Skip to content

feat(sandbox): add guarded image retention, cleanup, probes and alerts - #162

Open
akemmanuel wants to merge 1 commit into
fix/sandbox-image-preflightfrom
fix/sandbox-shell-lifecycle
Open

akemmanuel wants to merge 1 commit into
fix/sandbox-image-preflightfrom
fix/sandbox-shell-lifecycle

Conversation

@akemmanuel

Copy link
Copy Markdown
Owner

Summary

Refs #152. Stacked on #157 (fix/sandbox-image-preflight). Add opt-in shell-image lifecycle operator tooling and a documented recurring check/alert example; no deployment or service installation.

  • Inspect the configured image, runsc availability, keeper ownership, configuration consistency, and image provenance; do not equate image presence with execution readiness.
  • Retain images with an unstarted labeled keeper created from the inspected immutable ID with --pull=never.
  • Preview by default; serialize explicit apply operations using a real nonblocking kernel lock owned by the mutation process. Refuse foreign/running/mismatched keepers.
  • Resolve protected references and candidate labels/IDs before explicit disposable-image removal. No global pruning, forced removal, service restart, or native-shell fallback.
  • Exclusively prepare disposable probe fixtures; refuse customer/foreign/symlinked layouts. Support bounded authenticated direct-broker grant probes and optional fixed-summary webhook alerts.
  • Stream-check archive checksums and inspect loaded-image digests as separate facts; never claim to attest the intervening operator load. Document controlled upgrade/rollback steps.

Parent review and verification

Parent reproduced and corrected lock borrowing, unsafe existing-directory adoption/chmod, private-reference disclosure, and mutable-tag keeper creation. Corrections also cover total HTTP deadlines, stream faults, symlink refusal, and exact process-group/test-fixture cleanup.

  • Fresh lifecycle/CLI/doctor/broker/Host/Harness shell suites: 107 passed across 8 files.
  • CLI tests use real flock and fake Docker, with loopback fixture HTTP services; never mutate a daemon.
  • pnpm run check and git diff --check: passed.

Acceptance boundary

No live Docker/gVisor execution, real infrastructure webhook, registry/archive restoration, scheduling, production configuration, or deployment was performed. Existing rootless isolation preflight remains required; direct broker checks do not establish restricted Account-to-Harness acceptance. Keep #152 open until the operator completes the documented live verification and installs the chosen monitoring/recovery workflow.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant