Files
Drew Newberry 84960e70a3 fix(kubernetes): scope resource admission RBAC (#3571)
* fix(kubernetes): scope resource admission RBAC

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(helm): gate PVC admission reads

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

---------

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 00:02:10 +00:00
..

OpenShell Workspace Helm Chart

Experimental - the shared-gateway, multi-namespace deployment path is under active design.

This chart installs the namespace-scoped ServiceAccount, RBAC, and NetworkPolicy needed for OpenShell Kubernetes sandboxes. Install it once in every platform-managed workspace namespace. It does not create a namespace or deploy an OpenShell gateway.

Install the gateway chart with workspaceResources.enabled=false, then install this chart with the gateway ServiceAccount identity. Configure the gateway's Kubernetes driver in operator workspace mode when it serves more than one pre-provisioned workspace namespace:

helm install openshell-workspace ./deploy/helm/openshell-workspace \
  --namespace app-a \
  --set gateway.serviceAccount.name=openshell \
  --set gateway.serviceAccount.namespace=openshell

Keep sandboxServiceAccount.name aligned with the gateway chart's sandboxServiceAccount.name. The defaults for both charts are openshell-sandbox. If the gateway enables server.drivers.kubernetes.allowDriverConfig, also set gateway.allowDriverConfig=true in every workspace release so caller-selected PVCs can be admitted.

Values

Key Type Default Description
fullnameOverride string "" Override the full generated resource name.
gateway.allowDriverConfig bool false Grant PVC metadata reads required when the gateway enables caller driver config. Keep this aligned with server.drivers.kubernetes.allowDriverConfig in the gateway chart.
gateway.networkPolicy.podSelector object {"app.kubernetes.io/instance":"openshell","app.kubernetes.io/name":"openshell"} Labels selecting gateway pods allowed to reach sandbox SSH.
gateway.serviceAccount.name string "openshell" Name of the shared gateway ServiceAccount.
gateway.serviceAccount.namespace string "openshell" Namespace containing the shared gateway ServiceAccount.
nameOverride string "" Override the chart name used in generated resource names.
networkPolicy.enabled bool true Restrict sandbox SSH ingress to the shared gateway pods.
sandboxServiceAccount.annotations object {} Annotations added to the generated sandbox ServiceAccount.
sandboxServiceAccount.create bool true Create the ServiceAccount assigned to sandbox pods.
sandboxServiceAccount.name string "openshell-sandbox" Sandbox ServiceAccount name.

Autogenerated from chart metadata using helm-docs v1.14.2