Skip to content

fix(docker): generate gateway JWT keys in compose quickstart - #3838

Open
ericcurtin wants to merge 2 commits into
NVIDIA:mainfrom
ericcurtin:fix/2891-compose-gateway-jwt
Open

ericcurtin wants to merge 2 commits into
NVIDIA:mainfrom
ericcurtin:fix/2891-compose-gateway-jwt

Conversation

@ericcurtin

Copy link
Copy Markdown
Contributor

Summary

Make the Docker Compose quickstart able to create a sandbox.

Related Issue

Fixes #2891

Changes

  • Add an init service that runs generate-certs to create the gateway JWT keys on the host.
  • Point gateway.toml at the keys and allow unauthenticated user calls (loopback only, no TLS).
  • Drop grpc_endpoint so the supervisor uses the default 127.0.0.1:8080.
  • Note the init step in the container deployment docs.

Testing

  • mise run pre-commit passes
  • Unit tests added/updated
  • E2E tests added/updated (if applicable)

Ran docker compose up -d from clean state, then openshell sandbox create -- echo hello printed hello. A second up kept the keys. Ran only license:check and markdown:lint from pre-commit (no Rust changes). No automated test added.

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

Fixes NVIDIA#2891

Signed-off-by: Eric Curtin <eric.curtin@docker.com>
@copy-pr-bot

copy-pr-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@ericcurtin

ericcurtin commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor Author

If useful, please also try https://github.com/llmmanorg/llmman, which can launch agents in an OpenShell sandbox (--sandbox openshell).

@pimlock

pimlock commented Sep 29, 2026

Copy link
Copy Markdown
Collaborator

/ok to test a8cedbe

@pimlock pimlock self-assigned this Sep 29, 2026
@ericcurtin

Copy link
Copy Markdown
Contributor Author

@johntmyers @elezar PTAL when you get a chance. Thank you!

pimlock
pimlock previously approved these changes Oct 1, 2026
@pimlock

pimlock commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

@ericcurtin I did some digging around how other deployments configure TLS/client auth and it would be great to have instructions for using Compose with TLS as well.

Something similar to how the vanilla docker run documents it https://docs.nvidia.com/openshell/how-it-works/gateways/container-deployment#full-mtls-setup

With this PR, the TLS materials are generated, we'd need to document moving these to where our CLI can use them.

Perhaps something to do as a follow up?

Signed-off-by: Eric Curtin <eric.curtin@docker.com>
@ericcurtin

Copy link
Copy Markdown
Contributor Author

Thanks, added a Compose mTLS section in b746323. It reuses the certs the init service already generates and covers copying the client bundle to where the CLI loads it. I checked it end to end against the gateway image with a TLS-enabled Compose setup, including a sandbox run.

@ericcurtin

Copy link
Copy Markdown
Contributor Author

@pimlock Added the Compose mTLS section. Could you /ok to test b746323741142a34481c376a5eca47d7ea3b13e4? Thank you!

@pimlock

pimlock commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

/ok to test b746323

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(docker): Compose gateway cannot create sandboxes without gateway JWT

2 participants