Repository navigation
fix(docker): reach a WSL 2 gateway through Docker Desktop's host alias - #3924
fede-kamel wants to merge 2 commits into
Conversation
The Docker driver defaulted the supervisor's gateway endpoint to 127.0.0.1. When the gateway runs inside a WSL 2 distribution and the daemon is Docker Desktop, the host-networked supervisor runs in Docker Desktop's VM, whose loopback is not the distribution's, so every sandbox failed with ControlSupervisorStartFailed. When grpc_endpoint is unset, detect that combination from the gateway host's kernel release and the daemon's reported operating system, and default to host.docker.internal, which Docker Desktop routes to the Windows host that WSL forwards the gateway's loopback listener from. The generated server certificate already includes that name. Docker Engine inside WSL and Docker Desktop outside WSL keep the loopback default, and an explicit grpc_endpoint still wins. Closes NVIDIA#3880 Signed-off-by: fede-kamel <fkamelhar@gmail.com>
Docker Desktop 4.71 on WSL 2 reports OperatingSystem as "Docker Desktop (containerized)", so the exact match missed it and the WSL 2 endpoint default never applied. Match the "Docker Desktop" prefix. Refs NVIDIA#3880 Signed-off-by: fede-kamel <fkamelhar@gmail.com>
|
Probed live on Windows 11 + WSL 2 (kernel 6.18.40.1-microsoft-standard-WSL2) with Docker Desktop 4.71 (Docker 29.8.1), gateway config with no
The gateway logged Probing also caught a bug in the first revision: this Docker Desktop reports So with this change a default WSL 2 + Docker Desktop install works whether or not host networking is enabled; with host networking off, 0.1.2 reproduces #3880 exactly. |
|
The changes look good |
|
Thanks for taking a look, @LukeFrandsen! If you're able to, could you comment |
Summary
On WSL 2 with Docker Desktop, every sandbox failed with
ControlSupervisorStartFailedbecause the Docker driver defaulted the supervisor's gateway endpoint to127.0.0.1, and Docker Desktop's host network is its own VM, not the WSL distribution. Whengrpc_endpointis unset, the driver now detects this combination and defaults tohost.docker.internal, so a default install works without manual config.Related Issue
Closes #3880
Changes
openshell-driver-docker: newDockerSupervisorNetworkselection (mirrors the Podman driver's endpoint-environment pattern). It pickshost.docker.internalonly when the gateway host's kernel release is WSL (/proc/sys/kernel/osrelease) and the daemon'sOperatingSystemstarts withDocker Desktop(4.71 reportsDocker Desktop (containerized)). Docker Engine installed inside WSL and Docker Desktop outside WSL (macOS, Windows-native) keep the loopback default; an explicitgrpc_endpointstill wins. The chosen endpoint is logged.host.docker.internalas a SAN, so HTTPS works without changes.runtimes.mdx, andconfiguration.mdxdescribe the new default.Known limitation: as with any named
grpc_endpointtoday (including the manual workaround from the issue), the driver doesn't pin an address forhost.openshell.internal, so policy DNS refuses that alias on this platform. Sandboxes start and reach the gateway; reaching host services throughhost.openshell.internalon WSL 2 + Docker Desktop needs a follow-up that resolves Docker Desktop's host-gateway address.Testing
mise run pre-commitpassescargo test -p openshell-driver-docker --lib: 135 passed.failed to connect to OpenShell serverand this PR's build reaches Ready; with host networking on, both work. Details in the PR comments.Checklist