Skip to content

feat(helm): add sandbox UID and GID values - #3947

Merged
johntmyers merged 2 commits into
NVIDIA:mainfrom
ericcurtin:feat/2697-helm-sandbox-uid-gid
Oct 2, 2026
Merged

johntmyers merged 2 commits into
NVIDIA:mainfrom
ericcurtin:feat/2697-helm-sandbox-uid-gid

Conversation

@ericcurtin

Copy link
Copy Markdown
Contributor

Summary

Add server.sandboxUid and server.sandboxGid Helm values, rendered as sandbox_uid and sandbox_gid.

Related Issue

Closes #2697

Changes

  • Render both fields in the gateway config when set, validated as integers in 1..4294967294.
  • Add chart unit tests, docs rows, and regenerated chart README.

Testing

  • mise run pre-commit passes
  • Unit tests added/updated
  • E2E tests added/updated (if applicable)

mise run helm:test, helm:lint and helm:docs:check pass.

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

Closes NVIDIA#2697

Signed-off-by: Eric Curtin <eric.curtin@docker.com>
@copy-pr-bot

copy-pr-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@ericcurtin

Copy link
Copy Markdown
Contributor Author

If useful, please also try https://github.com/llmmanorg/llmman, which can launch agents in an OpenShell sandbox (--sandbox openshell).

@ericcurtin
ericcurtin requested a review from a team as a code owner September 30, 2026 09:13
@johntmyers johntmyers self-assigned this Oct 1, 2026

@johntmyers johntmyers left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

PR Review Status

This accepted Helm improvement is well scoped and includes the relevant Fern documentation, but the new scalar validator silently accepts a boolean as UID or GID 1.

Action required: Reject boolean values before numeric conversion and add a regression test for the shared UID/GID helper.

Blocking findings:

  • GATOR-6a07ea84-01: boolean identity values are coerced instead of rejected.

Carried findings:

  • None
Gator metadata
  • Validation: Implements accepted issue #2697 with a concentrated Helm chart change.
  • Docs: Fern configuration and runtime docs updated; navigation changes are not needed.
  • Checks: Review feedback must be resolved before required test dispatch.
  • E2E: test:e2e is required for this Helm/Kubernetes behavior after review feedback is resolved.
  • Head SHA: 6a07ea843be6b42ff15d4c6c1f0c22247dcbce7e
  • Base SHA: b8ffe5244cb244a1d74a4a03d69afe3da07e5f08
  • Merge base SHA: b8ffe5244cb244a1d74a4a03d69afe3da07e5f08
  • Patch ID: d732ea9a73a64cce9371b02cf7dc4121001deb1e
  • Gator payload: 9
  • Review mode: initial
  • Previous reviewed SHA: none
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Next state: gator:in-review

Comment thread deploy/helm/openshell/templates/_helpers.tpl
@johntmyers johntmyers added the gator:in-review Gator is reviewing or awaiting PR review feedback label Oct 1, 2026
Signed-off-by: Eric Curtin <eric.curtin@docker.com>
@johntmyers johntmyers added the test:e2e Requires end-to-end coverage label Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Label test:e2e applied, but pull-request/3947 does not exist yet. A maintainer needs to comment /ok to test ca73dcf6035208e395eebb902dc767f2d9c7df7d to mirror this PR. Once the mirror exists, re-apply the label or re-run Branch E2E Checks from the Actions tab.

@johntmyers johntmyers left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

PR Review Status

Thanks @ericcurtin. I checked your boolean-validation fix and the new UID and GID regression cases against the prior finding; GATOR-6a07ea84-01 is resolved, and the bounded follow-up review found no new blockers.

Blocking findings:

  • No blocking findings remain

Carried findings:

  • None
Gator metadata
  • Validation: Implements accepted issue #2697 with a concentrated Helm chart change.
  • Docs: Fern configuration and runtime docs are updated; navigation changes are not needed.
  • Checks: Required current-head test dispatch is in progress.
  • E2E: test:e2e is applied; Gator is waiting for the label-help workflow to dispatch the required current-head jobs.
  • Head SHA: ca73dcf6035208e395eebb902dc767f2d9c7df7d
  • Base SHA: b8ffe5244cb244a1d74a4a03d69afe3da07e5f08
  • Merge base SHA: b8ffe5244cb244a1d74a4a03d69afe3da07e5f08
  • Patch ID: 787925d5c36070887ca912affb4e4e62b7df00a8
  • Gator payload: 9
  • Review mode: follow_up
  • Previous reviewed SHA: 6a07ea843be6b42ff15d4c6c1f0c22247dcbce7e
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Next state: gator:in-review

@johntmyers

Copy link
Copy Markdown
Collaborator

/ok to test ca73dcf

@johntmyers johntmyers added gator:watch-pipeline Gator is monitoring PR CI/CD status gator:approval-needed Gator completed review; maintainer approval needed and removed gator:in-review Gator is reviewing or awaiting PR review feedback gator:watch-pipeline Gator is monitoring PR CI/CD status labels Oct 1, 2026
@johntmyers
johntmyers added this pull request to the merge queue Oct 2, 2026
@johntmyers johntmyers added gator:merge-ready and removed gator:approval-needed Gator completed review; maintainer approval needed labels Oct 2, 2026
Merged via the queue into NVIDIA:main with commit a48920a Oct 2, 2026
115 of 118 checks passed
@johntmyers

Copy link
Copy Markdown
Collaborator

gator-agent

Monitoring Complete

Monitoring is complete because this PR has merged.

Final status: the PR reached gator:merge-ready with maintainer approval and the required Branch Checks, Helm Lint, Trivy Changes, and E2E gates green.

I removed the active gator:* label because there is nothing left for gator to monitor on this PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

test:e2e Requires end-to-end coverage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(helm): expose sandbox_uid / sandbox_gid as first-class Helm values

2 participants