Conversation
Relay the reserved metadata endpoint to the supervisor and restore project, account, and placeholder token responses from live provider state. Cover Google SDK discovery and repeated refresh with provider E2E tests. Closes NVIDIA#3860 Signed-off-by: Philippe Martin <phmartin@redhat.com>
E2E Test AttestationLocal provider E2E tests passed against an isolated Podman gateway.
CommandOPENSHELL_GATEWAY_BIN="$PWD/target/debug/openshell-gateway" \
OPENSHELL_BIN="$PWD/target/debug/openshell" \
SUPERVISOR_IMAGE=localhost/openshell/supervisor:dev \
SANDBOX_IMAGE=localhost/openshell/sandbox:dev \
OPENSHELL_E2E_PODMAN_SANDBOX_IMAGE=localhost/openshell/e2e-python:dev \
UV_NO_SYNC=1 PYTHONPATH=python \
e2e/with-podman-gateway.sh uv run pytest \
-o 'python_files=test_*.py *_test.py' -vv e2e/python/test_sandbox_providers.pyRuntime images
Tests ExecutedAll tests are in
Full local |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
The restoration is project-valid and the full initial patch review found one blocking correctness gap in the default documented provider setup.
Action required: @feloy, make metadata-based refresh work when service_account_email is omitted and add coverage for that documented path.
Blocking findings:
GATOR-ed234d71-01: the recursive account response can select an empty account name and send the SDK to an unsupported token route.
Carried findings:
- None
Gator metadata
- Validation: Implements the validated regression in #3860.
- Docs: Updated, but the documented no-email setup exposes the blocking finding.
- Checks: Current-head branch and Helm gates are pending; pipeline handoff waits for review feedback.
- E2E: Required for provider credential and sandbox-network behavior; dispatch waits until the blocker is addressed.
- Head SHA:
ed234d71ee5f9677e6bce4fed21d93b3b01e21b4 - Base SHA:
7caff12d3c9013e7063d22391a76f775f6ce93b5 - Merge base SHA:
7caff12d3c9013e7063d22391a76f775f6ce93b5 - Patch ID:
c51d73bf9e9c8c269ff8710b12d2b5bc440af861 - Gator payload:
9 - Review mode:
initial - Previous reviewed SHA: none
- Review budget exhausted: no
- Maintainer decision required: no
- Next state:
gator:in-review
Use the default account identifier when the optional service account email is missing or empty. Cover repeated SDK refresh for missing, empty, and configured email values with distinct providers for parallel E2E execution. Signed-off-by: Philippe Martin <phmartin@redhat.com>
|
Label |
|
/ok to test c158fff |
|
Label |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
The follow-up review confirms that the default-account fix and expanded SDK coverage resolve GATOR-ed234d71-01. No blocking findings remain, and the required current-head Branch Checks and E2E workflows are now running.
Blocking findings:
- No blocking findings remain
Carried findings:
- None
Gator metadata
- Validation: Implements the validated GCP metadata regression in #3860.
- Docs: Updated for optional or empty
service_account_emailbehavior. - Checks: Current-head Branch Checks are queued or running; Helm dispatch is complete.
- E2E:
test:e2eapplied; the current-head Branch E2E Checks workflow is running. - Head SHA:
c158fff6b7562b59a536420d23cc3574eba63640 - Base SHA:
7caff12d3c9013e7063d22391a76f775f6ce93b5 - Merge base SHA:
7caff12d3c9013e7063d22391a76f775f6ce93b5 - Patch ID:
ea286f19a426e7fd6b2be7f6c31795406df95643 - Gator payload:
9 - Review mode:
follow_up - Previous reviewed SHA:
ed234d71ee5f9677e6bce4fed21d93b3b01e21b4 - Review budget exhausted: no
- Maintainer decision required: no
- Next state:
gator:watch-pipeline
Signed-off-by: Philippe Martin <phmartin@redhat.com>
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
The follow-up review confirms that the test-only timeout and import cleanup do not reopen the resolved metadata-account finding or introduce a new blocker. No blocking findings remain; current-head CI and E2E still need dispatch.
Blocking findings:
- No blocking findings remain
Carried findings:
- None
Gator metadata
- Validation: Implements the validated GCP metadata regression in #3860.
- Docs: Updated for the restored Google Cloud metadata behavior.
- Checks: Current-head workflows await contributor authorization and dispatch.
- E2E:
test:e2eis required; current-head dispatch is pending. - Head SHA:
ec01442e51ff943679ab0e5b1647881b794bfa31 - Base SHA:
7caff12d3c9013e7063d22391a76f775f6ce93b5 - Merge base SHA:
7caff12d3c9013e7063d22391a76f775f6ce93b5 - Patch ID:
514dbff67fcb4989bf62c31a966de9eae9263133 - Gator payload:
9 - Review mode:
follow_up - Previous reviewed SHA:
c158fff6b7562b59a536420d23cc3574eba63640 - Review budget exhausted: no
- Maintainer decision required: no
- Next state:
gator:in-review
|
/ok to test ec01442 |
|
Label |
Summary
Restore the Google Cloud metadata emulator removed during the sandbox/supervisor split. SDK requests to the injected
127.0.0.1:8174address now reach a supervisor-owned emulator through the existing authenticated network relay, allowing Application Default Credentials discovery and repeated token refresh.Related Issue
Closes #3860
Changes
503response without an explicit credential binding.Deviations from Plan
Local E2E validation uses Podman because Docker is unavailable on this development host. The regression tests remain in the existing Python E2E suite.
Testing
mise run pre-commitpasses, including the commit hook.mise run cipasses (lint, compile/type checks, Rust/Python/TypeScript/Go tests, and dependency policy checks).google-auth==2.40.3, ADC metadata detection, project/account discovery, repeated refresh, placeholder isolation, and missing credential bindings.200with a bound Google Cloud provider and503without a binding.E2E command:
Checklist
docs/how-it-works/providers/google.mdx; related public policy skill reviewed and updated.