Skip to content

feat(docker): select supervisor networking for ECI workloads - #4016

Draft
drew wants to merge 4 commits into
mainfrom
codex/4015-docker-supervisor-networking
Draft

drew wants to merge 4 commits into
mainfrom
codex/4015-docker-supervisor-networking

Conversation

@drew

@drew drew commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

The Docker supervisor always used host networking, which Docker Desktop Enhanced Container Isolation (ECI) prohibits. Add automatic supervisor networking: inspect the existing workload's runtime and select bridge for sysbox-runc, retaining host mode for ordinary workloads. Standard Desktop bridge setups derive a gateway callback endpoint without creating a diagnostic container.

Related Issue

Closes #4015.

Implementation and this draft PR were directly requested by the maintainer. The issue does not yet carry acceptance or agent request labels; those labels were left unchanged.

Changes

  • Add operator-owned supervisor_network_mode = "auto" | "host" | "bridge"; sandbox-supplied driver config cannot select this mode.
  • Inspect the existing workload on every supervisor launch, including restart. Preserve network=none, capability removal, and no-new-privileges on the workload boundary.
  • Derive bridge callbacks from Docker Desktop identification and the configured gateway listener. Preserve explicit endpoints and TLS verification; reject bridge loopback/unspecified endpoints and provide guidance for native Linux loopback-only listeners. Remapped container ports and remote layouts can use an explicit grpc_endpoint.
  • Inject Docker-resolved host aliases independently of the gateway endpoint in bridge mode. The supervisor pins the alias from its own driver-owned hosts file before admitting the workload, preventing workload DNS or hosts files from selecting the trusted host address.
  • Add configuration/runtime documentation, driver implementation notes, operational skill guidance, and compatibility with the existing mise run e2e:docker suite without a dedicated networking task or test. The E2E harness uses automatic selection with no networking-mode switches; host runs also discover the callback endpoint automatically, while containerized CI keeps its existing callback address.

Testing

  • mise run pre-commit passes, including workspace Clippy and formatting, Markdown/Mermaid, license, Helm, proto, Python, and TypeScript checks.
  • mise run test passes.
  • Focused Docker driver and supervisor unit tests pass; coverage includes Sysbox detection, explicit modes, endpoint preservation, IPv4/IPv6 handling, listener reachability, operator-only configuration, host alias pinning, and workload isolation.
  • mise run e2e:docker passes against local Docker Engine on Linux arm64 with automatic networking and endpoint selection, using branch-built supervisor and sandbox images. Existing CLI conformance and Rust E2E scenarios cover host aliases, corporate proxies, approved egress, interactive access, lifecycle and reconnect behavior. No dedicated networking test or task is added. Bridge operation was also validated earlier; Desktop ECI qualification remains pending.
  • Clippy passes for the Docker E2E test with its feature enabled.
  • Full mise run ci: fails in unrelated Go SDK gateway discovery tests (TestListGateways_MultipleGateways, TestListGateways_EmptyDirs, TestListGateways_ActiveStatus) because this machine has a configured system gateway under /etc/openshell/gateways. The tests count that additional gateway. No Go source changed.
  • Docker Desktop with ECI: unavailable on this Linux host. Runtime selection is unit-tested with inspected Sysbox metadata, and bridge operation is tested on Docker Engine. Landlock/seccomp qualification and ECI volume behavior still need validation on Desktop. A gateway container under ECI needs an administrator-approved Docker socket exception.

Checklist

  • Follows Conventional Commits.
  • Commit is signed off for DCO.
  • Configuration, runtime, implementation, and operational documentation updated.
  • Related skill maintenance reviewed using the sync-agent-infra maintenance map; debug-openshell-cluster updated.

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

drew added 3 commits October 1, 2026 12:30
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(docker): select supervisor bridge networking for ECI workloads

1 participant