Skip to content

fix(gateway): check launch signing before VM image preparation - #4034

Open
shiju-nv wants to merge 4 commits into
mainfrom
fix/3949-launch-signing-preflight
Open

shiju-nv wants to merge 4 commits into
mainfrom
fix/3949-launch-signing-preflight

Conversation

@shiju-nv

@shiju-nv shiju-nv commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Summary

A VM gateway with listener TLS but no launch signer can download and prepare an image before reporting missing credentials. Check the selected driver's launch-signing requirement before creation reaches driver validation, and reject missing or malformed VM launch credentials before image preparation or state changes. Add the missing signing table to the MicroVM configuration example and explain how to generate a local bundle.

Related Issue

Fixes #3949, accepted by a maintainer on 2026-09-30. Part of #3955.

Changes

  • Declare openshell.compute.launch-authentication through existing capability negotiation. Drivers that use another launch mechanism can omit it.
  • Load and validate signing keys at gateway startup, including the public/private match. Explicit gateway_jwt configuration takes precedence over local bundle discovery. Diagnostics identify the missing or invalid configuration without exposing credentials.
  • Validate saved credentials before startup restoration changes state, and validate replacement credentials before stopping an existing VM.
  • Include explicit signing configuration and a local-generation command in the MicroVM documentation. Explain that config preflight does not load signing keys; gateway startup and sandbox admission check launch readiness.

Testing

  • mise run pre-commit passes
  • Unit tests added/updated
  • E2E tests added/updated (if applicable)

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO). Every existing branch commit also has a verified SSH signature.
  • Architecture docs updated (if applicable). The reviewed configuration correction is committed.

Negotiate a launch-authentication requirement and reject incomplete gateway
configuration before driver validation, archive consumption or persistence.
Validate replacement VM credentials before stopping active compute and
prefer explicit signer configuration over local discovery.

Closes #3949. Part of #3955.

Signed-off-by: Shiju <shiju@nvidia.com>
Signed-off-by: Shiju <shiju@nvidia.com>
Include the gateway JWT paths in the standalone VM configuration and show
the output directory required by local certificate generation. Explain
the distinction between configuration preflight and launch-key validation.

Refs #3949. Part of #3955.

Signed-off-by: Shiju <shiju@nvidia.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

@shiju-nv
shiju-nv marked this pull request as ready for review October 1, 2026 19:19

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Validate sandbox launch-signing configuration before image preparation

1 participant