Files
Dhiraj Bokde cc4ded2088 feat(helm): split gateway and workspace charts (#2643)
* feat(helm): split gateway and workspace charts

Signed-off-by: Dhiraj Bokde <dbokde@nvidia.com>

* fix(helm): preserve split chart upgrade compatibility

Keep workspace manifests valid after value validation and default legacy reused values to the combined resource topology.

* fix(ci): preserve VM runtime for E2E

The Rust cache restores target/ after VM runtime artifacts are staged,
overwriting target/vm-runtime-compressed before openshell-driver-vm is built.
Stage the compressed runtime outside target and pass that location through
OPENSHELL_VM_RUNTIME_COMPRESSED_DIR so build.rs can embed the supervisor.

Also locate the Helm split-ownership test repository root from the script
path rather than git rev-parse. The test runs in a container where the
GitHub checkout can be owned by a different UID and rejected as dubious
ownership.

Signed-off-by: Dhiraj Bokde <dbokde@nvidia.com>

* fix(ci): install yq for Helm ownership test

The split-chart ownership regression uses yq to inspect rendered YAML,
but the Helm CI container installs only tools declared in mise.
Declare and lock yq so mise install --locked provides the test dependency.

Signed-off-by: Dhiraj Bokde <dbokde@nvidia.com>

---------

Signed-off-by: Dhiraj Bokde <dbokde@nvidia.com>
2026-09-02 00:23:39 +00:00
..

OpenShell Workspace Helm Chart

Experimental - the shared-gateway, multi-namespace deployment path is under active design.

This chart installs the namespace-scoped ServiceAccount, RBAC, and NetworkPolicy needed for OpenShell Kubernetes sandboxes. Install it once in every platform-managed workspace namespace. It does not create a namespace or deploy an OpenShell gateway.

Install the gateway chart with workspaceResources.enabled=false, then install this chart with the gateway ServiceAccount identity. Configure the gateway's Kubernetes driver in operator workspace mode when it serves more than one pre-provisioned workspace namespace:

helm install openshell-workspace ./deploy/helm/openshell-workspace \
  --namespace app-a \
  --set gateway.serviceAccount.name=openshell \
  --set gateway.serviceAccount.namespace=openshell

Keep sandboxServiceAccount.name aligned with the gateway chart's sandboxServiceAccount.name. The defaults for both charts are openshell-sandbox.

Values

Key Type Default Description
fullnameOverride string "" Override the full generated resource name.
gateway.networkPolicy.podSelector object {"app.kubernetes.io/instance":"openshell","app.kubernetes.io/name":"openshell"} Labels selecting gateway pods allowed to reach sandbox SSH.
gateway.serviceAccount.name string "openshell" Name of the shared gateway ServiceAccount.
gateway.serviceAccount.namespace string "openshell" Namespace containing the shared gateway ServiceAccount.
nameOverride string "" Override the chart name used in generated resource names.
networkPolicy.enabled bool true Restrict sandbox SSH ingress to the shared gateway pods.
sandboxServiceAccount.annotations object {} Annotations added to the generated sandbox ServiceAccount.
sandboxServiceAccount.create bool true Create the ServiceAccount assigned to sandbox pods.
sandboxServiceAccount.name string "openshell-sandbox" Sandbox ServiceAccount name.

Autogenerated from chart metadata using helm-docs v1.14.2