* refactor(inference): remove managed inference routes
Closes#3172
Remove the inference route control plane, inference.local data path, built-in router crate, and SDK surface. Move inference workloads to explicitly imported provider profiles and native endpoints, with migration cleanup and updated tests and documentation.
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
* fix(policy): preserve alternate upstream isolation
Restore the provider policy activation guard so legacy OpenAI and Anthropic providers configured for alternate base URLs do not grant egress to the built-in public vendor endpoints.
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
---------
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
* fix(gateway): align package TLS bootstrap path
Closes#1593
Default package-managed gateway services to a stable local TLS directory and use that same value for certificate generation and runtime startup.
Signed-off-by: Taylor Mutch <taylormutch@gmail.com>
* test(packaging): validate package asset paths exist
Signed-off-by: Taylor Mutch <taylormutch@gmail.com>
* ci(e2e): pin mise in kubernetes job
Signed-off-by: Taylor Mutch <taylormutch@gmail.com>
---------
Signed-off-by: Taylor Mutch <taylormutch@gmail.com>
After #1415 ships, users upgrading from previous releases need guidance
on the gateway.env deprecation, port/bind/database path changes, and
the podman.socket restart requirement.
- docs(rpm): add 'Migrating from gateway.env' section to TROUBLESHOOTING
covering backward compatibility, env-to-TOML key mapping, and three
breaking changes (default port 8080->17670, bind address 0.0.0.0->127.0.0.1,
database path move). Add podman.socket restart step to upgrade procedure.
- docs(rpm): add upgrade callout to CONFIGURATION.md pointing at migration
section.
- fix(podman): retry PodmanComputeDriver ping up to 5 times with 2s delay
to tolerate transient socket unavailability after package upgrades.
The systemd unit uses Wants=podman.socket (not Requires) so the gateway
can start while the socket is briefly re-activating after an RPM upgrade
changes its unit file on disk.
- chore(rpm): update EnvironmentFile comment in RPM spec to explain
backward-compatibility intent.
Signed-off-by: Adam Miller <admiller@redhat.com>
* fix(rpm): restore 0.0.0.0 bind address for Podman via default gateway.toml
The gateway binary default changed to 127.0.0.1 in recent commits
(b61a98db, f257ed01). This breaks the Podman compute driver because
sandbox containers reach the gateway over the host network bridge and
cannot connect to the loopback address.
Ship a default TOML config template that the RPM systemd unit seeds
into ~/.config/openshell/gateway.toml on first start. The template
sets bind_address = "0.0.0.0:17670" and pins compute_drivers =
["podman"] to prevent unexpected driver selection when Docker is also
installed. The binary default remains 127.0.0.1 (secure-by-default
for non-RPM installs).
Changes:
- deploy/rpm/gateway.toml.default: new default config template
- openshell.spec: install template to %{_datadir}/openshell-gateway/;
add ExecStartPre to seed ~/.config/openshell/gateway.toml on first
start; add %check assertions for template presence and unit reference
- deploy/rpm/CONFIGURATION.md: document default config, override paths,
and updated bind address throughout
- deploy/rpm/QUICKSTART.md: update bind address note for RPM installs
- crates/openshell-server/src/config_file.rs: contract test that parses
the RPM template through load() and asserts bind_address=0.0.0.0
and compute_drivers=[podman]
- e2e/with-podman-gateway.sh: start from RPM template as base config
so e2e exercises the same TOML path RPM users get on first start
* fix(rpm): restore openshell_python_version macro in dist-info metadata
* fix(rpm): reset Packit-managed version fields to match main baseline
Version, Source0, and Source1 were stamped to 0.0.43 by Packit CI
during branch builds. Reset to 0.0.37 (current main baseline) so
the spec diff only contains our intentional changes. Packit's
fix-spec-file action will re-stamp these fields at build time.
* Revert "fix(rpm): reset Packit-managed version fields to match main baseline"
This reverts commit 8ef9d7ad8e.
* fix(rpm): introduce openshell_version macro; remove hardcoded versions
Add %global openshell_version as the single source of truth for the
package version. Version:, Source0:, Source1:, openshell_cargo_version,
and openshell_python_version all expand from this one macro.
Update .packit.yaml fix-spec-file to patch %global openshell_version
instead of the Version:, Source0:, and Source1: lines individually.
* feat(rpm): replace init-pki.sh with openshell-gateway generate-certs
Cuts the RPM gateway over to the unified Rust certgen path. The systemd
user unit's first ExecStartPre now invokes:
/usr/bin/openshell-gateway generate-certs --output-dir %S/openshell/tls
producing the same six-PEM layout init-pki.sh built (ca.{crt,key},
server/tls.{crt,key}, client/tls.{crt,key}) and the same CLI mTLS copy
under $XDG_CONFIG_HOME/openshell/gateways/openshell/mtls/. None of the
OPENSHELL_TLS_* / OPENSHELL_PODMAN_TLS_* paths in the unit change.
Adds host.containers.internal to the gateway's built-in SAN list so
podman containers reaching their host validate cleanly with no
per-deployment --server-san flag. Docker (host.docker.internal) and
Kubernetes (cluster.local DNS) were already covered.
Drops 197 lines of openssl shell, the install/file lines for the script
itself, and updates the docs (man page, RPM CONFIGURATION.md, env-file
generator comment) to point at the new entrypoint. The %S state dir,
unit security hardening, and consumer paths are untouched.
* docs(certgen): remove stale init-pki.sh references in comments
---------
Co-authored-by: Taylor Mutch <taylormutch@gmail.com>
* chore: remove SSH handshake secret residuals and fix agent memory
Removes three artifacts left behind by the #1274 removal of
OPENSHELL_SSH_HANDSHAKE_SECRET, then corrects a sweep of stale and
inaccurate notes in .claude/agent-memory/arch-doc-writer/MEMORY.md
that were discovered during the audit.
Artifact removal (Refs OS-174):
- openshell.spec: stale comment claiming init-gateway-env.sh generates
an SSH handshake secret
- e2e/with-podman-gateway.sh: dead podman secret rm for
openshell-handshake-<id>, which is never created since #1274
Agent memory corrections:
- ssh_tunnel.rs no longer exists; replaced by ssh_sessions.rs
- Object types list was missing service_endpoint and provider_profile
- Pre-exec chain now includes harden_child_process() and uses the
linux::prepare()/enforce() two-phase pattern on Linux
- CLI SSH function list had nonexistent sandbox_rsync; corrected to
actual exported functions
- ExecSandbox is in grpc/sandbox.rs (not grpc.rs) and operates over
a supervisor relay DuplexStream, not a direct TCP connection
- resolve_ssh_gateway() moved to openshell-core/src/forward.rs
- SSH transport note rewrote: NSSH1 is an OCSF-only label (not a live
protocol preface); actual path is ForwardTcp -> DuplexStream ->
RelayStream -> Unix socket; access gated by CreateSshSession token;
TLS follows endpoint scheme (https:// = mTLS, http:// = plaintext;
Podman driver does not yet inject mTLS client materials)
- CLI flag note was self-contradictory; corrected to --gateway-endpoint
with resolution priority chain
* fix(vm): collapse nested if blocks to satisfy clippy::collapsible_if
Three nested if blocks in connect_local_container_engine() were
flagged by clippy after #1370. Collapse to single if-let chains
using && as suggested.
* feat(rpm): use :dev image tag for non-release builds
Add a %global image_tag macro to the spec file (default: dev) that
controls the container image tag baked into RPM-built binaries and
the installed systemd unit.
Packit's fix-spec-file action detects tagged stable releases via
git describe --exact-match and overrides the macro to 'latest'.
PR and commit-to-main builds keep the 'dev' default, matching the
:dev images pushed by release-dev.yml.
The init-gateway-env.sh installed copy is also patched at RPM build
time so its commented image defaults stay consistent with the tag
the RPM actually expects from the registry.
Signed-off-by: Adam Miller <admiller@redhat.com>
* fix(rpm): scope image_tag to supervisor only; sandbox base stays latest
The community sandbox base image (ghcr.io/nvidia/openshell-community/
sandboxes/base) does not publish :dev tags -- only :latest and version-
pinned tags are available. Applying %{image_tag} to it caused a
manifest unknown error when pulling the image on non-release builds.
Scope the dynamic tag to the supervisor image only, which is part of
the core OpenShell release pipeline and does receive :dev tags from
release-dev.yml. The sandbox base image unconditionally uses :latest.
Also tighten the sed in %install to target only the supervisor image
line in init-gateway-env.sh rather than blanket-replacing all :latest
occurrences.
Signed-off-by: Adam Miller <admiller@redhat.com>
* fix(rpm): restore %%{openshell_python_version} in Python dist-info METADATA
The Version field inside the METADATA heredoc was hardcoded to 0.0.37
instead of using the %%{openshell_python_version} macro. This caused
the installed Python dist-info to always report the wrong version on
non-release builds.
Signed-off-by: Adam Miller <admiller@redhat.com>
---------
Signed-off-by: Adam Miller <admiller@redhat.com>