Commit Graph
16 Commits
Author SHA1 Message Date
Drew Newberry 17ce738bfb fix(ci)!: remove gateway callback listener dependency (#3365)
* fix(ci): repair post-merge release canary

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(packaging): bootstrap canary runtime prerequisites

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* ci(canary): collect macOS VM diagnostics

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* ci(canary): pin libkrun-compatible macOS runner

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* ci(canary): limit macOS smoke test to package startup

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* refactor(compute)!: remove gateway callback listeners

Run Docker supervisors on host networking so they use the operator-configured primary gateway endpoint. Remove the unused compute-driver callback listener negotiation and listener-scoped routing machinery.

BREAKING CHANGE: The ComputeDriver API no longer exposes GetGatewayListenerRequirements or GatewayListenerRequirement. External drivers must regenerate bindings and connect supervisors to the configured primary gateway endpoint.

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* refactor(docker): use sandbox runtime image in launcher

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* test(podman): exercise production endpoint selection

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(e2e): route supervisors to reachable gateways

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* test(e2e): align Podman endpoint fixtures

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(docker): preserve host aliases for supervisors

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(docker): align sandbox host gateway pin

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(e2e): address Docker fixtures by bridge IP

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* test(e2e): serialize sandbox lifecycle cases

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(e2e): host Docker TCP fixture with gateway

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(e2e): use loopback for host-network supervisor

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

---------

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-18 20:55:55 +00:00
Simon Scatton 8bd3dcc565 refactor(tmachine): separate installers from environments (#3419)
Signed-off-by: Simon Scatton <sscatton@nvidia.com>
2026-09-18 12:59:20 +00:00
Simon Scatton 4b2cb7f007 test(tmachine): verify SELinux in Fedora scenarios (#3457)
Closes #2973

Closes #2976

Signed-off-by: Simon Scatton <sscatton@nvidia.com>
2026-09-18 13:57:13 +02:00
Evan Lezar 2263685cf3 test(tmachine): migrate Keycloak provider refresh coverage (#3404)
* test(tmachine): add Keycloak provider refresh suite

Signed-off-by: Evan Lezar <elezar@nvidia.com>

* refactor(tmachine): share container runtime detection

Signed-off-by: Evan Lezar <elezar@nvidia.com>

* ci(tmachine): run feature suites in GitHub Actions

Signed-off-by: Evan Lezar <elezar@nvidia.com>

* ci(tmachine): run conformance with Podman tests

Signed-off-by: Evan Lezar <elezar@nvidia.com>

* ci(tmachine): cover provider refresh with Podman

Signed-off-by: Evan Lezar <elezar@nvidia.com>

* ci(integration): split input preparation from runners

Signed-off-by: Evan Lezar <elezar@nvidia.com>

---------

Signed-off-by: Evan Lezar <elezar@nvidia.com>
2026-09-18 13:56:07 +02:00
Simon Scatton fc07165544 test(tmachine): accept scalar playbook inputs (#3418)
Signed-off-by: Simon Scatton <sscatton@nvidia.com>
2026-09-17 20:07:32 +00:00
Evan Lezar af4b200786 test(conformance): cover sandbox lifecycle in archives (#3375)
* test(conformance): add sandbox lifecycle coverage

Signed-off-by: Evan Lezar <elezar@nvidia.com>

* test(tmachine): rename smoke suite to conformance

Signed-off-by: Evan Lezar <elezar@nvidia.com>

* test(tmachine): configure client during scenario install

Signed-off-by: Evan Lezar <elezar@nvidia.com>

---------

Signed-off-by: Evan Lezar <elezar@nvidia.com>
2026-09-17 16:10:31 +00:00
Simon Scatton 0a0a563dd3 ci(conformance): run tmachine suites in release dev (#3382)
Signed-off-by: Simon Scatton <sscatton@nvidia.com>
2026-09-17 17:13:56 +02:00
Evan Lezar 292559c41c test(tmachine): run smoke tests from nextest archives (#3372)
* test(conformance): package CLI smoke test archive

Signed-off-by: Evan Lezar <elezar@nvidia.com>

* test(tmachine): execute nextest archives in guests

Signed-off-by: Evan Lezar <elezar@nvidia.com>

---------

Signed-off-by: Evan Lezar <elezar@nvidia.com>
2026-09-16 12:49:55 +00:00
Simon ScattonandEvan Lezar 9b52b43b39 test(tmachine): add portable VM-based container runtime testing (#3371)
* test(tmachine): add Docker VM scenario

Signed-off-by: Simon Scatton <sscatton@nvidia.com>

* test(tmachine): add portable container scenarios

Signed-off-by: Simon Scatton <sscatton@nvidia.com>

* chore(tmachine): isolate downloaded Ansible roles

Signed-off-by: Simon Scatton <sscatton@nvidia.com>

* test(tmachine): increase VM resources

Signed-off-by: Simon Scatton <sscatton@nvidia.com>

* test(tmachine): improve artifact builds and diagnostics

Signed-off-by: Simon Scatton <sscatton@nvidia.com>

* fix(nix): pin tmachine runtime on macOS

Signed-off-by: Evan Lezar <elezar@nvidia.com>

* feat(tests): enable tty and fix supervisor image path

* fix(nix): isolate testing tools from default shell

Signed-off-by: Simon Scatton <sscatton@nvidia.com>

* fix(tmachine): initialize test runner working directory

Signed-off-by: Simon Scatton <sscatton@nvidia.com>

* fix(tmachine): include Ansible sources in layer cache keys

Signed-off-by: Simon Scatton <sscatton@nvidia.com>

* fix(tmachine): build and load separate runtime images

Signed-off-by: Simon Scatton <sscatton@nvidia.com>

* fix(tmachine): use local runtime images for Docker

Signed-off-by: Simon Scatton <sscatton@nvidia.com>

---------

Signed-off-by: Simon Scatton <sscatton@nvidia.com>
Signed-off-by: Evan Lezar <elezar@nvidia.com>
Co-authored-by: Evan Lezar <elezar@nvidia.com>
2026-09-16 11:54:28 +00:00
Drew Newberry ad388219c2 chore(tests): cleanup unused tests 2026-02-19 23:20:21 -08:00
Drew Newberry f362963c7b feat(sandbox): add provider entity to support configuring tools such as claude, outlook, etc (!23)
## Summary
- Add `Provider` entity for managing 3p deps from a sandbox
- Add provider CRUD API/server persistence and new CLI workflows (`nav provider create/get/list/update/delete`), including `--from-existing` laptop discovery.
- Integrate providers into sandbox create flow: infer from command (`-- claude`), support repeatable `--provider <type>`, prompt before auto-create, and allow manual in-sandbox setup.
- Add a dedicated `navigator-providers` crate with per-provider modules and mockable discovery test helpers.

## Key UX Changes
- `nav sandbox create --provider gitlab -- claude`
- Missing provider prompt now asks before creating from local state.
- `nav provider list --names` for scripting/cleanup.

## Test Plan
- `mise run cluster:deploy`
- `mise run test:e2e:sandbox`
- `mise run pre-commit`

Closes #19
Closes #22
Closes #11
2026-02-16 14:40:32 -08:00
Drew Newberry d2f3ca71d4 feat(sandbox): add callable python exec API and refresh e2e coverage (!19)
Closes #13

## Summary
- add Python sandbox execution APIs for command and callable workflows
- consolidate sandbox policy fixtures and expand e2e test coverage for policy and Python exec paths
- update CI/build config and images for sandbox e2e execution dependencies

## Test Plan
- mise run pre-commit
2026-02-12 23:30:24 -08:00
John Myers 87b2446501 feat(sandbox): OPA policy engine with process-identity binding 2026-02-10 10:57:31 -08:00
Drew Newberry ede23ea7c4 fix(server): cleanup server multiplexing, tls 2026-02-04 11:41:04 -08:00
Drew Newberry d5d3c71e9c feat(sandboxes): initial kube sandbox impl 2026-02-03 22:13:20 -08:00
Drew Newberry 516125c3d4 test(e2e): add e2e tests on skaffold 2026-02-02 17:19:00 -08:00