feat(inference): route DNS-backed HTTPS endpoints with scoped credentials - #7188
Conversation
Co-authored-by: DisturbedSage <maruteymani31@gmail.com> Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughAdds a runtime-aware HTTPS Pin Runtime adapter for DNS-backed inference endpoints, including pinned forwarding, credential isolation, route lifecycle management, port validation, uninstall cleanup, inference-set integration, and live test coverage. ChangesHTTPS Pin Runtime Adapter
Estimated code review effort: 5 (Critical) | ~120 minutes Possibly related PRs
Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage in commit 5d63951 in the TypeScript / code-coverage/cliThe overall coverage in commit 5d63951 in the Show a code coverage summary of the most impacted files.
Updated |
|
🌿 Preview your docs: https://nvidia-preview-pr-7188.docs.buildwithfern.com/nemoclaw |
PR Review Advisor — No blocking findings reportedAdvisor assessment: No blocking advisor findings reported Model lanes
Nemotron output stays in workflow artifacts and does not change the assessment above. E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: 1 optional E2E recommendation
This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge. |
Co-authored-by: DisturbedSage <maruteymani31@gmail.com> Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
There was a problem hiding this comment.
Actionable comments posted: 3
🧹 Nitpick comments (1)
src/lib/inference/https-pin-runtime-adapter-forward.ts (1)
239-243: 🩺 Stability & Availability | 🔵 Trivial | ⚡ Quick winUse
closewithreadableEndedfor upstream truncation.
abortedis deprecated here, butclosealso fires on normal completion. If you switch this handler, gate it with!upstreamRes.readableEndedso a clean end doesn’t surface a 502.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@src/lib/inference/https-pin-runtime-adapter-forward.ts` around lines 239 - 243, Replace the upstreamRes “aborted” listener with a “close” listener in the forwarding request flow, and only call failRequest with the existing 502 ForwardHttpError when !upstreamRes.readableEnded. Preserve clean completion without surfacing an error.Source: Learnings
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/lib/actions/inference-set-https-pin-runtime.test.ts`:
- Around line 44-52: The codebase-growth-guardrails scan rejects all seven newly
introduced conditionals across the two inference HTTPS pin test files. In
src/lib/actions/inference-set-https-pin-runtime.test.ts#L44-L52, rework the
provider get/update mock dispatch, inference-set override branch, and failure
=== "list" setup at the cited lines; in
src/lib/actions/inference-set-https-pin-provider.test.ts#L40-L48, rework the
captureSequence guard and makeCapture get dispatch, using ternaries or lookup
tables while preserving behavior. Alternatively, raise the guardrail baseline
only through the sanctioned repository process.
In `@src/lib/actions/sandbox/destroy-https-pin-route.test.ts`:
- Around line 42-62: Remove the failure-based if branch inside the parameterized
test for revokeDestroyedSandboxHttpsPinRoute. Replace the it.each case with two
dedicated it() tests, one simulating listSandboxes failure and one simulating
revokeRoute failure, while preserving the successful resolution and warning
assertions.
In `@src/lib/inference/https-pin-runtime-adapter.test.ts`:
- Around line 85-89: In the sendRawHttpMethod socket “end” handler, remove the
added if/else conditional while preserving rejection for an invalid response and
resolving the parsed status code for valid responses. Use an expression-based
control flow so the test-conditionals guardrail remains at zero.
---
Nitpick comments:
In `@src/lib/inference/https-pin-runtime-adapter-forward.ts`:
- Around line 239-243: Replace the upstreamRes “aborted” listener with a “close”
listener in the forwarding request flow, and only call failRequest with the
existing 502 ForwardHttpError when !upstreamRes.readableEnded. Preserve clean
completion without surfacing an error.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: ecf1cacc-2529-4897-9c7f-cd710b8b7721
📒 Files selected for processing (41)
ci/env-var-doc-allowlist.jsondocs/inference/custom-endpoint-security.mdxdocs/reference/commands.mdxdocs/reference/troubleshooting.mdxnemoclaw/src/blueprint/ssrf.tssrc/lib/actions/inference-set-compatible-provider.test.tssrc/lib/actions/inference-set-endpoint-security.test.tssrc/lib/actions/inference-set-gateway-route-containment.test.tssrc/lib/actions/inference-set-https-pin-provider.test.tssrc/lib/actions/inference-set-https-pin-provider.tssrc/lib/actions/inference-set-https-pin-runtime.test.tssrc/lib/actions/inference-set-provider-alias.test.tssrc/lib/actions/inference-set-route-containment.tssrc/lib/actions/inference-set.test-support.tssrc/lib/actions/inference-set.tssrc/lib/actions/sandbox/destroy-flow.test.tssrc/lib/actions/sandbox/destroy-https-pin-route.test.tssrc/lib/actions/sandbox/destroy.tssrc/lib/actions/uninstall/openrouter-runtime-adapter-cleanup.test.tssrc/lib/actions/uninstall/openrouter-runtime-adapter-cleanup.tssrc/lib/actions/uninstall/run-plan-gateway-segregation.test.tssrc/lib/actions/uninstall/run-plan.test.tssrc/lib/actions/uninstall/run-plan.tssrc/lib/core/ports.test.tssrc/lib/core/ports.tssrc/lib/inference/https-pin-runtime-adapter-forward.test.tssrc/lib/inference/https-pin-runtime-adapter-forward.tssrc/lib/inference/https-pin-runtime-adapter.test.tssrc/lib/inference/https-pin-runtime-adapter.tssrc/lib/inference/https-pin-runtime.test.tssrc/lib/inference/https-pin-runtime.tssrc/lib/inference/openrouter-runtime-adapter-lifecycle.tssrc/lib/onboard/gateway-recovery.tssrc/lib/onboard/inference-providers/hermes.tssrc/lib/sandbox/config.tssrc/lib/subprocess-env.test.tssrc/lib/subprocess-env.tstest/e2e/live/https-pin-compatible-server.tstest/e2e/live/inference-routing.test.tstest/e2e/live/mcp-bridge-servers.tstest/helpers/destroy-flow-test-harness.ts
Co-authored-by: DisturbedSage <maruteymani31@gmail.com> Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Co-authored-by: DisturbedSage <maruteymani31@gmail.com> Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
|
E2E follow-up for exact head |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@test/e2e/support/e2e-workflow.test.ts`:
- Around line 254-263: Extend the test around validateE2eWorkflowBoundary to
mutate prerequisite.env.CLOUDFLARED_DEB_SHA256 to a mutable or invalid value,
then assert the resulting validation errors include the expected SHA256 pin
rejection. Keep this as a separate mutation from the existing
CLOUDFLARED_VERSION check so both security guards are independently covered.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: ed3f61ea-fbef-46ca-9e91-2aede7326c2d
📒 Files selected for processing (5)
.github/workflows/e2e.yamlscripts/checks/check-cloudflared-update.shtest/cloudflared-update-check-workflow.test.tstest/e2e/support/e2e-workflow.test.tstools/e2e/workflow-boundary.mts
Co-authored-by: DisturbedSage <maruteymani31@gmail.com> Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Co-authored-by: DisturbedSage <maruteymani31@gmail.com> Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Co-authored-by: DisturbedSage <maruteymani31@gmail.com> Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
|
Pushed exact-head E2E remediation in The inference-routing failure was in TC-INF-11's disposable onboarding fixture, not the HTTPS pinning transport: it advertised The fixture now retains the localhost rewrite contract while listening on bridge-facing interfaces, matching TC-INF-09 and the shared mock adapter. Validation:
Fresh ordinary CI/advisors are running. The failed protected E2E from the prior revision will not be retried; this revision will receive a fresh exact-head dispatch only after ordinary gates settle. |
|
Protected E2E has been dispatched exactly once for exact head Pre-dispatch recheck: PR mergeable and non-draft, assignment and labels unchanged, commit Verified/DCO, canonical advisor clean, zero unresolved threads, and all ordinary checks green. The secondary advisor lane's red is a tool-protocol execution failure with an empty finding ledger, not a code finding. |
Co-authored-by: DisturbedSage <maruteymani31@gmail.com> Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
|
Protected E2E follow-up on exact head I pushed signed, DCO-compliant, GitHub-Verified commit |
Co-authored-by: DisturbedSage <maruteymani31@gmail.com> Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Co-authored-by: DisturbedSage <maruteymani31@gmail.com> Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Co-authored-by: DisturbedSage <maruteymani31@gmail.com> Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
|
@coderabbitai review |
✅ Action performedReview finished.
|
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
There was a problem hiding this comment.
🧹 Nitpick comments (2)
src/lib/actions/inference-set-https-pin-provider.test.ts (1)
51-51: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low valueUse a behavioral suite title with the linked issue suffix.
Rename this suite to describe its observable contract and append
(#6141); child titles do not need to repeat the suffix.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@src/lib/actions/inference-set-https-pin-provider.test.ts` at line 51, Rename the suite in “HTTPS-pin provider binding” to a title describing the observable behavior it verifies, and append the linked issue suffix “(`#6141`)”. Leave the child test titles unchanged.Source: Coding guidelines
.github/workflows/e2e.yaml (1)
2915-2923: 🩺 Stability & Availability | 🔵 Trivial | ⚡ Quick winDuplicated unhardened swap provisioning bypasses the new
trusted-hermes-e2e-swapanchor. Both rebuild jobs allocate swap at the same fixed/mnt/nemoclaw-hermes-rebuild.swappath with no already-sufficient check, runner-environment check, disk-reserve check, pre-existing-path rejection, or cleanup — the exact guards the anchored step added in this PR.
.github/workflows/e2e.yaml#L2915-L2923: replace the inline block inrebuild-hermeswith the*trusted-hermes-e2e-swapalias (plus itsenv:and hardenedshell:), or extract a shared anchor if the trust gating must differ..github/workflows/e2e.yaml#L3029-L3037: apply the same replacement inrebuild-hermes-stale-baseso both lanes share one swap implementation.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/e2e.yaml around lines 2915 - 2923, Replace the inline swap provisioning in rebuild-hermes at .github/workflows/e2e.yaml:2915-2923 with the trusted-hermes-e2e-swap anchor, including its env and hardened shell configuration. Apply the same replacement in rebuild-hermes-stale-base at .github/workflows/e2e.yaml:3029-3037 so both jobs use the shared guarded swap implementation.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In @.github/workflows/e2e.yaml:
- Around line 2915-2923: Replace the inline swap provisioning in rebuild-hermes
at .github/workflows/e2e.yaml:2915-2923 with the trusted-hermes-e2e-swap anchor,
including its env and hardened shell configuration. Apply the same replacement
in rebuild-hermes-stale-base at .github/workflows/e2e.yaml:3029-3037 so both
jobs use the shared guarded swap implementation.
In `@src/lib/actions/inference-set-https-pin-provider.test.ts`:
- Line 51: Rename the suite in “HTTPS-pin provider binding” to a title
describing the observable behavior it verifies, and append the linked issue
suffix “(`#6141`)”. Leave the child test titles unchanged.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: ef4c53de-8f57-4b59-98fb-a39a8ac6504a
📒 Files selected for processing (14)
.github/workflows/e2e.yamlci/env-var-doc-allowlist.jsondocs/inference/custom-endpoint-security.mdxdocs/reference/commands.mdxdocs/reference/troubleshooting.mdxsrc/lib/actions/inference-set-compatible-provider.test.tssrc/lib/actions/inference-set-degraded-state.test.tssrc/lib/actions/inference-set-gateway-route-containment.test.tssrc/lib/actions/inference-set-https-pin-provider.test.tssrc/lib/actions/inference-set-https-pin-provider.tssrc/lib/actions/inference-set-https-pin-runtime.test.tssrc/lib/actions/inference-set-provider-alias.test.tssrc/lib/actions/inference-set-route-containment.tssrc/lib/actions/inference-set.ts
🚧 Files skipped from review as they are similar to previous changes (7)
- docs/reference/troubleshooting.mdx
- src/lib/actions/inference-set-compatible-provider.test.ts
- src/lib/actions/inference-set-https-pin-runtime.test.ts
- src/lib/actions/inference-set-gateway-route-containment.test.ts
- src/lib/actions/inference-set-provider-alias.test.ts
- src/lib/actions/inference-set-route-containment.ts
- src/lib/actions/inference-set.ts
|
Reviewed exact head
Product scope, separately: #6141 remains open, In Progress, and labeled |
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
|
Addressed the deterministic correctness blocker at exact head |
|
@cv @senthilr-nv — #6141 was closed as completed by @cv at 2026-07-26 01:51 UTC, but the issue has no closure note and this PR has no subsequent product/security review. Does that closure constitute the requested design, ownership, lifecycle, compatibility, security, and validation acceptance for exact head 5d63951? I am keeping this gate fail-closed until one of you confirms explicitly. |
<!-- markdownlint-disable MD041 --> ## Summary Add the canonical `docs/changelog/2026-07-25.mdx` release entry with the exact `## v0.0.96` heading. The entry reconciles all 90 first-parent commits since v0.0.95 with all 92 merged PRs in the live `v0.0.96` label ledger and groups the user-visible changes by operator journey. ## Changes - Add the parser-safe dated MDX changelog entry for v0.0.96 with root-absolute links to the focused user guides. - Source summary: - [#7194](#7194) -> `docs/changelog/2026-07-25.mdx`: Document persistent baseline network policy exclusions and their inspection, rebuild, and snapshot behavior. - [#7188](#7188), [#7427](#7427), and [#7546](#7546) -> `docs/changelog/2026-07-25.mdx`: Document DNS-backed HTTPS inference routing, keyless loopback endpoints, and provider-marker isolation. - [#7238](#7238) -> `docs/changelog/2026-07-25.mdx`: Document blueprint sandbox and provider identifier validation before state writes or OpenShell calls, with bounded terminal-safe rejection previews. - [#7319](#7319), [#7274](#7274), [#7528](#7528), [#7353](#7353), and [#7560](#7560) -> `docs/changelog/2026-07-25.mdx`: Document the managed default gateway service, onboarding readiness, and container-runtime identity safeguards. - [#7349](#7349), [#7498](#7498), [#7406](#7406), [#7196](#7196), [#7559](#7559), [#7421](#7421), [#7510](#7510), [#7295](#7295), and [#7565](#7565) -> `docs/changelog/2026-07-25.mdx`: Document gateway-scoped status, lifecycle diagnostics, managed MCP recovery, delete-edge safeguards, and fail-closed CLI prompt and command output. - [#7591](#7591) -> `docs/changelog/2026-07-25.mdx`: Document opt-in authenticated MCP tool-name discovery, its bounded and names-only contract, probe interaction, and rebuild requirement. - [#7305](#7305), [#7480](#7480), [#7471](#7471), [#7365](#7365), and [#7541](#7541) -> `docs/changelog/2026-07-25.mdx`: Document installer version checks, version-tag reporting, license guidance, WSL Ollama selection, and DGX Station vLLM detection. - [#7482](#7482), [#7466](#7466), [#7208](#7208), [#7434](#7434), and [#7586](#7586) -> `docs/changelog/2026-07-25.mdx`: Document Ollama resource details, reasoning precedence, Hermes onboarding behavior, and preserved managed Hermes BuildKit failures. - [#6830](#6830), [#7492](#7492), [#7563](#7563), and [#7582](#7582) -> `docs/changelog/2026-07-25.mdx`: Document the authoritative OpenClaw production lock, fixed managed-image dependencies, immutable Hermes base adoption, and Hermes image-size reduction. - [#7505](#7505), [#7530](#7530), [#7547](#7547), [#7508](#7508), [#7548](#7548), [#7549](#7549), [#7537](#7537), [#7534](#7534), [#7515](#7515), [#7511](#7511), [#7551](#7551), [#7562](#7562), [#7575](#7575), [#7496](#7496), [#7594](#7594), [#7595](#7595), and [#7599](#7599) -> `docs/changelog/2026-07-25.mdx`: Summarize release validation, transient and bounded dispatch reconciliation, exact pre-tag qualification, identity revalidation, npm-audit retry, sharding, image reuse, timeout, telemetry, and workflow-hardening changes. - Reconciled without separate changelog prose: - [#7539](#7539), [#7526](#7526), [#7507](#7507), [#7506](#7506), [#7519](#7519), [#7516](#7516), [#7396](#7396), [#7254](#7254), [#7583](#7583), [#7596](#7596), and [#7598](#7598): Test-harness or fixture-only changes. - [#7403](#7403), [#7161](#7161), [#6877](#6877), [#7531](#7531), [#7525](#7525), [#7522](#7522), [#7536](#7536), [#7552](#7552), [#7566](#7566), [#7553](#7553), [#7561](#7561), [#7577](#7577), [#7569](#7569), [#7585](#7585), [#7584](#7584), [#7592](#7592), [#7580](#7580), [#7571](#7571), [#7517](#7517), [#7589](#7589), [#7402](#7402), [#7558](#7558), [#7544](#7544), and [#7601](#7601): Dependency, internal recovery, validation, contributor-workflow, E2E optimization, telemetry, or CI trust changes with no separate user-facing release claim. - [#7556](#7556), [#7573](#7573), [#7576](#7576), and [#7578](#7578): Experimental repository-maintainer conflict automation with no canonical user documentation surface. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [x] Existing tests cover changed behavior — justification: `test/changelog-docs.test.ts` validates dated changelog structure, version headings, and published links. - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `docs-updated` - Evidence: Reviewed `docs/changelog/2026-07-25.mdx` at exact head `0f5dedb47` against 90 first-parent release commits and 92 merged PRs labeled `v0.0.96`. Verified parser-safe MDX SPDX, the exact version heading, literal CLI names, writing style, skip terms, all 20 root-absolute published links, and the accepted #7591 opt-in authenticated discovery bounds. #7544, #7599, and #7601 remain internal or CI-only release-ledger entries. Changelog tests passed 6/6, the docs build passed with 0 errors and two pre-existing Fern warnings, and `npm run check:diff` plus the final diff check passed. - Agent: Codex Desktop documentation-writer subagent <!-- docs-review-head-sha: 0f5dedb --> <!-- docs-review-agents-blob-sha: be20a09 --> ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: - Station profile/scenario: - Result: - Supporting evidence: ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — `npx vitest run test/changelog-docs.test.ts`: 6/6 passed. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: Not applicable to this prose-only changelog entry. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — the build passed with 0 errors and 2 existing Fern warnings; the published-route check passed. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) — native changelog files use the required parser-safe MDX SPDX comment and no frontmatter. --- Signed-off-by: Carlos Villela <cvillela@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Persistent network policy exclusions with consistent restore/exclusion reporting across rebuilds/snapshots. * Opt-in MCP tool discovery via `mcp status --tools` with bounded, redacted authenticated traffic. * Improved HTTPS inference switching for custom endpoints and refreshed onboarding/model menu details. * Refined OpenShell gateway defaults for port `8080`, including more reliable readiness checks. * **Bug Fixes** * Prevent incorrect provider/model restoration after compatible-provider update failures. * Preserve managed MCP state after exec loss and tighten gateway/doctor status scoping. * **Tests** * Stronger, fail-closed release validation with hardened evidence/artifact handoff and bounded timeouts/retries. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com> Co-authored-by: Prekshi Vyas <prekshiv@nvidia.com>
Summary
Carries forward the original implementation from #6906 and closes its blocking cross-route credential-isolation gap.
inference set --endpoint-urlcan now use DNS-backed HTTPS custom endpoints through a pinned host adapter while every sandbox-facing route receives its own credential and the real upstream secret remains host-only.Related Issue
Fixes #6141
Changes
inference seton already-onboarded OpenClaw and Hermes sandboxes. Direct IP substitution cannot preserve TLS SNI/certificate validation, so the adapter resolves and validates the public peer on the host, connects to the pinned address with the original hostname, and exposes only an opaquehost.openshell.internalroute to OpenShell.openshell-dockernetwork. Reject unrelated RFC1918, ULA, and link-local peers, fail closed when no valid bridge CIDR is available, and bind adapter reuse proofs to the source-policy digest./v1for bare-origin OpenAI endpoints, recognize persisted routes across adapter-port changes, restrict health metadata to admitted sources, and register upstream route credentials only through the authenticated loopback control plane after spawn.Type of Change
Quality Gates
senthilr-nv.Documentation Writer Review
docs-updateddocs/inference/custom-endpoint-security.mdxdocuments exactopenshell-dockerIPAM source restriction, rejection of unrelated private peers, fail-closed bridge discovery, source-policy-bound adapter reuse, bare-origin path preservation, the total upstream deadline, late-response disposal, health visibility, and loopback-only post-spawn credential registration. The exact-head E2E-only follow-up was re-reviewed asno-docs-neededbecause the canonical page already documents query/userinfo rejection and non-persistence.5d639519f; the rollback recovery paragraph remains accurate after the normal current-main sync, andnpm run docspasses.Verification
Signed-off-by:line and every commit appears asVerifiedin GitHubpre-commit,commit-msg, andpre-pushhooks passed, ornpm run check:diffpassed when hooks were skipped or unavailable5d639519f: all 18 inference-set files / 158 tests passed after current-main sync, including the provider-update rollback regression; Biome, CLI typecheck, test-title/source-shape checks, normal commit/pre-push hooks, and the docs build passed. Earlier exact head54954d4b6also passed the combined inference suite (68 files, 1,121 passed, 1 skipped) and credential-state E2E workflow contracts.npm testfor broad runtime/test-harness changes;npm run checkfor repo-wide validation/coverage changes — command/result:npm run docsbuilds without warnings (doc changes only) — passed with zero errors; existing Node deprecation and two Fern warnings remain.Signed-off-by: Apurv Kumaria akumaria@nvidia.com
Summary by CodeRabbit