Files

OpenShell Workspace Helm Chart

Experimental - the shared-gateway, multi-namespace deployment path is under active design.

This chart installs the namespace-scoped ServiceAccount, RBAC, and NetworkPolicy needed for OpenShell Kubernetes sandboxes. Install it once in every platform-managed workspace namespace. It does not create a namespace or deploy an OpenShell gateway.

Install the gateway chart with workspaceResources.enabled=false, then install this chart with the gateway ServiceAccount identity. Configure the gateway's Kubernetes driver in operator workspace mode when it serves more than one pre-provisioned workspace namespace:

helm install openshell-workspace ./deploy/helm/openshell-workspace \
  --namespace app-a \
  --set gateway.serviceAccount.name=openshell \
  --set gateway.serviceAccount.namespace=openshell

Keep sandboxServiceAccount.name aligned with the gateway chart's sandboxServiceAccount.name. The defaults for both charts are openshell-sandbox.

Values

Key Type Default Description
fullnameOverride string "" Override the full generated resource name.
gateway.networkPolicy.podSelector object {"app.kubernetes.io/instance":"openshell","app.kubernetes.io/name":"openshell"} Labels selecting gateway pods allowed to reach sandbox SSH.
gateway.serviceAccount.name string "openshell" Name of the shared gateway ServiceAccount.
gateway.serviceAccount.namespace string "openshell" Namespace containing the shared gateway ServiceAccount.
nameOverride string "" Override the chart name used in generated resource names.
networkPolicy.enabled bool true Restrict sandbox SSH ingress to the shared gateway pods.
sandboxServiceAccount.annotations object {} Annotations added to the generated sandbox ServiceAccount.
sandboxServiceAccount.create bool true Create the ServiceAccount assigned to sandbox pods.
sandboxServiceAccount.name string "openshell-sandbox" Sandbox ServiceAccount name.

Autogenerated from chart metadata using helm-docs v1.14.2