You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 84bb437
Browse filesBrowse the repository at this point in the historyBrowse files
1. Connect to the persistence store (`Store::connect`), which auto-detects SQLite vs Postgres from the URL prefix and runs migrations.
97
-
2. Create `SandboxClient` (initializes a `kube::Client` from in-cluster or kubeconfig).
99
+
2. Create `ComputeRuntime` with the in-process Kubernetes compute backend (`KubernetesComputeDriver`).
98
100
3. Build `ServerState` (shared via `Arc<ServerState>` across all handlers).
99
101
4.**Spawn background tasks**:
100
-
-`spawn_sandbox_watcher` -- watches Kubernetes Sandbox CRDs and syncs state to the store.
101
-
-`spawn_kube_event_tailer` -- watches Kubernetes Events in the sandbox namespace and publishes them to the `PlatformEventBus`.
102
+
-`ComputeRuntime::spawn_watchers` -- consumes the compute-driver watch stream, updates persisted sandbox records, and republishes platform events.
102
103
5. Create `MultiplexService`.
103
104
6. Bind `TcpListener` on `config.bind_address`.
104
105
7. Optionally create `TlsAcceptor` from cert/key files.
@@ -137,7 +138,7 @@ All handlers share an `Arc<ServerState>` (`crates/openshell-server/src/lib.rs`):
137
138
pubstructServerState {
138
139
pubconfig:Config,
139
140
pubstore:Arc<Store>,
140
-
pubsandbox_client:SandboxClient,
141
+
pubcompute:ComputeRuntime,
141
142
pubsandbox_index:SandboxIndex,
142
143
pubsandbox_watch_bus:SandboxWatchBus,
143
144
pubtracing_log_bus:TracingLogBus,
@@ -148,10 +149,10 @@ pub struct ServerState {
148
149
```
149
150
150
151
-**`store`** -- persistence backend (SQLite or Postgres) for all object types.
151
-
-**`sandbox_client`** -- Kubernetes client scoped to the sandbox namespace; creates/deletes CRDs and resolves pod IPs.
152
-
-**`sandbox_index`** -- in-memory bidirectional index mapping sandbox names and agent pod names to sandbox IDs. Used by the event tailer to correlate Kubernetes events.
152
+
-**`compute`** -- gateway-owned compute orchestration. Persists sandbox lifecycle transitions, validates create requests through the compute backend, resolves exec/SSH endpoints, and consumes the backend watch stream.
153
+
-**`sandbox_index`** -- in-memory bidirectional index mapping sandbox names and agent pod names to sandbox IDs. Updated from compute-driver sandbox snapshots.
153
154
-**`sandbox_watch_bus`** -- `broadcast`-based notification bus keyed by sandbox ID. Producers call `notify(&id)` when the persisted sandbox record changes; consumers in `WatchSandbox` streams receive `()` signals and re-read the record.
154
-
-**`tracing_log_bus`** -- captures `tracing` events that include a `sandbox_id` field and republishes them as `SandboxLogLine` messages. Maintains a per-sandbox tail buffer (default 200 entries). Also contains a nested `PlatformEventBus` for Kubernetes events.
155
+
-**`tracing_log_bus`** -- captures `tracing` events that include a `sandbox_id` field and republishes them as `SandboxLogLine` messages. Maintains a per-sandbox tail buffer (default 200 entries). Also contains a nested `PlatformEventBus` for compute-driver platform events.
155
156
-**`settings_mutex`** -- serializes settings mutations (global and sandbox) to prevent read-modify-write races. Held for the duration of any setting set/delete or global policy set/delete operation. See [Gateway Settings Channel](gateway-settings.md#global-policy-lifecycle).
156
157
157
158
## Protocol Multiplexing
@@ -499,15 +500,15 @@ The Helm chart template is at `deploy/helm/openshell/templates/statefulset.yaml`
`KubernetesComputeDriver` (`crates/openshell-driver-kubernetes/src/driver.rs`) manages `agents.x-k8s.io/v1alpha1/Sandbox` CRDs behind the gateway's compute interface.
503
504
504
-
-**Create**: Translates a `Sandbox`proto into a Kubernetes `DynamicObject` with labels (`openshell.ai/sandbox-id`, `openshell.ai/managed-by: openshell`) and a spec that includes the pod template, environment variables, and gateway-required env vars (`OPENSHELL_SANDBOX_ID`, `OPENSHELL_ENDPOINT`, `OPENSHELL_SSH_LISTEN_ADDR`, etc.). When callers do not provide custom `volumeClaimTemplates`, the server injects a default `workspace` PVC and mounts it at `/sandbox` so the default sandbox home/workdir survives pod rescheduling.
505
+
-**Create**: Translates a shared `openshell.sandbox.v1.Sandbox`message into a Kubernetes `DynamicObject` with labels (`openshell.ai/sandbox-id`, `openshell.ai/managed-by: openshell`) and a spec that includes the pod template, environment variables, and gateway-required env vars (`OPENSHELL_SANDBOX_ID`, `OPENSHELL_ENDPOINT`, `OPENSHELL_SSH_LISTEN_ADDR`, etc.). When callers do not provide custom `volumeClaimTemplates`, the driver injects a default `workspace` PVC and mounts it at `/sandbox` so the default sandbox home/workdir survives pod rescheduling.
505
506
-**Delete**: Calls the Kubernetes API to delete the CRD by name. Returns `false` if already gone (404).
506
507
-**Pod IP resolution**: `agent_pod_ip()` fetches the agent pod and reads `status.podIP`.
507
508
508
509
### Sandbox Watcher
509
510
510
-
`spawn_sandbox_watcher()` (`crates/openshell-server/src/sandbox/mod.rs`) runs a Kubernetes watcher on `Sandbox` CRDs and processes three event types:
511
+
The Kubernetes driver emits `WatchSandboxes` events through `proto/compute_driver.proto`. `ComputeRuntime` consumes that stream and applies the resulting snapshots to the store.
511
512
512
513
-**Applied**: Extracts the sandbox ID from labels (or falls back to name prefix stripping), reads the CRD status, derives the phase, and upserts the sandbox record in the store. Notifies the watch bus.
513
514
-**Deleted**: Removes the sandbox record from the store and the index. Notifies the watch bus.
@@ -530,7 +531,7 @@ All other `Ready=False` reasons are treated as terminal failures (`Error` phase)
530
531
531
532
### Kubernetes Event Tailer
532
533
533
-
`spawn_kube_event_tailer()` (`crates/openshell-server/src/sandbox_watch.rs`) watches all Kubernetes `Event` objects in the sandbox namespace and correlates them to sandbox IDs using `SandboxIndex`:
534
+
The Kubernetes driver also watches namespace-scoped Kubernetes `Event` objects and correlates them to sandbox IDs before emitting them as compute-driver platform events:
534
535
535
536
- Events involving `kind: Sandbox` are correlated by sandbox name.
536
537
- Events involving `kind: Pod` are correlated by agent pod name.
0 commit comments