Skip to content

fix(providers): restore supervisor-backed GCP metadata discovery - #3973

Open
feloy wants to merge 3 commits into
NVIDIA:mainfrom
feloy:fix-3860/restore-gcp-metadata
Open

feloy wants to merge 3 commits into
NVIDIA:mainfrom
feloy:fix-3860/restore-gcp-metadata

Conversation

@feloy

@feloy feloy commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

🏗️ build-from-issue-agent

Summary

Restore the Google Cloud metadata emulator removed during the sandbox/supervisor split. SDK requests to the injected 127.0.0.1:8174 address now reach a supervisor-owned emulator through the existing authenticated network relay, allowing Application Default Credentials discovery and repeated token refresh.

Related Issue

Closes #3860

Changes

  • Adapt the metadata handler removed in feat(isolation): implement the RFC 0012 sandbox architecture #2942 to the supervisor's live provider state, serving project/account metadata and token placeholders while preserving non-secret classification and credential expiry.
  • Reserve the exact metadata loopback destination in the sandbox broker and dispatch direct TCP and HTTP proxy requests locally, with verified workload identity and bounded request parsing.
  • Add Google SDK discovery and repeated-refresh E2E coverage, plus the expected 503 response without an explicit credential binding.
  • Update Google provider documentation and the sandbox-policy skill to explain supported Linux runtimes, the reserved address, and credential-binding requirements.

Deviations from Plan

Local E2E validation uses Podman because Docker is unavailable on this development host. The regression tests remain in the existing Python E2E suite.

Testing

  • mise run pre-commit passes, including the commit hook.
  • mise run ci passes (lint, compile/type checks, Rust/Python/TypeScript/Go tests, and dependency policy checks).
  • Provider E2E suite passes against an isolated Podman gateway: 18 passed, 0 skipped in 134.02s.
  • Unit tests added/updated: metadata responses and headers, credential refresh/removal/expiry, configuration classification, account aliases, exact destination matching, identity verification, and malformed/oversized/incomplete requests.
  • E2E tests added/updated: pinned google-auth==2.40.3, ADC metadata detection, project/account discovery, repeated refresh, placeholder isolation, and missing credential bindings.
  • Manual Podman reproduction: metadata probe returns 200 with a bound Google Cloud provider and 503 without a binding.
  • Linux-only broker tests cover TCP relay, ordinary loopback connections, and rejection of UDP to the reserved address; these tests are not executable on the macOS host.

E2E command:

OPENSHELL_GATEWAY_BIN="$PWD/target/debug/openshell-gateway" \
OPENSHELL_BIN="$PWD/target/debug/openshell" \
SUPERVISOR_IMAGE=localhost/openshell/supervisor:dev \
SANDBOX_IMAGE=localhost/openshell/sandbox:dev \
OPENSHELL_E2E_PODMAN_SANDBOX_IMAGE=localhost/openshell/e2e-python:dev \
UV_NO_SYNC=1 PYTHONPATH=python \
e2e/with-podman-gateway.sh uv run pytest \
  -o 'python_files=test_*.py *_test.py' -vv e2e/python/test_sandbox_providers.py

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Documentation updated in docs/how-it-works/providers/google.mdx; related public policy skill reviewed and updated.

Relay the reserved metadata endpoint to the supervisor and restore project, account, and placeholder token responses from live provider state. Cover Google SDK discovery and repeated refresh with provider E2E tests.

Closes NVIDIA#3860

Signed-off-by: Philippe Martin <phmartin@redhat.com>
@copy-pr-bot

copy-pr-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@feloy

feloy commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

🏗️ build-from-issue-agent

E2E Test Attestation

Local provider E2E tests passed against an isolated Podman gateway.

Field Value
Commit ed234d71ee5f9677e6bce4fed21d93b3b01e21b4
Gateway mode Podman on macOS, Linux arm64 runtime images
Result 18 passed, 0 skipped in 134.02s
SDK google-auth 2.40.3, requests 2.32.5

Command

OPENSHELL_GATEWAY_BIN="$PWD/target/debug/openshell-gateway" \
OPENSHELL_BIN="$PWD/target/debug/openshell" \
SUPERVISOR_IMAGE=localhost/openshell/supervisor:dev \
SANDBOX_IMAGE=localhost/openshell/sandbox:dev \
OPENSHELL_E2E_PODMAN_SANDBOX_IMAGE=localhost/openshell/e2e-python:dev \
UV_NO_SYNC=1 PYTHONPATH=python \
e2e/with-podman-gateway.sh uv run pytest \
  -o 'python_files=test_*.py *_test.py' -vv e2e/python/test_sandbox_providers.py

Runtime images

  • Supervisor: localhost/openshell/supervisor@sha256:976c0ed75b7a0612517d347062ee504eba9b29a9e7670fa069b1a41c2c292758
  • Sandbox runtime image ID: 9c7561b5c640dfb892610763cd8f4a44d681c57c030309a89eec2569c27d1f14
  • Workload: localhost/openshell/e2e-python@sha256:f48c1464036a5fddc110d594697d6d390f55af8809520758c96ade1bc639a138

Tests Executed

All tests are in e2e/python/test_sandbox_providers.py.

  • test_provider_credentials_available_as_env_vars — PASSED
  • test_profileless_provider_creation_is_rejected — PASSED
  • test_endpointless_profile_credentials_fail_closed_without_policy_binding — PASSED
  • test_endpointless_profile_credentials_use_explicit_policy_binding — PASSED
  • test_google_metadata_sdk_discovery — PASSED
  • test_nvidia_provider_injects_nvidia_api_key_env_var — PASSED
  • test_attach_detach_updates_credentials_for_later_exec_launches — PASSED
  • test_imported_openai_profile_allows_native_endpoint_with_attached_provider — PASSED
  • test_imported_anthropic_profile_allows_native_endpoint_with_attached_provider — PASSED
  • test_create_sandbox_rejects_unknown_provider — PASSED
  • test_credentials_not_in_persisted_spec_environment — PASSED
  • test_update_provider_preserves_unset_credentials_and_config — PASSED
  • test_update_provider_empty_maps_preserves_all — PASSED
  • test_update_provider_merges_config_preserves_credentials — PASSED
  • test_update_provider_rejects_type_change — PASSED
  • test_github_provider_allows_https_git_clone — PASSED
  • test_provider_profile_platform_vs_workspace_isolation — PASSED
  • test_cross_workspace_profile_ids_do_not_collide — PASSED

Full local mise run ci and final mise run pre-commit also passed. Linux-only broker unit tests could not run on the macOS host; the Podman E2E exercised the Linux broker.

@johntmyers johntmyers left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

PR Review Status

The restoration is project-valid and the full initial patch review found one blocking correctness gap in the default documented provider setup.

Action required: @feloy, make metadata-based refresh work when service_account_email is omitted and add coverage for that documented path.

Blocking findings:

  • GATOR-ed234d71-01: the recursive account response can select an empty account name and send the SDK to an unsupported token route.

Carried findings:

  • None
Gator metadata
  • Validation: Implements the validated regression in #3860.
  • Docs: Updated, but the documented no-email setup exposes the blocking finding.
  • Checks: Current-head branch and Helm gates are pending; pipeline handoff waits for review feedback.
  • E2E: Required for provider credential and sandbox-network behavior; dispatch waits until the blocker is addressed.
  • Head SHA: ed234d71ee5f9677e6bce4fed21d93b3b01e21b4
  • Base SHA: 7caff12d3c9013e7063d22391a76f775f6ce93b5
  • Merge base SHA: 7caff12d3c9013e7063d22391a76f775f6ce93b5
  • Patch ID: c51d73bf9e9c8c269ff8710b12d2b5bc440af861
  • Gator payload: 9
  • Review mode: initial
  • Previous reviewed SHA: none
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Next state: gator:in-review

Comment thread crates/openshell-supervisor-network/src/google_cloud_metadata.rs Outdated
Use the default account identifier when the optional service account email is missing or empty. Cover repeated SDK refresh for missing, empty, and configured email values with distinct providers for parallel E2E execution.

Signed-off-by: Philippe Martin <phmartin@redhat.com>
@johntmyers johntmyers added the test:e2e Requires end-to-end coverage label Sep 30, 2026
@github-actions

Copy link
Copy Markdown

Label test:e2e applied, but pull-request/3973 does not exist yet. A maintainer needs to comment /ok to test c158fff6b7562b59a536420d23cc3574eba63640 to mirror this PR. Once the mirror exists, re-apply the label or re-run Branch E2E Checks from the Actions tab.

@johntmyers

Copy link
Copy Markdown
Collaborator

/ok to test c158fff

@johntmyers johntmyers added test:e2e Requires end-to-end coverage and removed test:e2e Requires end-to-end coverage labels Sep 30, 2026
@github-actions

Copy link
Copy Markdown

Label test:e2e applied for c158fff. Open the existing run and click Re-run all jobs to execute with the label set. The run will execute the standard E2E suite after building the required gateway, sandbox, and supervisor images once. The matching required CI gate status on this PR will flip green automatically once the run finishes.

@johntmyers johntmyers left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

PR Review Status

The follow-up review confirms that the default-account fix and expanded SDK coverage resolve GATOR-ed234d71-01. No blocking findings remain, and the required current-head Branch Checks and E2E workflows are now running.

Blocking findings:

  • No blocking findings remain

Carried findings:

  • None
Gator metadata
  • Validation: Implements the validated GCP metadata regression in #3860.
  • Docs: Updated for optional or empty service_account_email behavior.
  • Checks: Current-head Branch Checks are queued or running; Helm dispatch is complete.
  • E2E: test:e2e applied; the current-head Branch E2E Checks workflow is running.
  • Head SHA: c158fff6b7562b59a536420d23cc3574eba63640
  • Base SHA: 7caff12d3c9013e7063d22391a76f775f6ce93b5
  • Merge base SHA: 7caff12d3c9013e7063d22391a76f775f6ce93b5
  • Patch ID: ea286f19a426e7fd6b2be7f6c31795406df95643
  • Gator payload: 9
  • Review mode: follow_up
  • Previous reviewed SHA: ed234d71ee5f9677e6bce4fed21d93b3b01e21b4
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Next state: gator:watch-pipeline

@johntmyers johntmyers added gator:watch-pipeline Gator is monitoring PR CI/CD status gator:blocked Gator is blocked by process or repository gates gator:in-review Gator is reviewing or awaiting PR review feedback and removed gator:in-review Gator is reviewing or awaiting PR review feedback gator:watch-pipeline Gator is monitoring PR CI/CD status gator:blocked Gator is blocked by process or repository gates labels Sep 30, 2026
Signed-off-by: Philippe Martin <phmartin@redhat.com>

@johntmyers johntmyers left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

PR Review Status

The follow-up review confirms that the test-only timeout and import cleanup do not reopen the resolved metadata-account finding or introduce a new blocker. No blocking findings remain; current-head CI and E2E still need dispatch.

Blocking findings:

  • No blocking findings remain

Carried findings:

  • None
Gator metadata
  • Validation: Implements the validated GCP metadata regression in #3860.
  • Docs: Updated for the restored Google Cloud metadata behavior.
  • Checks: Current-head workflows await contributor authorization and dispatch.
  • E2E: test:e2e is required; current-head dispatch is pending.
  • Head SHA: ec01442e51ff943679ab0e5b1647881b794bfa31
  • Base SHA: 7caff12d3c9013e7063d22391a76f775f6ce93b5
  • Merge base SHA: 7caff12d3c9013e7063d22391a76f775f6ce93b5
  • Patch ID: 514dbff67fcb4989bf62c31a966de9eae9263133
  • Gator payload: 9
  • Review mode: follow_up
  • Previous reviewed SHA: c158fff6b7562b59a536420d23cc3574eba63640
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Next state: gator:in-review

@johntmyers

Copy link
Copy Markdown
Collaborator

/ok to test ec01442

@johntmyers johntmyers added test:e2e Requires end-to-end coverage and removed test:e2e Requires end-to-end coverage labels Sep 30, 2026
@github-actions

Copy link
Copy Markdown

Label test:e2e applied for ec01442. Open the existing run and click Re-run all jobs to execute with the label set. The run will execute the standard E2E suite after building the required gateway, sandbox, and supervisor images once. The matching required CI gate status on this PR will flip green automatically once the run finishes.

@johntmyers johntmyers added gator:blocked Gator is blocked by process or repository gates gator:watch-pipeline Gator is monitoring PR CI/CD status gator:approval-needed Gator completed review; maintainer approval needed and removed gator:in-review Gator is reviewing or awaiting PR review feedback gator:blocked Gator is blocked by process or repository gates gator:watch-pipeline Gator is monitoring PR CI/CD status labels Sep 30, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gator:approval-needed Gator completed review; maintainer approval needed test:e2e Requires end-to-end coverage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug: Restore GCP metadata server support

2 participants