Skip to content

feat(policy): add --dry-run flag to policy set command - #838

Closed
joeVenner wants to merge 1 commit into
NVIDIA:mainfrom
joeVenner:feat/policy-dry-run
Closed

joeVenner wants to merge 1 commit into
NVIDIA:mainfrom
joeVenner:feat/policy-dry-run

Conversation

@joeVenner

Copy link
Copy Markdown

Add validation-only mode for policy updates. When --dry-run is set, the gateway runs all validation checks (safety, static field immutability, global lock) and returns a diff of network rule changes without persisting the revision or notifying the sandbox.

  • Add dry_run field to UpdateConfigRequest proto
  • Add dry_run, added_network_rules, removed_network_rules to UpdateConfigResponse proto
  • Add PolicyDiff utility in openshell-core for comparing network rules between two SandboxPolicy protos
  • Refactor handle_update_config to skip DB writes and sandbox notification when dry_run=true
  • Add --dry-run flag to CLI policy set (sandbox and global)
  • Incompatible with --wait since dry-run does not apply the policy
  • Update architecture and user-facing docs

Summary

Related Issue

Changes

Testing

  • mise run pre-commit passes
  • Unit tests added/updated
  • E2E tests added/updated (if applicable)

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

Add validation-only mode for policy updates. When --dry-run is set,
the gateway runs all validation checks (safety, static field
immutability, global lock) and returns a diff of network rule
changes without persisting the revision or notifying the sandbox.

- Add dry_run field to UpdateConfigRequest proto
- Add dry_run, added_network_rules, removed_network_rules to
  UpdateConfigResponse proto
- Add PolicyDiff utility in openshell-core for comparing network
  rules between two SandboxPolicy protos
- Refactor handle_update_config to skip DB writes and sandbox
  notification when dry_run=true
- Add --dry-run flag to CLI policy set (sandbox and global)
- Incompatible with --wait since dry-run does not apply the policy
- Update architecture and user-facing docs

Signed-off-by: JoeVenner <ylafrimi@gmail.com>
@joeVenner
joeVenner requested a review from a team as a code owner April 14, 2026 23:58
@copy-pr-bot

copy-pr-bot Bot commented Apr 14, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@github-actions

Copy link
Copy Markdown

Thank you for your submission! We ask that you sign our Developer Certificate of Origin before we can accept your contribution. You can sign the DCO by adding a comment below using this text:


I have read the DCO document and I hereby sign the DCO.


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the DCO Assistant Lite bot.

@github-actions

Copy link
Copy Markdown

Thank you for your interest in contributing to OpenShell, @joeVenner.

This project uses a vouch system for first-time contributors. Before submitting a pull request, you need to be vouched by a maintainer.

To get vouched:

  1. Open a Vouch Request discussion.
  2. Describe what you want to change and why.
  3. Write in your own words — do not have an AI generate the request.
  4. A maintainer will comment /vouch if approved.
  5. Once vouched, open a new PR (preferred) or reopen this one after a few minutes.

See CONTRIBUTING.md for details.

@github-actions github-actions Bot closed this Apr 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant