Drew Newberry
17ce738bfb
fix(ci)!: remove gateway callback listener dependency ( #3365 )
...
* fix(ci): repair post-merge release canary
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(packaging): bootstrap canary runtime prerequisites
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* ci(canary): collect macOS VM diagnostics
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* ci(canary): pin libkrun-compatible macOS runner
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* ci(canary): limit macOS smoke test to package startup
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* refactor(compute)!: remove gateway callback listeners
Run Docker supervisors on host networking so they use the operator-configured primary gateway endpoint. Remove the unused compute-driver callback listener negotiation and listener-scoped routing machinery.
BREAKING CHANGE: The ComputeDriver API no longer exposes GetGatewayListenerRequirements or GatewayListenerRequirement. External drivers must regenerate bindings and connect supervisors to the configured primary gateway endpoint.
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* refactor(docker): use sandbox runtime image in launcher
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* test(podman): exercise production endpoint selection
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(e2e): route supervisors to reachable gateways
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* test(e2e): align Podman endpoint fixtures
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(docker): preserve host aliases for supervisors
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(docker): align sandbox host gateway pin
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(e2e): address Docker fixtures by bridge IP
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* test(e2e): serialize sandbox lifecycle cases
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(e2e): host Docker TCP fixture with gateway
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
* fix(e2e): use loopback for host-network supervisor
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
---------
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
2026-09-18 20:55:55 +00:00
Simon Scatton
8bd3dcc565
refactor(tmachine): separate installers from environments ( #3419 )
...
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
2026-09-18 12:59:20 +00:00
Simon Scatton
4b2cb7f007
test(tmachine): verify SELinux in Fedora scenarios ( #3457 )
...
Closes #2973
Closes #2976
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
2026-09-18 13:57:13 +02:00
Evan Lezar
2263685cf3
test(tmachine): migrate Keycloak provider refresh coverage ( #3404 )
...
* test(tmachine): add Keycloak provider refresh suite
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* refactor(tmachine): share container runtime detection
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* ci(tmachine): run feature suites in GitHub Actions
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* ci(tmachine): run conformance with Podman tests
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* ci(tmachine): cover provider refresh with Podman
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* ci(integration): split input preparation from runners
Signed-off-by: Evan Lezar <elezar@nvidia.com >
---------
Signed-off-by: Evan Lezar <elezar@nvidia.com >
2026-09-18 13:56:07 +02:00
Simon Scatton
fc07165544
test(tmachine): accept scalar playbook inputs ( #3418 )
...
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
2026-09-17 20:07:32 +00:00
Evan Lezar
af4b200786
test(conformance): cover sandbox lifecycle in archives ( #3375 )
...
* test(conformance): add sandbox lifecycle coverage
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* test(tmachine): rename smoke suite to conformance
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* test(tmachine): configure client during scenario install
Signed-off-by: Evan Lezar <elezar@nvidia.com >
---------
Signed-off-by: Evan Lezar <elezar@nvidia.com >
2026-09-17 16:10:31 +00:00
Simon Scatton
0a0a563dd3
ci(conformance): run tmachine suites in release dev ( #3382 )
...
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
2026-09-17 17:13:56 +02:00
Evan Lezar
292559c41c
test(tmachine): run smoke tests from nextest archives ( #3372 )
...
* test(conformance): package CLI smoke test archive
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* test(tmachine): execute nextest archives in guests
Signed-off-by: Evan Lezar <elezar@nvidia.com >
---------
Signed-off-by: Evan Lezar <elezar@nvidia.com >
2026-09-16 12:49:55 +00:00
Simon Scatton and Evan Lezar
9b52b43b39
test(tmachine): add portable VM-based container runtime testing ( #3371 )
...
* test(tmachine): add Docker VM scenario
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* test(tmachine): add portable container scenarios
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* chore(tmachine): isolate downloaded Ansible roles
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* test(tmachine): increase VM resources
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* test(tmachine): improve artifact builds and diagnostics
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* fix(nix): pin tmachine runtime on macOS
Signed-off-by: Evan Lezar <elezar@nvidia.com >
* feat(tests): enable tty and fix supervisor image path
* fix(nix): isolate testing tools from default shell
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* fix(tmachine): initialize test runner working directory
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* fix(tmachine): include Ansible sources in layer cache keys
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* fix(tmachine): build and load separate runtime images
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
* fix(tmachine): use local runtime images for Docker
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
---------
Signed-off-by: Simon Scatton <sscatton@nvidia.com >
Signed-off-by: Evan Lezar <elezar@nvidia.com >
Co-authored-by: Evan Lezar <elezar@nvidia.com >
2026-09-16 11:54:28 +00:00
Drew Newberry
ad388219c2
chore(tests): cleanup unused tests
2026-02-19 23:20:21 -08:00
Drew Newberry
f362963c7b
feat(sandbox): add provider entity to support configuring tools such as claude, outlook, etc ( !23 )
...
## Summary
- Add `Provider` entity for managing 3p deps from a sandbox
- Add provider CRUD API/server persistence and new CLI workflows (`nav provider create/get/list/update/delete`), including `--from-existing` laptop discovery.
- Integrate providers into sandbox create flow: infer from command (`-- claude`), support repeatable `--provider <type>`, prompt before auto-create, and allow manual in-sandbox setup.
- Add a dedicated `navigator-providers` crate with per-provider modules and mockable discovery test helpers.
## Key UX Changes
- `nav sandbox create --provider gitlab -- claude`
- Missing provider prompt now asks before creating from local state.
- `nav provider list --names` for scripting/cleanup.
## Test Plan
- `mise run cluster:deploy`
- `mise run test:e2e:sandbox`
- `mise run pre-commit`
Closes #19
Closes #22
Closes #11
2026-02-16 14:40:32 -08:00
Drew Newberry
d2f3ca71d4
feat(sandbox): add callable python exec API and refresh e2e coverage ( !19 )
...
Closes #13
## Summary
- add Python sandbox execution APIs for command and callable workflows
- consolidate sandbox policy fixtures and expand e2e test coverage for policy and Python exec paths
- update CI/build config and images for sandbox e2e execution dependencies
## Test Plan
- mise run pre-commit
2026-02-12 23:30:24 -08:00
John Myers
87b2446501
feat(sandbox): OPA policy engine with process-identity binding
2026-02-10 10:57:31 -08:00
Drew Newberry
ede23ea7c4
fix(server): cleanup server multiplexing, tls
2026-02-04 11:41:04 -08:00
Drew Newberry
d5d3c71e9c
feat(sandboxes): initial kube sandbox impl
2026-02-03 22:13:20 -08:00
Drew Newberry
516125c3d4
test(e2e): add e2e tests on skaffold
2026-02-02 17:19:00 -08:00