You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Previously, Helm installations could not enable the gateway OCSF JSONL
destination through chart values because generated `gateway.toml` omitted the
`openshell.gateway.ocsf_log` table.
Now, setting `server.ocsfLog.enabled` renders the path, optional schema
version, rotation, retention, and queue limits into gateway configuration.
Output is disabled by default. The default path, `/tmp/gateway-ocsf.jsonl`,
is writable in the gateway container with either the StatefulSet or
Deployment workload, so enabling output does not require persistent storage.
Invalid schema versions, rotation values, non-positive limits, or an empty
path while enabled fail chart rendering.
Additionally, `server.extraVolumes` and `server.extraVolumeMounts` add
operator-supplied volumes to the gateway pod, so operators who want records
to survive restarts can place the OCSF path on persistent storage without
replacing chart-generated configuration.
The gateway pod's default termination grace period rises from 5 to 30
seconds. Gateway shutdown can spend up to 10 seconds on supervisor session
cleanup before allowing 5 seconds to drain queued OCSF records, so the
5-second default risked a SIGKILL before the final records were written.
The grace period is only an upper bound: the gateway exits as soon as its
shutdown completes.
Refs #2762
Signed-off-by: Kris Hicks <khicks@nvidia.com>
Copy file name to clipboardExpand all lines: deploy/helm/openshell/README.md
+10-1Lines changed: 10 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -355,7 +355,7 @@ discovery endpoint or its TLS CA.
355
355
| pkiInitJob.timeoutSeconds | int |`120`| Maximum time in seconds for the certgen hook to poll for cert-manager certificates. When using cert-manager with BackendTLSPolicy, the hook polls for this many seconds waiting for the certificate to be issued, then creates the backend CA ConfigMap. The Job deadline is set to (timeoutSeconds + 30) to allow time for ConfigMap creation and cleanup. Increase this if cert-manager takes longer than 120 seconds to issue certificates. |
356
356
| podAnnotations | object |`{}`| Extra annotations to add to the gateway pod. |
357
357
| podLabels | object |`{}`| Extra labels to add to the gateway pod. |
358
-
| podLifecycle.terminationGracePeriodSeconds | int |`5`|Grace period, in seconds, before Kubernetes terminates the gateway pod. |
358
+
| podLifecycle.terminationGracePeriodSeconds | int |`30`|Maximum time, in seconds, Kubernetes waits for the gateway to exit before killing it. The gateway exits as soon as shutdown completes; the limit covers supervisor session cleanup and draining queued OCSF records. |
359
359
| podSecurityContext.fsGroup | int |`1000`| fsGroup assigned to the gateway pod. |
360
360
| probes.liveness.failureThreshold | int |`3`| Liveness probe failure threshold before the container is restarted. |
361
361
| probes.liveness.initialDelaySeconds | int |`2`| Liveness probe initial delay, in seconds. |
@@ -420,12 +420,21 @@ discovery endpoint or its TLS CA.
420
420
| server.enableUserNamespaces | bool |`false`| Enable Kubernetes user namespace isolation (hostUsers: false) for sandbox pods. Requires Kubernetes 1.33+ with user namespace support available (beta through 1.35, GA in 1.36+), plus a supporting container runtime and Linux 5.12+. When enabled, container UID 0 maps to an unprivileged host UID and capabilities become namespaced. |
421
421
| server.enableWebsocketTunnel | bool |`false`| Enable the WebSocket tunnel used by CLI/SDK clients behind an authenticated edge proxy. Leave disabled for direct gateway installs. |
422
422
| server.externalDbSecret | string |`""`| Name of a pre-existing Opaque Secret containing a PostgreSQL connection URI (key: uri). When set, the gateway reads OPENSHELL_DB_URL from this Secret instead of using dbUrl. The Secret must contain a `uri` key, e.g. postgresql://user:pass@host:5432/dbname. |
423
+
| server.extraVolumeMounts | list |`[]`| Additional volume mounts for the gateway container. |
424
+
| server.extraVolumes | list |`[]`| Additional volumes for the gateway pod. |
423
425
| server.grpcEndpoint | string |`""`| gRPC endpoint sandboxes call back into the gateway. Leave empty to derive it from the chart fullname, release namespace, service port, and disableTls flag, for example https://openshell.openshell.svc.cluster.local:8080. Override only when sandboxes must reach the gateway via a different hostname (e.g. an external ingress or a host alias). |
424
426
| server.grpcRateLimit.requests | int |`0`| Maximum gRPC requests allowed per window. Must be positive (alongside windowSeconds) to enable rate limiting; 0 (default) disables it. |
425
427
| server.grpcRateLimit.windowSeconds | int |`0`| gRPC rate-limit window length in seconds. Must be positive (alongside requests) to enable rate limiting; 0 (default) disables it. |
426
428
| server.hostGatewayIP | string |`""`| Host gateway IP for sandbox pod hostAliases. When set, sandbox pods get hostAliases entries mapping host.docker.internal and host.openshell.internal to this IP, allowing them to reach services running on the Docker host. Auto-detected by the cluster entrypoint script. |
| server.name | string |`""`| Operator-facing gateway name. Defaults to the chart fullname so all replicas in one installation share an identity. Set explicitly when one telemetry collector receives spans from multiple namespaces or clusters. |
| server.ocsfLog.maxFiles | int |`7`| Rotated files retained when rotation is daily. |
433
+
| server.ocsfLog.path | string |`"/tmp/gateway-ocsf.jsonl"`| OCSF JSONL path. The default is writable in the gateway container but does not persist across restarts. To keep records, mount a volume with server.extraVolumes and server.extraVolumeMounts and set a path on it. When replicas share the volume, set subPathExpr: $(OPENSHELL_POD_NAME) on the mount so each replica writes its own file. |
434
+
| server.ocsfLog.queueCapacity | int |`10000`| Maximum records waiting for the file writer. |
435
+
| server.ocsfLog.queueMaxBytes | int |`16777216`| Maximum encoded bytes waiting for the file writer. |
436
+
| server.ocsfLog.rotation | string |`"daily"`| Rotate the active file daily in UTC, or never. |
| server.oidc.adminRole | string |`""`| Role name for admin access. Leave empty (with userRole also empty) for authentication-only mode. Both must be set or both empty. |
430
439
| server.oidc.audience | string |`"openshell-cli"`| Expected audience claim for the API resource server. This should match the server's --oidc-audience, NOT the CLI client ID. |
431
440
| server.oidc.caConfigMapName | string |`""`| Name of a ConfigMap containing a CA certificate bundle (key: ca.crt) for verifying the OIDC issuer's TLS certificate. Required when the issuer uses a non-public CA (e.g. OpenShift ingress, private PKI). |
Copy file name to clipboardExpand all lines: docs/how-it-works/gateways/configuration.mdx
+2Lines changed: 2 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -303,6 +303,8 @@ queue_max_bytes = 16777216
303
303
304
304
Unknown fields are rejected. This is one file destination, not an exporter registry. The existing `ocsf_json_enabled` sandbox setting remains independent.
305
305
306
+
For Helm installations, set `server.ocsfLog.enabled` to render this table and optionally set `server.ocsfLog.schemaVersion`. The default `server.ocsfLog.path`, `/tmp/gateway-ocsf.jsonl`, is writable in the gateway container with either the StatefulSet or Deployment workload but does not persist across pod restarts. To keep records, mount a volume with `server.extraVolumes` and `server.extraVolumeMounts` and set the path on it. When replicas share a volume, add `subPathExpr: $(OPENSHELL_POD_NAME)` to the mount so each replica writes its own file.
307
+
306
308
Give each gateway replica its own writable file and an external shipper read access to the containing directory. New files use owner-only permissions on Unix; arrange shipper access deliberately. Rotation renames the active file to a date- and UUID-suffixed sibling. The shipper must follow rotated files and checkpoint its progress. Do not use multiple writers or external copy-truncate rotation on this path.
307
309
308
310
The gateway queues OCSF independently of `RUST_LOG`, excludes ordinary diagnostics, and preserves native event IDs. It writes up to 100 records per batch with a 500 ms batching interval. One additional bounded batch can be in flight. File errors do not stop sandbox execution: failed writes are not replayed, and subsequent records are discarded during reopen backoff. A restarted writer removes an incomplete trailing line before appending.
0 commit comments