Evan Lezar and Drew Newberry
d220d89468
feat(compute): negotiate gateway callback listeners ( #2492 )
...
* feat(compute): query gateway listener requirements
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* feat(compute): add Podman listener requirements
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* test(docker): use default gateway bind address
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* fix(gateway): avoid wildcard primary listener
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* fix(podman): validate callback listener discovery
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* fix(server): support split dual-stack listeners
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* fix(podman): support legacy rootless listener discovery
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* test(e2e): accept loopback plaintext rejection
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* docs(agent): add callback listener diagnostics
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* fix(server): restrict compute callback listeners
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* fix(podman): validate local callback port
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* test(server): clarify callback listener contract
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* fix(podman): require pasta for local callbacks
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* docs(gateway): document RPM listener default
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* refactor(server): keep listener provenance diagnostic-only
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* fix(compute): preserve callback listener isolation
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* test(e2e): remove Podman callback relay
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(packaging): preserve Podman callback loopback
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* ci(e2e): run VM smoke on nested-virt runner
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* ci(e2e): gate VM smoke on usable KVM
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* ci(e2e): probe KVM through VM driver
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* ci(e2e): tolerate hosted KVM denial
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* test(server): close traced futures before assertions
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* revert: remove tracing test stabilization
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
---------
Signed-off-by: Evan Lezar <elezar@nvidia.com >
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
Co-authored-by: Drew Newberry <anewberry@nvidia.com >
2026-07-31 16:41:06 +00:00
Drew Newberry
e4b4e923ae
test(e2e): run suites against docker gateway ( #1153 )
2026-05-05 13:28:08 -07:00
Drew Newberry
fbd93a4632
refactor: rename navigator- crate prefix to openshell- ( #277 )
2026-03-13 02:02:18 -07:00
Drew Newberry
756950140c
refactor(python): rename navigator module to openshell and migrate config to gateway paths ( #220 )
2026-03-10 22:24:04 -07:00
Drew Newberry
984d1a6e5c
chore: rename project from NemoClaw to OpenShell ( #198 )
2026-03-10 11:49:09 -07:00
Drew Newberry
9099bc3972
chore: rename Navigator to NemoClaw across user facing contracts ( #73 )
2026-03-03 11:41:19 -08:00
Alexander Watson
1d7909cb38
chore: add open-source compliance files and SPDX headers ( #71 )
...
Add Apache 2.0 licensing, SPDX copyright headers on all source files,
DCO enforcement, third-party notices, and CI enforcement.
- LICENSE: Apache License 2.0 full text
- DCO: Developer Certificate of Origin 1.1
- SPDX headers on all 176 source files (.rs, .py, .proto, .rego, .sh,
.toml, .yaml, Dockerfiles)
- scripts/update_license_headers.py: header management with --check mode
- scripts/generate_third_party_notices.py: dependency license aggregation
- THIRD-PARTY-NOTICES: generated listing of all Rust and Python deps
- build/license.toml: mise tasks for license:check and license:update
- CI: license-headers job in checks.yml, DCO check workflow
- CONTRIBUTING.md: DCO sign-off requirement and license header docs
- Cargo.toml: license changed to Apache-2.0, repository URL updated
- pyproject.toml: license field added
Closes #58
2026-03-03 09:30:56 -08:00
Drew Newberry
2d85338940
feat(platform): cleanup api surface area and mtls flows ( !39 )
...
Closes #48 , #52
## Summary
- Replace the envoy-gateway-based TLS setup with inline PKI generation during cluster bootstrap, generating CA, server, and client certificates directly in the `navigator-bootstrap` crate
- Remove all envoy gateway Helm templates (`gateway.yaml`, `gatewayclass.yaml`, `grpcroute.yaml`, PKI job, traffic policies) and the `Dockerfile.pki-job`
- Add native mTLS support to the navigator server with `tokio-rustls`, mounting client TLS certs as volumes into sandbox pods
- Update cluster entrypoint, healthcheck, and deploy scripts to work with the new direct-TLS architecture
- Add TLS security e2e test and fix formatting/clippy warnings
## Test Plan
- All unit tests pass (`cargo test --workspace`)
- Clippy clean (`cargo clippy --workspace --all-targets`)
- Format clean (`cargo fmt --all -- --check`)
- Python tests pass (`uv run pytest python/`)
- Full `mise run pre-commit` passes
2026-02-24 11:33:33 -08:00