fix(kernel): allow browser CDP endpoints - #335
Merged
Merged
Conversation
Signed-off-by: Rafael <raf@kernel.sh>
mdelapenya
approved these changes
Sep 28, 2026
Member
|
Merged, thanks! BTW @rgarcia could you add yourself to CODEOWNERS for kernel? 🙏 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
onkernel.comCDP proxy endpointskernel.shCDP endpointsapi.github.comSpec choices worth flagging for review
**.onkernel.comis the v2 multi-label wildcard and covers bothapi.onkernel.comand regional hosts such asproxy.<region>.onkernel.com.*.kernel.shcovers the direct CDP hosts returned by some Kernel browser sessions.api.onkernel.com; neither CDP destination receives the Kernel API key.KERNEL_NO_UPDATE_CHECK=1suppresses the optional update request instead of broadening the network policy to allowapi.github.com.Test plan
sbx kit validate ./kernel/./scripts/test-kit.sh kernel./scripts/test-kit-e2e.sh kernel— the fork's scopedsbxdaemon is not authenticated to Docker Hub; per the repository docs, fork PR CI also skips e2e because it cannot access the required secretssbx run --kit ./kernel/ claude— blocked by the same Docker Hub login prerequisiteOrigin
Ported from
kernel/docker-sbx-kit#2.