Skip to content

fix(ssh): persist sandbox host identities - #4027

Closed
quocanh261997 wants to merge 1 commit into
NVIDIA:mainfrom
quocanh261997:feat/3835-stable-ssh-host-key
Closed

quocanh261997 wants to merge 1 commit into
NVIDIA:mainfrom
quocanh261997:feat/3835-stable-ssh-host-key

Conversation

@quocanh261997

Copy link
Copy Markdown

Summary

Sandbox SSH host keys currently change when the supervisor restarts, so clients cannot reliably recognize the same sandbox. Give each sandbox ID one Ed25519 host key and expose its public SHA256 fingerprint. Keep the private key in the configured gateway credential store and deliver it only to the supervisor.

Related Issue

Closes #3835

Changes

  • Persist a sandbox-owned credential handle and fingerprint. Keep identity across stop/start, automatic restarts, and gateway recovery; remove credentials during deletion. Retain cleanup ownership when credential deletion fails and finish staging if a request is interrupted.
  • Require the managed supervisor to use its assigned host key. Reject missing, invalid, or mismatched key material instead of replacing an established identity.
  • Return the fingerprint on Sandbox and SSH-session responses, sandbox JSON output, and Rust, Python, Go, and TypeScript sandbox references.
  • Document identity lifetime, authenticated fingerprint lookup, workload isolation, and matching runtime releases. CLI/TUI automatic verification remains the optional follow-on from the issue.

Testing

  • mise run pre-commit passes.
  • Unit tests added/updated.
  • E2E tests added/updated.
  • mise run ci — passed, including workspace and gateway Rust tests, Python tests, Go checks, TypeScript tests, formatting, lint, and compile checks.
  • mise run sdk:ts:ci — passed, including 142 tests, coverage, and build validation.
  • mise run go:ci — passed.
  • Feature-enabled lint of ssh_host_identity — passed.
  • Docker CLI conformance — all six scenarios passed.
  • Docker SSH identity E2E — one test passed, with no failures or skips. Verified Get/List against the presented SSH fingerprint, a pinned OpenSSH connection after stop/start and managed gateway restart, workload read restrictions, and a new identity after delete/recreate.

Rust checks used LIBRARY_PATH=/opt/homebrew/lib for Homebrew Z3 on macOS. Installed e2fsprogs for the existing VM filesystem tests.

The stock Docker E2E launcher failed locally because its container-side 127.0.0.1 endpoint cannot reach the macOS gateway. The successful conformance run uses an ignored copy of the launcher with host.docker.internal as the supervisor endpoint and the temporary mTLS gateway bound on all interfaces. This local launcher adjustment is excluded from the PR.

Added tests cover credential-store reconstruction, concurrent candidates, interrupted preparation, deletion retries, failed candidate cleanup, inconsistent published identity, secret redaction, older bootstrap bundles, client conversion, fingerprint responses, and real SSH handshakes with direct and relayed streams after listener restart. A live sandbox test checks Get/List fingerprints, a remembered OpenSSH host key through stop/start and gateway restart, workload access restrictions, and recreation under the same name.

The live test uses the Docker driver. Kubernetes pod rescheduling and other compute-driver lanes have not been exercised locally.

Checklist

  • Follows Conventional Commits.
  • Commits are signed off (DCO).
  • Architecture docs updated where applicable; public behavior and related operating skills are documented.

Store each sandbox's Ed25519 host key in the gateway credential store and
deliver it only to the supervisor. Preserve identity across restarts,
delete owned credentials with the sandbox, and expose the public SHA256
fingerprint through sandbox and SSH-session APIs and client SDKs.

Cover credential ownership, cancellation, deletion retries, client
compatibility, and pinned SSH connections through lifecycle transitions.

Closes NVIDIA#3835

Signed-off-by: Mike Nguyen <miken@nvidia.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Thank you for your interest in contributing to OpenShell, @quocanh261997.

This project uses a vouch system for first-time contributors. Before submitting a pull request, you need to be vouched by a maintainer.

To get vouched:

  1. Open a Vouch Request discussion.
  2. Describe what you want to change and why.
  3. Write in your own words — do not have an AI generate the request.
  4. A maintainer will comment /vouch if approved.
  5. Once vouched, open a new PR (preferred) or reopen this one after a few minutes.

See CONTRIBUTING.md for details.

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

All contributors have signed the DCO ✍️ ✅
Posted by the DCO Assistant Lite bot.

@github-actions github-actions Bot closed this Oct 1, 2026
@quocanh261997

Copy link
Copy Markdown
Author

I have read the DCO document and I hereby sign the DCO.

@quocanh261997

Copy link
Copy Markdown
Author

recheck

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat: stable per-sandbox SSH host key, exposed so clients can verify it

1 participant