Repository navigation
Docker driver requires launch-scoped session JWT that local gateway does not mint (0.1.2) #3900
Description
Activity
- addedstate:triage-neededOpened without agent diagnostics and needs triageOpened without agent diagnostics and needs triage
on Sep 29, 2026 Resolved. The launch-scoped failure was caused by incomplete gateway configuration, not a defect in the sandbox driver. Closing with the full causal chain, since each link masked the next.
1. Missing
[openshell.gateway.gateway_jwt]openshell-serveronly constructs asandbox_session_jwt_authoritywhenconfig.gateway_jwtisSome. Otherwiselaunch_authenticationisNone, and the Docker driver rejects the launch via.filter(|spec| !spec.launch_authentication.is_empty()). mTLS transport auth was working throughout and was never the missing piece — the gateway simply had no signing material to mint a launch-scoped JWT from.Adding the block (Ed25519
signing_key_path/public_key_path/kid_path/gateway_id) producedgateway-minted sandbox JWT enabledand removed the original refusal.2.
bind_addresswas loopbackThe gateway listened on
127.0.0.1, which is unreachable from the supervisor container. This surfaced only after link 1, asStartup configuration fetch failed/failed to connect to OpenShell server. Settingbind_address = "0.0.0.0:17670"fixed it.3.
grpc_endpointMust be set, and because TLS materials are present it must use
https://. Note the coupling indocker_supervisor_host_address: it returnsSomeonly for an IPv4 literal or the literallocalhost; any other domain returnsNoneand no host alias is created. So an IP endpoint is what generates thehost.openshell.internal/host.docker.internalaliases — using the alias name directly would silently disable the mechanism that provides it.4. Server certificate SANs
The final blocker. The server certificate was
CN=localhostwithDNS:localhost, IP:127.0.0.1only. The TCP probe succeeded while the TLS handshake failed, because the supervisor validates the endpoint identity and172.21.216.231was absent from the SANs. Re-issuing withDNS:host.openshell.internal, DNS:host.docker.internal, DNS:localhost, IP:127.0.0.1, IP:<host>resolved it.A sandbox now boots and executes (
uid=1000, companion supervisor running).Observations worth considering
- The error text for link 1 names an identity a local user cannot supply. Every link above presented as the same "failed to connect"-class symptom, and links 2-4 were only reachable sequentially. A startup preflight that validates listener reachability and certificate SAN coverage against the configured supervisor endpoint would fail fast with an actionable message instead.
- Binding loopback while a peer container is expected to connect is a configuration state worth rejecting or warning on at startup.
Environment: v0.1.2, Docker driver, WSL2 bare-metal gateway (not a Compose service, so Compose service DNS does not apply). Happy to provide the full working
gateway.tomlshape if useful.Root cause: missing [openshell.gateway.gateway_jwt] config (plus loopback bind and certificate SAN coverage). Full chain in the comment above. Sandbox now boots and executes.
- removedstate:triage-neededOpened without agent diagnostics and needs triageOpened without agent diagnostics and needs triage
on Oct 1, 2026
Summary
Sandbox creation through the Docker compute driver fails on a local,
mTLS-authenticated OpenShell gateway. The driver aborts with:
Per #2965, the launch-scoped credential is a gateway-minted sandbox/session
JWT used to authenticate the protected channel between the workload and its
companion supervisor — not a user-supplied identity. It is therefore an
internal gateway-to-driver contract, and the local gateway is not minting or
exposing it in this deployment.
v0.1.2 was published 2026-09-28, which postdates #2965 (closed 2026-09-14), so
the supervisor architecture should be present in this release. This is
reported against 0.1.2.
Environment
docker, selected and connectedGateway configuration
Accepted only with the version-2 schema. Complete non-secret configuration;
TLS material is generated outside the repo and is not included.
allow_driver_configgoverns caller-suppliedtemplate.driver_configand wasaccepted. Enabling it did not change the failure.
Reproduction
Actual result
The error above, unchanged across every variation attempted. No supervisor
companion container is observable on the Docker host.
Expected result
Any one of these would resolve the report:
proceeds to launch the workload plus companion supervisor.
condition, rather than referring to an identity the user cannot supply.
Ruled out
Using compute driver driver=docker;Compute driver connected configured_driver=dockerallow_driver_config = trueaccepted; error unchangedAuthenticated (mTLS transport)--templatepath reproduces failureopenshell doctor checkall checks passed;docker run --rm alpinesucceedsQuestions for maintainers
launch-scoped session JWT for the Docker driver, and what would cause it to
be absent here?
non-expiring tokens. Is there a configuration or gateway state that still
selects the legacy contract, which the Docker driver then rejects?
error text actionable? Naming an identity no local user can supply is likely
to cost the same debugging time for others.
Related validation (not the subject of this report)
The consumer's own live-runtime integration found two defects upstream of this
blocker, both fixed:
process.user/process.groupare not supported policyfields in 0.1.2, and run IDs producing sandbox names over the 19-character
limit are rejected before staging. The client is not the blocker here.