Skip to content

fix(kernel): allow browser CDP endpoints - #335

Merged
mdelapenya merged 1 commit into
docker:mainfrom
kernel:hypeship/fix-kernel-network
Sep 28, 2026
Merged

mdelapenya merged 1 commit into
docker:mainfrom
kernel:hypeship/fix-kernel-network

Conversation

@rgarcia

@rgarcia rgarcia commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

Summary

  • allow multi-label onkernel.com CDP proxy endpoints
  • allow direct kernel.sh CDP endpoints
  • disable the Kernel CLI update check so it does not make a blocked request to api.github.com

Spec choices worth flagging for review

  • **.onkernel.com is the v2 multi-label wildcard and covers both api.onkernel.com and regional hosts such as proxy.<region>.onkernel.com.
  • *.kernel.sh covers the direct CDP hosts returned by some Kernel browser sessions.
  • Credential injection remains restricted to api.onkernel.com; neither CDP destination receives the Kernel API key.
  • KERNEL_NO_UPDATE_CHECK=1 suppresses the optional update request instead of broadening the network policy to allow api.github.com.

Test plan

  • sbx kit validate ./kernel/
  • ./scripts/test-kit.sh kernel
  • ./scripts/test-kit-e2e.sh kernel — the fork's scoped sbx daemon is not authenticated to Docker Hub; per the repository docs, fork PR CI also skips e2e because it cannot access the required secrets
  • sbx run --kit ./kernel/ claude — blocked by the same Docker Hub login prerequisite

Origin

Ported from kernel/docker-sbx-kit#2.

Signed-off-by: Rafael <raf@kernel.sh>
@rgarcia
rgarcia requested a review from a team as a code owner September 26, 2026 16:00
@mdelapenya
mdelapenya merged commit f345be6 into docker:main Sep 28, 2026
17 checks passed
@mdelapenya

Copy link
Copy Markdown
Member

Merged, thanks!

BTW @rgarcia could you add yourself to CODEOWNERS for kernel? 🙏

@rgarcia rgarcia mentioned this pull request Sep 28, 2026
3 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants