResponse + 183, // 463: openshell.v1.OpenShell.PushSandboxLogs:output_type -> openshell.v1.PushSandboxLogsResponse + 186, // 464: openshell.v1.OpenShell.ConnectSupervisor:output_type -> openshell.v1.GatewayMessage + 193, // 465: openshell.v1.OpenShell.ReportMainProcessExit:output_type -> openshell.v1.ReportMainProcessExitResponse + 195, // 466: openshell.v1.OpenShell.FinalizeMainProcessExit:output_type -> openshell.v1.FinalizeMainProcessExitResponse + 200, // 467: openshell.v1.OpenShell.RelayStream:output_type -> openshell.v1.RelayFrame + 202, // 468: openshell.v1.OpenShell.PeerRelay:output_type -> openshell.v1.PeerRelayFrame + 85, // 469: openshell.v1.OpenShell.PeerReportProviderReadiness:output_type -> openshell.v1.ReportProviderReadinessResponse + 249, // 470: openshell.v1.OpenShell.PeerReportEndpointStatus:output_type -> openshell.v1.ReportEndpointStatusResponse + 83, // 471: openshell.v1.OpenShell.PeerGetSandboxProviderStatus:output_type -> openshell.v1.GetSandboxProviderStatusResponse + 110, // 472: openshell.v1.OpenShell.WatchSandbox:output_type -> openshell.v1.SandboxStreamEvent + 212, // 473: openshell.v1.OpenShell.SubmitPolicyAnalysis:output_type -> openshell.v1.SubmitPolicyAnalysisResponse + 214, // 474: openshell.v1.OpenShell.GetDraftPolicy:output_type -> openshell.v1.GetDraftPolicyResponse + 216, // 475: openshell.v1.OpenShell.ApproveDraftChunk:output_type -> openshell.v1.ApproveDraftChunkResponse + 218, // 476: openshell.v1.OpenShell.RejectDraftChunk:output_type -> openshell.v1.RejectDraftChunkResponse + 221, // 477: openshell.v1.OpenShell.ApproveAllDraftChunks:output_type -> openshell.v1.ApproveAllDraftChunksResponse + 223, // 478: openshell.v1.OpenShell.EditDraftChunk:output_type -> openshell.v1.EditDraftChunkResponse + 225, // 479: openshell.v1.OpenShell.UndoDraftChunk:output_type -> openshell.v1.UndoDraftChunkResponse + 227, // 480: openshell.v1.OpenShell.ClearDraftChunks:output_type -> openshell.v1.ClearDraftChunksResponse + 230, // 481: openshell.v1.OpenShell.GetDraftHistory:output_type -> openshell.v1.GetDraftHistoryResponse + 21, // 482: openshell.v1.OpenShell.IssueSandboxToken:output_type -> openshell.v1.IssueSandboxTokenResponse + 23, // 483: openshell.v1.OpenShell.RefreshSandboxToken:output_type -> openshell.v1.RefreshSandboxTokenResponse + 232, // 484: openshell.v1.OpenShell.CreateWorkspace:output_type -> openshell.v1.CreateWorkspaceResponse + 234, // 485: openshell.v1.OpenShell.GetWorkspace:output_type -> openshell.v1.GetWorkspaceResponse + 236, // 486: openshell.v1.OpenShell.ListWorkspaces:output_type -> openshell.v1.ListWorkspacesResponse + 238, // 487: openshell.v1.OpenShell.DeleteWorkspace:output_type -> openshell.v1.DeleteWorkspaceResponse + 241, // 488: openshell.v1.OpenShell.AddWorkspaceMember:output_type -> openshell.v1.AddWorkspaceMemberResponse + 243, // 489: openshell.v1.OpenShell.RemoveWorkspaceMember:output_type -> openshell.v1.RemoveWorkspaceMemberResponse + 245, // 490: openshell.v1.OpenShell.ListWorkspaceMembers:output_type -> openshell.v1.ListWorkspaceMembersResponse + 409, // [409:491] is the sub-list for method output_type + 327, // [327:409] is the sub-list for method input_type + 327, // [327:327] is the sub-list for extension type_name + 327, // [327:327] is the sub-list for extension extendee + 0, // [0:327] is the sub-list for field type_name } func init() { file_openshell_proto_init() } @@ -20322,7 +20425,7 @@ func file_openshell_proto_init() { (*SandboxStreamEvent_Warning)(nil), (*SandboxStreamEvent_DraftPolicyUpdate)(nil), } - file_openshell_proto_msgTypes[141].OneofWrappers = []any{ + file_openshell_proto_msgTypes[142].OneofWrappers = []any{ (*PolicyMergeOperation_AddRule)(nil), (*PolicyMergeOperation_RemoveEndpoint)(nil), (*PolicyMergeOperation_RemoveRule)(nil), @@ -20330,29 +20433,29 @@ func file_openshell_proto_init() { (*PolicyMergeOperation_AddAllowRules)(nil), (*PolicyMergeOperation_RemoveBinary)(nil), } - file_openshell_proto_msgTypes[145].OneofWrappers = []any{} - file_openshell_proto_msgTypes[164].OneofWrappers = []any{ + file_openshell_proto_msgTypes[146].OneofWrappers = []any{} + file_openshell_proto_msgTypes[165].OneofWrappers = []any{ (*SupervisorMessage_Hello)(nil), (*SupervisorMessage_Heartbeat)(nil), (*SupervisorMessage_RelayOpenResult)(nil), (*SupervisorMessage_RelayClose)(nil), } - file_openshell_proto_msgTypes[165].OneofWrappers = []any{ + file_openshell_proto_msgTypes[166].OneofWrappers = []any{ (*GatewayMessage_SessionAccepted)(nil), (*GatewayMessage_SessionRejected)(nil), (*GatewayMessage_Heartbeat)(nil), (*GatewayMessage_RelayOpen)(nil), (*GatewayMessage_RelayClose)(nil), } - file_openshell_proto_msgTypes[175].OneofWrappers = []any{ + file_openshell_proto_msgTypes[176].OneofWrappers = []any{ (*RelayOpen_Ssh)(nil), (*RelayOpen_Tcp)(nil), } - file_openshell_proto_msgTypes[179].OneofWrappers = []any{ + file_openshell_proto_msgTypes[180].OneofWrappers = []any{ (*RelayFrame_Init)(nil), (*RelayFrame_Data)(nil), } - file_openshell_proto_msgTypes[181].OneofWrappers = []any{ + file_openshell_proto_msgTypes[182].OneofWrappers = []any{ (*PeerRelayFrame_Init)(nil), (*PeerRelayFrame_Data)(nil), } @@ -20362,7 +20465,7 @@ func file_openshell_proto_init() { GoPackagePath: reflect.TypeOf(x{}).PkgPath(), RawDescriptor: unsafe.Slice(unsafe.StringData(file_openshell_proto_rawDesc), len(file_openshell_proto_rawDesc)), NumEnums: 20, - NumMessages: 255, + NumMessages: 258, NumExtensions: 0, NumServices: 1, }, diff --git a/skills/debug-openshell-cluster/SKILL.md b/skills/debug-openshell-cluster/SKILL.md index 6382428946..a0de023719 100644 --- a/skills/debug-openshell-cluster/SKILL.md +++ b/skills/debug-openshell-cluster/SKILL.md @@ -959,7 +959,7 @@ credential failures. | Gateway fails before serving health after enabling an interceptor | Interceptor endpoint unavailable or manifest/binding validation failed | Gateway and interceptor logs; interceptor socket; `binding_policy`, phases, and failure policy | | Authenticated interceptor or middleware rejects gateway calls | Private CA or hostname mismatch, expected audience or issuer mismatch, stale/unknown `kid`, or malformed extension token | `tls_ca_cert_path`, registration `audience`, service verifier config and logs; fetch well-known metadata only through the already-trusted gateway TLS endpoint | | Provider profiles disappear after enabling an interceptor catalog | `provider_profile_sources` selected only an authoritative interceptor or returned invalid/duplicate IDs | Inspect source list and interceptor `Describe`/catalog logs; include `user` when composition with imported profiles is intended | -| `provider list-profiles` is empty on a new gateway | Profiles are import-only and nothing has been imported | Import with `openshell provider profile import --from providers --global`; an empty catalog is a valid ready state, not a failure | +| `provider list-profiles` is empty on a new gateway | Profiles are import-only and nothing has been imported | Import a reviewed profile with `openshell profile import -f --global`; an empty catalog is a valid ready state, not a failure. A directory import containing a profile that requires an unavailable adapter fails as a batch. | | Sandbox create or provider attach fails naming a missing profile | The provider's profile was never imported, was deleted, or lives at another scope | Import it at the scope the provider uses; the error names the profile ID and the command | | Gateway fails after registering supervisor middleware | Service unavailable, invalid manifest, duplicate binding, reserved name, or invalid payload/timeout limit | Middleware service and gateway logs; `[[openshell.supervisor.middleware]]`; `Describe` response | | Policy update rejects `network_middlewares` | Unknown middleware name, implementation-owned config invalid, duplicate order, broad/invalid host selector, or fail-closed coverage of `tls: skip` | Policy error, gateway logs, middleware `ValidateConfig`, selector and order fields | diff --git a/skills/openshell-cli/SKILL.md b/skills/openshell-cli/SKILL.md index 3977018a01..ad3f563105 100644 --- a/skills/openshell-cli/SKILL.md +++ b/skills/openshell-cli/SKILL.md @@ -176,7 +176,7 @@ openshell profile import --url https://example.com/profiles/my-profile.yaml binary grants before importing it. The URL path must end in `.yaml`, `.yml`, or `.json`; downloads are limited to 1 MiB and 15 seconds. -Use `profile describe` to inspect a definition's credential metadata, endpoints, TLS handling, MCP access settings, rule counts, binaries, source, and scope before creating a provider. Check for `tls: skip` and the uninspected-credential opt-in before relying on displayed L7 rules. List and describe accept table, JSON, and YAML output; use structured output for complete rule definitions, `--workspace` for a workspace catalog, or `--global` for platform scope. Use `profile export` when preparing an editable definition, `profile update --file ` to replace an existing custom profile with its current resource version, and `profile delete ...` to remove custom profiles. Provider instances remain under `provider`. +Use `profile describe` to inspect a definition's credential metadata, endpoints, TLS handling, MCP access settings, rule counts, binaries, source, and scope before creating a provider. Inspect structured output for declared environment defaults, discovery config keys, and required platform adapters. Renaming a profile preserves its declared behavior; the ID does not activate SDK defaults. An unavailable required adapter rejects import or attachment. Check for `tls: skip` and the uninspected-credential opt-in before relying on displayed L7 rules. List and describe accept table, JSON, and YAML output; use structured output for complete rule definitions, `--workspace` for a workspace catalog, or `--global` for platform scope. Use `profile export` when preparing an editable definition, `profile update --file ` to replace an existing custom profile with its current resource version, and `profile delete ...` to remove custom profiles. Provider instances remain under `provider`. Existing scripts can continue using `provider list-profiles` and `provider profile export/import/update/lint/delete`. These commands share the top-level handlers and preserve their arguments, output options, and workspace/global flags. Prefer `profile` when writing new commands. diff --git a/tasks/scripts/test-e2e-provider-profiles.sh b/tasks/scripts/test-e2e-provider-profiles.sh new file mode 100644 index 0000000000..9cf8180b2b --- /dev/null +++ b/tasks/scripts/test-e2e-provider-profiles.sh @@ -0,0 +1,37 @@ +#!/usr/bin/env bash +# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. +# SPDX-License-Identifier: Apache-2.0 + +set -euo pipefail + +ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)" +# shellcheck source=e2e/support/gateway-common.sh +source "${ROOT}/e2e/support/gateway-common.sh" + +PROFILE_WORK="$(mktemp -d)" +trap 'rm -rf "${PROFILE_WORK}"' EXIT +mkdir -p "${PROFILE_WORK}/providers" +printf 'id: google-cloud\n' > "${PROFILE_WORK}/providers/google-cloud.yaml" +printf 'id: acme\nrequired_platform_adapter: gcp-metadata\n' > "${PROFILE_WORK}/providers/acme.yaml" + +capture_profile_import() { + printf '%s\n' "$*" >> "${PROFILE_WORK}/imports" +} + +e2e_import_example_provider_profiles capture_profile_import "${PROFILE_WORK}" +expected="provider profile import --file ${PROFILE_WORK}/providers/google-cloud.yaml --global" +if [ "$(cat "${PROFILE_WORK}/imports")" != "${expected}" ]; then + echo "FAIL: profile selection must follow adapter declarations, independent of ID" >&2 + exit 1 +fi + +fail_profile_import() { + return 1 +} + +if e2e_import_example_provider_profiles fail_profile_import "${PROFILE_WORK}" > "${PROFILE_WORK}/failure.log" 2>&1; then + echo "FAIL: an import error must fail gateway setup" >&2 + exit 1 +fi + +echo "E2E provider profile setup tests passed." diff --git a/tasks/test.toml b/tasks/test.toml index c45826f1db..405dc5c675 100644 --- a/tasks/test.toml +++ b/tasks/test.toml @@ -14,6 +14,7 @@ depends = [ "test:build-env", "test:gateway-pull-policy", "test:e2e-image-overrides", + "test:e2e-provider-profiles", "test:gateway-config", "test:e2e-parity", "test:packaging-assets", @@ -62,6 +63,12 @@ run = "tasks/scripts/test-e2e-image-overrides.sh" run_windows = "echo Skipping test:e2e-image-overrides: Unix E2E wrappers do not apply on Windows." hide = true +["test:e2e-provider-profiles"] +description = "Test E2E provider profile selection and import failures" +run = "bash tasks/scripts/test-e2e-provider-profiles.sh" +run_windows = "echo Skipping test:e2e-provider-profiles: Unix E2E wrappers do not apply on Windows." +hide = true + ["test:packaging-assets"] description = "Run static packaging asset tests" run = "tasks/scripts/test-packaging-assets.sh"