* feat(helm): split gateway and workspace charts Signed-off-by: Dhiraj Bokde <dbokde@nvidia.com> * fix(helm): preserve split chart upgrade compatibility Keep workspace manifests valid after value validation and default legacy reused values to the combined resource topology. * fix(ci): preserve VM runtime for E2E The Rust cache restores target/ after VM runtime artifacts are staged, overwriting target/vm-runtime-compressed before openshell-driver-vm is built. Stage the compressed runtime outside target and pass that location through OPENSHELL_VM_RUNTIME_COMPRESSED_DIR so build.rs can embed the supervisor. Also locate the Helm split-ownership test repository root from the script path rather than git rev-parse. The test runs in a container where the GitHub checkout can be owned by a different UID and rejected as dubious ownership. Signed-off-by: Dhiraj Bokde <dbokde@nvidia.com> * fix(ci): install yq for Helm ownership test The split-chart ownership regression uses yq to inspect rendered YAML, but the Helm CI container installs only tools declared in mise. Declare and lock yq so mise install --locked provides the test dependency. Signed-off-by: Dhiraj Bokde <dbokde@nvidia.com> --------- Signed-off-by: Dhiraj Bokde <dbokde@nvidia.com>
OpenShell Workspace Helm Chart
Experimental - the shared-gateway, multi-namespace deployment path is under active design.
This chart installs the namespace-scoped ServiceAccount, RBAC, and NetworkPolicy needed for OpenShell Kubernetes sandboxes. Install it once in every platform-managed workspace namespace. It does not create a namespace or deploy an OpenShell gateway.
Install the gateway chart with workspaceResources.enabled=false, then install
this chart with the gateway ServiceAccount identity. Configure the gateway's
Kubernetes driver in operator workspace mode when it serves more than one
pre-provisioned workspace namespace:
helm install openshell-workspace ./deploy/helm/openshell-workspace \
--namespace app-a \
--set gateway.serviceAccount.name=openshell \
--set gateway.serviceAccount.namespace=openshell
Keep sandboxServiceAccount.name aligned with the gateway chart's
sandboxServiceAccount.name. The defaults for both charts are
openshell-sandbox.
Values
| Key | Type | Default | Description |
|---|---|---|---|
| fullnameOverride | string | "" |
Override the full generated resource name. |
| gateway.networkPolicy.podSelector | object | {"app.kubernetes.io/instance":"openshell","app.kubernetes.io/name":"openshell"} |
Labels selecting gateway pods allowed to reach sandbox SSH. |
| gateway.serviceAccount.name | string | "openshell" |
Name of the shared gateway ServiceAccount. |
| gateway.serviceAccount.namespace | string | "openshell" |
Namespace containing the shared gateway ServiceAccount. |
| nameOverride | string | "" |
Override the chart name used in generated resource names. |
| networkPolicy.enabled | bool | true |
Restrict sandbox SSH ingress to the shared gateway pods. |
| sandboxServiceAccount.annotations | object | {} |
Annotations added to the generated sandbox ServiceAccount. |
| sandboxServiceAccount.create | bool | true |
Create the ServiceAccount assigned to sandbox pods. |
| sandboxServiceAccount.name | string | "openshell-sandbox" |
Sandbox ServiceAccount name. |
Autogenerated from chart metadata using helm-docs v1.14.2