fix(docker): generate gateway JWT keys in compose quickstart - #3838
ericcurtin wants to merge 2 commits into
Conversation
Fixes NVIDIA#2891 Signed-off-by: Eric Curtin <eric.curtin@docker.com>
|
If useful, please also try https://github.com/llmmanorg/llmman, which can launch agents in an OpenShell sandbox ( |
|
/ok to test a8cedbe |
|
@johntmyers @elezar PTAL when you get a chance. Thank you! |
|
@ericcurtin I did some digging around how other deployments configure TLS/client auth and it would be great to have instructions for using Compose with TLS as well. Something similar to how the vanilla With this PR, the TLS materials are generated, we'd need to document moving these to where our CLI can use them. Perhaps something to do as a follow up? |
Signed-off-by: Eric Curtin <eric.curtin@docker.com>
|
Thanks, added a Compose mTLS section in b746323. It reuses the certs the init service already generates and covers copying the client bundle to where the CLI loads it. I checked it end to end against the gateway image with a TLS-enabled Compose setup, including a sandbox run. |
|
@pimlock Added the Compose mTLS section. Could you |
|
/ok to test b746323 |
Summary
Make the Docker Compose quickstart able to create a sandbox.
Related Issue
Fixes #2891
Changes
initservice that runsgenerate-certsto create the gateway JWT keys on the host.gateway.tomlat the keys and allow unauthenticated user calls (loopback only, no TLS).grpc_endpointso the supervisor uses the default127.0.0.1:8080.Testing
mise run pre-commitpassesRan
docker compose up -dfrom clean state, thenopenshell sandbox create -- echo helloprintedhello. A secondupkept the keys. Ran onlylicense:checkandmarkdown:lintfrom pre-commit (no Rust changes). No automated test added.Checklist