You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
feat(policy): adopt image policy only during initial sandbox setup #4381
As an operator of gateway-connected sandboxes, I want images to provide basic policy defaults while managing provider credential bindings through the gateway.
Problem Statement
Supervisors currently upload image-discovered policy and later sync policy after adding runtime filesystem paths. This mixes initial image defaults with ongoing management of gateway-owned policy.
Impact / Why This Matters
Basic image policies are useful portable defaults. Credential bindings reference provider instances configured in a particular gateway and belong in its management workflow. Policy ownership should remain clear after initialization.
Proposed Design
Allow a supervisor to submit an image policy only when the sandbox has no initialized gateway policy.
Reject the complete image-policy upload if it contains credential_binding.
Once policy is initialized, reject further supervisor policy replacements, including after restart.
Preserve required filesystem enrichment without uploading the complete policy.
Use a restrictive default when no policy is supplied by the gateway or image.
Require workspace admin approval for proposals that introduce or change credential bindings.
Existing stored policies remain unchanged; upgrading requires no policy reapproval.
Suggested UX
An image policy containing a credential binding leaves the sandbox in Provisioning, with ConfigurationReady=False and this diagnostic:
Image policy contains credential_binding. A workspace admin must submit the reviewed policy through the gateway.
The workload does not start. The admin repairs it with:
openshell policy set my-sandbox --policy reviewed-policy.yaml --wait
Startup resumes after repair. The existing five-minute repair window applies; expiration moves the sandbox to Error. After repairing an expired sandbox, the admin runs:
openshell sandbox start my-sandbox
Acceptance Criteria
Basic image policies initialize successfully.
Image policies containing credential bindings are rejected with the actionable diagnostic above.
Concurrent uploads, retries, and restarts cannot replace an initialized policy.
Workspace admins can apply credential bindings using existing policy commands.
Filesystem enrichment continues to work without full-policy synchronization.
Automatic proposals cannot introduce or change bindings without admin approval.
Existing policies continue working after upgrade.
Alternatives Considered
Rejecting all image policies would remove useful portable defaults. Allowing unrestricted initial policies would retain gateway-specific provider configuration inside images.
User Story
As an operator of gateway-connected sandboxes, I want images to provide basic policy defaults while managing provider credential bindings through the gateway.
Problem Statement
Supervisors currently upload image-discovered policy and later sync policy after adding runtime filesystem paths. This mixes initial image defaults with ongoing management of gateway-owned policy.
Impact / Why This Matters
Basic image policies are useful portable defaults. Credential bindings reference provider instances configured in a particular gateway and belong in its management workflow. Policy ownership should remain clear after initialization.
Proposed Design
credential_binding.Existing stored policies remain unchanged; upgrading requires no policy reapproval.
Suggested UX
An image policy containing a credential binding leaves the sandbox in
Provisioning, withConfigurationReady=Falseand this diagnostic:The workload does not start. The admin repairs it with:
openshell policy set my-sandbox --policy reviewed-policy.yaml --waitStartup resumes after repair. The existing five-minute repair window applies; expiration moves the sandbox to
Error. After repairing an expired sandbox, the admin runs:Acceptance Criteria
Alternatives Considered
Rejecting all image policies would remove useful portable defaults. Allowing unrestricted initial policies would retain gateway-specific provider configuration inside images.