Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 6 additions & 2 deletions crates/openshell-driver-kubernetes/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,8 +17,12 @@ workspace namespace modes via `workspace_mode`:
- **Shared** (default): All sandboxes render into a single static namespace.
Resource names use `{workspace}--{name}` for collision avoidance.
- **Managed**: The driver auto-creates/deletes a K8s namespace per workspace
(`openshell-{gateway_id}-{workspace_name}`), creates a ServiceAccount in each,
and copies OpenShift SCC annotations from the gateway namespace when present.
(`openshell-{gateway_id}-{workspace_name}`) and creates a ServiceAccount in
each. On OpenShift, it leaves SCC annotations to the namespace allocator and
waits for the namespace's own MCS, UID-range, and supplemental-group
annotations before provisioning sandbox resources. An existing namespace with
a UID range but no MCS must be recreated so OpenShift can allocate a complete
set of SCC annotations.
- **Operator**: Workspace names map 1:1 to pre-provisioned namespaces discovered
through exactly one source: either a label selector
(`operator_namespace_label`) or a drop-in allowlist file
Expand Down
3 changes: 3 additions & 0 deletions crates/openshell-driver-kubernetes/src/config.rs
Original file line number Diff line number Diff line change
Expand Up @@ -312,6 +312,9 @@ pub(crate) const DEFAULT_SANDBOX_UID: u32 = 10001;
/// Format: `<start>/<size>` (e.g. `1000000000/10000`).
pub const ANNOTATION_SCC_UID_RANGE: &str = "openshift.io/sa.scc.uid-range";

/// The annotation key for the `OpenShift` MCS label allocated to a namespace.
pub const ANNOTATION_SCC_MCS: &str = "openshift.io/sa.scc.mcs";

/// The annotation key for the `OpenShift` `ServiceAccount` supplemental groups.
/// Format: `<start>/<size>` (e.g. `1000000000/10000`).
pub const ANNOTATION_SCC_SUPPLEMENTAL_GROUPS: &str = "openshift.io/sa.scc.supplemental-groups";
Expand Down
Loading
Loading