mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-02 07:34:45 +08:00
docs(website): sync dev docs from 5448fb4f98
This commit is contained in:
@@ -1,8 +1,8 @@
|
||||
snapshots:
|
||||
dev:
|
||||
source-ref: d376c9075523d8ba37775d57b8a842a4b0f32c26
|
||||
source-sha: d376c9075523d8ba37775d57b8a842a4b0f32c26
|
||||
version: 0.0.117.dev284
|
||||
source-ref: 5448fb4f9814fae3d8dbb7329510d70348ed86dd
|
||||
source-sha: 5448fb4f9814fae3d8dbb7329510d70348ed86dd
|
||||
version: 0.0.117.dev285
|
||||
latest:
|
||||
source-ref: e36d2315cab8b638e3b718d6cc9d6146e732c2ad
|
||||
source-sha: e36d2315cab8b638e3b718d6cc9d6146e732c2ad
|
||||
|
||||
@@ -270,7 +270,7 @@ The client-certificate handshake policy is derived and has no `require_client_au
|
||||
|
||||
`[openshell.gateway] policy_validation_failure_mode` controls what sandbox supervisors do when a complete candidate policy fails runtime validation. The default, `fail_closed`, deactivates the previous network policy, closes relays pinned to it, and denies new egress until a valid generation loads. `retain_last_valid` leaves the previous valid generation active. Both modes reject the candidate atomically; startup keeps the workload unstarted until the effective policy and matching provider configuration pass admission. A rejected startup exposes `ConfigurationInvalid` and remains available for policy/provider repair in either mode. Gateway mutation paths that can preflight a known effective scope reject invalid candidates before persistence and leave the active policy unchanged regardless of this setting. Changing the value requires restarting the gateway so it can reload `gateway.toml` and distribute the new posture to sandbox supervisors.
|
||||
|
||||
`[openshell.gateway.gateway_jwt] ttl_secs` controls generation-bound gateway-facing and Sandbox Protocol credentials minted for a sandbox session, plus typed extension JWTs. Omit it for non-expiring local sandbox session credentials: both session tokens carry `exp = 0`, and refresh responses omit their expiration timestamps. Typed extension JWTs retain a 900-second default when the field is omitted. Use omission only for local single-player Docker, Podman, or VM gateways. Explicit `0` is invalid. Kubernetes and other shared deployments should set a positive TTL; Helm renders `3600` seconds by default, and the gateway logs a warning when a Kubernetes gateway omits the field.
|
||||
`[openshell.gateway.gateway_jwt] ttl_secs` controls generation-bound gateway-facing and Sandbox Protocol credentials minted for a sandbox session, plus typed extension JWTs. Omit it for non-expiring local sandbox session credentials: both session tokens carry `exp = 0`, supervisors skip periodic session-token renewal, and refresh responses omit their expiration timestamps. Typed extension JWTs retain a 900-second default when the field is omitted. Use omission only for local single-player Docker, Podman, or VM gateways. Explicit `0` is invalid. Kubernetes and other shared deployments should set a positive TTL; Helm renders `3600` seconds by default, and the gateway logs a warning when a Kubernetes gateway omits the field.
|
||||
|
||||
`[openshell.gateway.auth] allow_unauthenticated_users = true` is an unsafe local-development and trusted-proxy escape hatch. It accepts user-facing CLI/API calls without OIDC or mTLS credentials while sandbox supervisors still authenticate with gateway-minted sandbox JWTs. Leave it false for shared and production gateways.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user