Skip to content

fix(docker): reach a WSL 2 gateway through Docker Desktop's host alias - #3924

Open
fede-kamel wants to merge 2 commits into
NVIDIA:mainfrom
fede-kamel:fix/3880-wsl-docker-desktop-endpoint
Open

fede-kamel wants to merge 2 commits into
NVIDIA:mainfrom
fede-kamel:fix/3880-wsl-docker-desktop-endpoint

Conversation

@fede-kamel

@fede-kamel fede-kamel commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

On WSL 2 with Docker Desktop, every sandbox failed with ControlSupervisorStartFailed because the Docker driver defaulted the supervisor's gateway endpoint to 127.0.0.1, and Docker Desktop's host network is its own VM, not the WSL distribution. When grpc_endpoint is unset, the driver now detects this combination and defaults to host.docker.internal, so a default install works without manual config.

Related Issue

Closes #3880

Changes

  • openshell-driver-docker: new DockerSupervisorNetwork selection (mirrors the Podman driver's endpoint-environment pattern). It picks host.docker.internal only when the gateway host's kernel release is WSL (/proc/sys/kernel/osrelease) and the daemon's OperatingSystem starts with Docker Desktop (4.71 reports Docker Desktop (containerized)). Docker Engine installed inside WSL and Docker Desktop outside WSL (macOS, Windows-native) keep the loopback default; an explicit grpc_endpoint still wins. The chosen endpoint is logged.
  • The generated gateway certificate already includes host.docker.internal as a SAN, so HTTPS works without changes.
  • Docs: driver README, runtimes.mdx, and configuration.mdx describe the new default.

Known limitation: as with any named grpc_endpoint today (including the manual workaround from the issue), the driver doesn't pin an address for host.openshell.internal, so policy DNS refuses that alias on this platform. Sandboxes start and reach the gateway; reaching host services through host.openshell.internal on WSL 2 + Docker Desktop needs a follow-up that resolves Docker Desktop's host-gateway address.

Testing

  • mise run pre-commit passes
  • Unit tests added/updated: selection for WSL + Docker Desktop, Docker Desktop outside WSL, Docker Engine inside WSL, the endpoint format, WSL kernel detection, and that the named endpoint adds no pinned host alias. cargo test -p openshell-driver-docker --lib: 135 passed.
  • E2E tests added/updated (if applicable)
  • Verified live on Windows 11 + WSL 2 with Docker Desktop 4.71: with host networking off (the default), released 0.1.2 fails with failed to connect to OpenShell server and this PR's build reaches Ready; with host networking on, both work. Details in the PR comments.

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

The Docker driver defaulted the supervisor's gateway endpoint to
127.0.0.1. When the gateway runs inside a WSL 2 distribution and the
daemon is Docker Desktop, the host-networked supervisor runs in Docker
Desktop's VM, whose loopback is not the distribution's, so every
sandbox failed with ControlSupervisorStartFailed.

When grpc_endpoint is unset, detect that combination from the gateway
host's kernel release and the daemon's reported operating system, and
default to host.docker.internal, which Docker Desktop routes to the
Windows host that WSL forwards the gateway's loopback listener from.
The generated server certificate already includes that name. Docker
Engine inside WSL and Docker Desktop outside WSL keep the loopback
default, and an explicit grpc_endpoint still wins.

Closes NVIDIA#3880

Signed-off-by: fede-kamel <fkamelhar@gmail.com>
@copy-pr-bot

copy-pr-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

Docker Desktop 4.71 on WSL 2 reports OperatingSystem as
"Docker Desktop (containerized)", so the exact match missed it and the
WSL 2 endpoint default never applied. Match the "Docker Desktop" prefix.

Refs NVIDIA#3880

Signed-off-by: fede-kamel <fkamelhar@gmail.com>
@fede-kamel

Copy link
Copy Markdown
Contributor Author

Probed live on Windows 11 + WSL 2 (kernel 6.18.40.1-microsoft-standard-WSL2) with Docker Desktop 4.71 (Docker 29.8.1), gateway config with no grpc_endpoint, openshell sandbox create -- sh -c 'echo SANDBOX_READY':

Docker Desktop host networking Released 0.1.2 This PR
Off (default) Fails after 14 s: Startup configuration fetch failed after 5 attempts: failed to connect to OpenShell server Ready in ~1 s
On Ready Ready

The gateway logged Auto-detected Docker supervisor gRPC endpoint grpc_endpoint=https://host.docker.internal:18670 network=WslDockerDesktop.

Probing also caught a bug in the first revision: this Docker Desktop reports OperatingSystem as Docker Desktop (containerized), not exactly Docker Desktop, so the exact match missed it. 02bb080 matches the Docker Desktop prefix and adds that real value as a test fixture.

So with this change a default WSL 2 + Docker Desktop install works whether or not host networking is enabled; with host networking off, 0.1.2 reproduces #3880 exactly.

@LukeFrandsen

Copy link
Copy Markdown

The changes look good

@fede-kamel

Copy link
Copy Markdown
Contributor Author

Thanks for taking a look, @LukeFrandsen! If you're able to, could you comment /ok to test so Branch Checks and Helm Lint can run? If that needs a maintainer, no worries. I've also asked in #3888.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(docker): sandboxes never become Ready on WSL 2 + Docker Desktop (supervisor dials 127.0.0.1)

2 participants