Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
142 commits
Select commit Hold shift + click to select a range
ac3fc48
fix(core): exclude vm-dev tag from git describe version glob (#843)
mjamiv Apr 15, 2026
25d2530
fix(inference): allowlist routed request headers (#826)
johntmyers Apr 15, 2026
3b21df1
feat(sandbox): load system CA certificates for upstream TLS connectio…
matz3 Apr 16, 2026
5718553
feat(release): publish standalone openshell-gateway binaries (#853)
drew Apr 16, 2026
3bc8e44
docs(rfc): adopt per-RFC folder structure (#870)
drew Apr 17, 2026
4e8dbcf
fix(sandbox): harden seccomp, inference routing, and process limits (…
johntmyers Apr 17, 2026
e4d6f92
feat(vm): add standalone libkrun compute driver (#858)
drew Apr 17, 2026
2c9c146
docs: fix TOC structure (#797)
miyoungc Apr 17, 2026
b7c7632
docs: refresh user-facing docs for recent sandbox and inference chang…
miyoungc Apr 17, 2026
5c3015a
docs(contributing): add bash shell setup example for mise (#877)
mrunalp Apr 17, 2026
ae7e901
fix(sandbox): strip " (deleted)" suffix from unlinked /proc/<pid>/exe…
mjamiv Apr 17, 2026
e39bb38
test(sandbox): fix flaky arm64 procfs binary_path tests (#881)
pimlock Apr 18, 2026
40e9bf6
feat(policy): add incremental sandbox policy updates (#860)
johntmyers Apr 20, 2026
7a0a3d0
fix(cli,tui): escape and validate SSH session response fields (#876)
johntmyers Apr 20, 2026
8a813ab
fix(sandbox): apply supervisor seccomp prelude (#891)
johntmyers Apr 20, 2026
b39f5aa
feat(install-vm): install gateway + vm driver, add --driver-dir resol…
drew Apr 20, 2026
9ac725f
fix(cli): sandbox get returns currently active runtime policy (#880)
TaylorMutch Apr 20, 2026
c960d48
fix(sandbox): canonicalize HTTP request-targets before L7 policy eval…
johntmyers Apr 21, 2026
a6d4552
feat(server,sandbox): supervisor-initiated SSH connect and exec over …
pimlock Apr 21, 2026
ba56206
feat(server): add request-level logging via tower-http TraceLayer (#895)
sjenning Apr 21, 2026
bd11395
feat(server): serve health endpoints on separate unauthenticated port…
sjenning Apr 21, 2026
42c3cf6
fix(k8s-driver): use dedicated kube client without read_timeout for w…
sjenning Apr 21, 2026
cbcc4b7
feat(server): allow disabling health check listener (#915)
TaylorMutch Apr 22, 2026
78b685e
feat: add configurable timeout for image transfer to gateway containe…
tmckayus Apr 22, 2026
e28ca07
fix(sandbox): preserve explicit read-only baseline paths (#910)
johntmyers Apr 22, 2026
f954e59
fix(sandbox): resolve sandbox host aliases in SSRF checks (#912)
johntmyers Apr 22, 2026
2f8e8ac
fix(sandbox): inject GIT_SSL_CAINFO so git clone trusts the sandbox C…
laitingsheng Apr 22, 2026
30ddca4
ci(e2e): enable E2E to run on external forks throught the copy-pr-bot…
pimlock Apr 22, 2026
4483c86
feat(server,driver-vm,e2e): gateway-owned readiness + VM compute driv…
drew Apr 22, 2026
d0a29b6
fix(driver-vm): preflight supervisor cross-compile toolchain in start…
pimlock Apr 23, 2026
89dd10b
fix(ci): e2e gate must verify work actually ran, not just top-level s…
pimlock Apr 23, 2026
c6f5792
fix(ci): bump ci-image tooling versions to address vendored CVEs (#929)
johntmyers Apr 23, 2026
c5d5855
fix(ci): bump helm to 4.1.4 to address plugin vulnerabilities (#928)
johntmyers Apr 23, 2026
8405cea
fix(skills): remove --assignee @me from gh pr/issue create commands (…
sjenning Apr 23, 2026
b19a3dc
chore(mise): replace deprecated ubi: prefix by github: prefix (#923)
benoitf Apr 23, 2026
9bc2e2c
fix(ci): rename mise --no-prepare to --no-deps (#942)
pimlock Apr 23, 2026
3b7d309
feat(server): add Prometheus metrics infrastructure and gRPC/HTTP req…
sjenning Apr 23, 2026
ab3f3e0
fix(ci): post E2E Gate check to the PR when workflow_run fires (#938)
pimlock Apr 23, 2026
550c6e4
chore(helm): remove unused ClusterRole and ClusterRoleBinding (#943)
TaylorMutch Apr 23, 2026
0a09404
feat(ci): add shadow-shared-cpu-spike workflow for OS-49 Phase 2 (#934)
jtoelke2 Apr 23, 2026
75b880b
chore(ci): add ARC baseline collector for OS-49 runner migration (#927)
jtoelke2 Apr 23, 2026
ef2d993
fix(ci): expose GHA sccache env in shadow-shared-cpu-spike (#950)
jtoelke2 Apr 24, 2026
a4dfa5a
feat(ci): add driver input to setup-buildx action (#941)
jtoelke2 Apr 24, 2026
0d301d5
fix(cli): preserve directory basename when uploading to sandbox (#952)
mjamiv Apr 24, 2026
7f8e210
fix(sandbox): route console logs to stderr (#949)
johntmyers Apr 24, 2026
87f50f5
fix(e2e): add /dev/urandom to provider test sandbox policy (#948)
derekwaynecarr Apr 24, 2026
a34b25a
test(e2e): fix rust upload path assertions (#960)
drew Apr 24, 2026
8cf5ebd
test(e2e): fix gitignore upload assertion path (#962)
johntmyers Apr 24, 2026
77a88c3
fix(ci): partition GHA sccache cache per arch in shadow spike (#961)
jtoelke2 Apr 24, 2026
d44d8a1
feat: Openshell driver podman (#904)
maxamillion Apr 24, 2026
df38d1f
feat(ci): add Markdown and Mermaid linting (#933)
pimlock Apr 24, 2026
8a3c0b0
feat(docker): add BINARY_SOURCE selector for prebuilt Rust binaries (…
jtoelke2 Apr 24, 2026
25c827d
test(e2e): fix filtered upload path assertion (#963)
drew Apr 24, 2026
d331ed5
feat(ci): add shadow-docker-build workflow for OS-49 Phase 3 (#964)
jtoelke2 Apr 24, 2026
daa7d7d
fix(ci): use nv-gha-runners buildkit mirror to avoid Docker Hub rate …
jtoelke2 Apr 24, 2026
a01b6dd
fix(docs): scope fenced code language linting (#965)
pimlock Apr 24, 2026
55b0266
fix(ci): make buildkitd-config opt-in for setup-buildx (#970)
jtoelke2 Apr 24, 2026
bb5bdb4
fix(ci): ignore local artifacts in license checks (#974)
johntmyers Apr 24, 2026
f8fb382
fix(scripts): handle docker cleanup when no containers are running (#…
derekwaynecarr Apr 27, 2026
5e28ea3
feat(server): add object meta convention to top-level objects (#919)
derekwaynecarr Apr 27, 2026
30115bd
fix(ci): patch CI container vulnerability toolchain (#959)
johntmyers Apr 27, 2026
e5360b3
docs(rfc): add core architecture RFC (#836)
drew Apr 27, 2026
de9dce0
fix(e2e): use high UID range to avoid host user conflicts (#978)
derekwaynecarr Apr 27, 2026
e703b59
ci(e2e): add label dispatcher and contributor CI docs (#975)
pimlock Apr 27, 2026
c428664
ci(e2e): replace label dispatcher with comment-only helper (#990)
pimlock Apr 27, 2026
aee7443
fix(deps): add missing cargo-zigbuild dep for macOS cross-compilation…
benoitf Apr 27, 2026
cde20dc
docs: weekly documentation refresh (#993)
miyoungc Apr 27, 2026
2646b8c
fix(sandbox): deny ambiguous socket ownership (#958)
johntmyers Apr 27, 2026
c890f0e
chore(ci): relax agent diagnostic gate (#1001)
johntmyers Apr 27, 2026
b264cb8
chore(mise): add lockfile with multi-platform support and version pin…
pimlock Apr 27, 2026
385855c
fix(podman): use podman machine socket path on macOS (#999)
benoitf Apr 27, 2026
5975805
feat(server): add bundled docker compute driver (#888)
drew Apr 28, 2026
c49ae09
fix(ci): grant actions:read and contents:read to E2E label helper (#995)
pimlock Apr 28, 2026
cd5c16d
chore(tools): sync mise version to v2026.4.25 (#1013)
TaylorMutch Apr 28, 2026
3e69c36
feat(ci): add shadow-rust-native-build workflow for OS-49 Phase 4 (PR…
jtoelke2 Apr 28, 2026
d414e69
refactor(server): unify policy persistence in objects table (#972)
johntmyers Apr 28, 2026
20ffc72
fix(cli): preserve directory basename for filtered uploads (#1028)
johntmyers Apr 29, 2026
4510b0d
fix(net): catch IPv4-mapped blocked ranges in is_always_blocked_net (…
mesutoezdil Apr 29, 2026
c0ffa93
feat(openshell-vm): allow to have tty with exec (#939)
benoitf Apr 29, 2026
2adddaa
feat: Adding qemu vm driver support with GPU pass-through (#992)
vince-brisebois Apr 29, 2026
2472474
ci(rust): enforce -D warnings on clippy (#1008)
drew Apr 29, 2026
0914f3f
fix(sandbox): log L7 parse denials (#1072)
johntmyers Apr 29, 2026
ee2de81
fix(sandbox): preserve encoded slash policy from proto (#1073)
pimlock Apr 29, 2026
a656ed7
ci(docker): use prebuilt Rust binaries by default (#1027)
jtoelke2 Apr 30, 2026
78f0b6f
ci(rust): keep sccache stats non-blocking
jtoelke2 Apr 30, 2026
ebbd9de
docs(examples): add multi-agent notepad demo (#991)
zredlined Apr 30, 2026
5c77b06
ci: add OS-49 phase 5 shadow workflows (#1075)
jtoelke2 Apr 30, 2026
0845054
feat(auth): add OIDC/Keycloak authentication with RBAC and scope-base…
mrunalp Apr 30, 2026
51351e4
chore(ci): update checkout action to v6 (#1086)
drew Apr 30, 2026
182cbc6
fix(docker): set apparmor=unconfined on sandbox containers (#1078)
elezar Apr 30, 2026
0c0f3e3
feat(docker): enable CDI GPU sandboxes (#1036)
elezar Apr 30, 2026
ea4915a
feat(server): add feat: auto-detection of compute driver at startup (…
sjenning May 1, 2026
f46b296
test(e2e): skip docker gpu test in rust suite (#1103)
pimlock May 1, 2026
888f1dd
chore: sync Cargo.lock (#1084)
TaylorMutch May 1, 2026
dd98eb2
ci: drop duplicate shadow e2e workflow (#1104)
jtoelke2 May 1, 2026
b39af3d
chore(ci): label mon maintainer issues for triage (#1102)
johntmyers May 1, 2026
9751872
feat(release): add Debian package publishing (#1069)
drew May 1, 2026
fcefdd5
feat(driver-docker): use host networking for sandboxes (#1080)
drew May 1, 2026
230824e
fix(install): refresh dev gateway registration (#1110)
drew May 1, 2026
8e28209
chore(ci): label maintainer issues by repo permission (#1116)
johntmyers May 1, 2026
55f0e37
chore(ci): label non-maintainer issues for triage (#1120)
johntmyers May 1, 2026
a3aed62
chore(openshell-core): discover proto files in build script (#1122)
ddurst-nvidia May 1, 2026
4c25648
fix(sandbox): accept ENOENT in drop_privileges identity lookup tests …
ddurst-nvidia May 1, 2026
5d0a44c
fix(sandbox): invalidate stale l7 tunnels after reload (#1118)
johntmyers May 1, 2026
76093e7
refactor(sandbox): remove dead relay_response_to_client wrapper (#1125)
mesutoezdil May 1, 2026
32857eb
fix(helm): grant node read access for GPU capacity checks (#1106)
jtoelke2 May 1, 2026
c035227
docs: fix broken link and capitalise GitHub correctly (#1135)
mesutoezdil May 2, 2026
721c39f
docs: fix tutorial links pointing to /tutorials instead of /get-start…
mesutoezdil May 2, 2026
08001ca
fix(docker): harden supervisor startup and gateway routing (#1128)
drew May 4, 2026
2e0afea
feat(vm): derive guest rootfs from sandbox images (#957)
drew May 4, 2026
a255ad9
fix(e2e): stabilize wildcard host DNS test (#1144)
drew May 4, 2026
213025d
fix(bootstrap): add no-progress timeout to image build (#1109)
laitingsheng May 4, 2026
6b21804
feat(policy): add GraphQL L7 inspection (#1083)
johntmyers May 4, 2026
4803889
ci: cut over non-release workflows to shared runners (#1131)
jtoelke2 May 4, 2026
d73860f
feat(driver-kubernetes): sideload supervisor binary via init containe…
TaylorMutch May 4, 2026
25c4fde
fix(examples): repair multi-agent notepad uploads (#1152)
zredlined May 4, 2026
04e48d5
feat(server): add request-ID middleware for request correlation (#1082)
sauagarwa May 4, 2026
043bde2
feat(providers): add profile-backed policy composition (#1037)
johntmyers May 5, 2026
e405e40
fix(ci): include provider profiles in macos docker builds (#1163)
johntmyers May 5, 2026
9c53d12
ci(os-49): remove obsolete shadow PR workflows (#1161)
jtoelke2 May 5, 2026
f56c09c
docs: update gateway deployment architecture (#1108)
drew May 5, 2026
9efb346
chore: add new core maintainers to OpenShell (#1167)
drew May 5, 2026
e73a4ea
ci(os-49): draft release runner cutover (#1164)
jtoelke2 May 5, 2026
142a3a3
fix(examples): harden multi-agent notepad 409 retry and improve docs …
zredlined May 5, 2026
8bfd3e1
ci(os-49): fix release jobs on shared runners (#1172)
jtoelke2 May 5, 2026
b77b60b
Two podman driver fixes (#1077)
cgwalters May 5, 2026
e4b4e92
test(e2e): run suites against docker gateway (#1153)
drew May 5, 2026
5116cc2
feat(helm): add kubernetes local-dev environment (#1158)
TaylorMutch May 5, 2026
c0cc196
feat(cli): add openshell gateway list subcommand (#1179)
maxdubrinsky May 5, 2026
5b29189
chore: Simplify codeowners rules (#1178)
TaylorMutch May 5, 2026
d8b8477
feat(rpm): add RPM packaging with Packit/COPR and GHA release publish…
maxamillion May 5, 2026
f17806c
fix(ci): sync mise lock header with CI (#1187)
drew May 6, 2026
6ce988d
fix(ci): harden packit rpm source prep (#1182)
drew May 6, 2026
4d388d2
ci(vm): cleanup vm build infra (#1186)
drew May 6, 2026
56ba935
docs: add missing provider types to supported providers table (#1180)
mesutoezdil May 6, 2026
9291eaf
chore(ci): enable Dependabot for GitHub Actions with 48h cooldown (#1…
fcanogab May 6, 2026
152d059
ci(vm): remove remaining EKS release assumptions (#1195)
jtoelke2 May 6, 2026
8ace316
fix(ci): allowlist dependabot for DCO (#1202)
johntmyers May 6, 2026
bb4dbd7
fix(kube): add RBAC rule for sandbox finalizer updates (#1203)
sjenning May 6, 2026
86b8ffd
fix(docker): copy providers/ into rust-builder stage (#1211)
TaylorMutch May 6, 2026
b2feacc
fix(bootstrap): stabilize release canary gateway startup (#1210)
jtoelke2 May 6, 2026
26bdb03
feat(cli): add --gateway-insecure flag to skip TLS certificate verifi…
sjenning May 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
29 changes: 12 additions & 17 deletions .agents/skills/build-from-issue/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -402,29 +402,24 @@ git diff --name-only main -- e2e/

If there are no changes under `e2e/`, skip this phase entirely.

If E2E files were modified, deploy to the local cluster and run the E2E test suite:
If E2E files were modified, run the relevant E2E lane for the driver touched by the change:

```bash
# Deploy all changes to the local k3s cluster
mise run cluster:deploy

# Run the E2E sandbox tests
mise run test:e2e:sandbox
# Docker-backed gateway smoke E2E
mise run e2e:docker
```

`mise run test:e2e:sandbox` depends on `cluster:deploy` and `python:proto`, then runs `uv run pytest -o python_files='test_*.py' e2e/python`. However, since the cluster may need explicit deploy for code changes beyond just E2E test files, always run `mise run cluster:deploy` first as a separate step to ensure all sandbox/proxy/policy changes are live on the cluster before running E2E tests.
Use `mise run e2e:podman`, `mise run e2e:vm`, or a Helm-backed Kubernetes E2E lane when the change targets those drivers.

**E2E retry loop** (up to 3 attempts):

1. Run `mise run cluster:deploy` (only on the first attempt, or if code was changed between attempts).
2. Run `mise run test:e2e:sandbox`.
3. If tests fail:
1. Run the selected E2E lane.
2. If tests fail:
- Read the pytest output carefully — identify which tests failed and why.
- Distinguish between **test bugs** (the test itself is wrong) and **implementation bugs** (the code under test is wrong).
- Fix the failing code or tests.
- If code changes were made (not just test fixes), re-run `mise run cluster:deploy` before retrying.
- Decrement the retry counter and try again.
4. If tests pass, Phase 2 is green.
3. If tests pass, Phase 2 is green.

**If all 3 E2E attempts fail**, stop and report to the user:
- Which E2E tests are failing
Expand Down Expand Up @@ -478,7 +473,6 @@ Create the PR:
```bash
gh pr create \
--title "<type>(<scope>): <short description>" \
--assignee "@me" \
--body "$(cat <<'EOF'
> **🏗️ build-from-issue-agent**

Expand Down Expand Up @@ -577,8 +571,8 @@ Local E2E tests passed. CI does not currently run E2E tests, so this comment ser
| Field | Value |
|-------|-------|
| **Commit** | `<commit-sha>` |
| **Command** | `mise run test:e2e:sandbox` |
| **Cluster deploy** | `mise run cluster:deploy` (completed before test run) |
| **Command** | `<selected e2e command>` |
| **Gateway mode** | `<docker / podman / vm / helm>` |
| **Result** | ✅ All passed |

### Test Summary
Expand Down Expand Up @@ -646,8 +640,9 @@ If the `state:in-progress` label is present, the skill was previously started bu
| `gh pr create --title "..." --body "..."` | Create a pull request |
| `gh api user --jq '.login'` | Get current GitHub username |
| `mise run pre-commit` | Run pre-commit checks (includes unit tests, lint, format) |
| `mise run cluster:deploy` | Deploy all changes to local k3s cluster |
| `mise run test:e2e:sandbox` | Run E2E sandbox tests (depends on cluster:deploy) |
| `mise run e2e:docker` | Run smoke E2E against a standalone Docker-backed gateway |
| `mise run e2e:podman` | Run smoke E2E against a Podman-backed gateway |
| `mise run e2e:vm` | Run smoke E2E against the VM compute driver |

## Example Usage

Expand Down
1 change: 0 additions & 1 deletion .agents/skills/create-github-issue/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -114,7 +114,6 @@ GitHub built-in issue types (`Bug`, `Feature`, `Task`) should come from the matc
| `--title, -t` | Issue title (required) |
| `--body, -b` | Issue description |
| `--label, -l` | Add label (can use multiple times) |
| `--assignee, -a` | Assign to user |
| `--milestone, -m` | Add to milestone |
| `--project, -p` | Add to project |
| `--web` | Open in browser after creation |
Expand Down
21 changes: 1 addition & 20 deletions .agents/skills/create-github-pr/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -99,30 +99,13 @@ gh pr create --title "PR title" --body "PR description"
- `refactor(models): simplify deployment logic`
- `chore(ci): update Python version in pipeline`

## Required PR Fields

Every PR **must** have:

1. **Assignee** - Always assign to yourself

## Assignee and Reviewer

### Always Assign to Yourself

**Every PR must be assigned to the user creating it.** Use the `--assignee` flag:

```bash
gh pr create --title "Title" --assignee "@me"
```

### Link to an Issue

Use `Closes #<issue-number>` in the body to auto-close the issue when merged:

```bash
gh pr create \
--title "Fix validation error for empty requests" \
--assignee "@me" \
--body "Closes #123

## Summary
Expand All @@ -135,7 +118,7 @@ gh pr create \
For work-in-progress that's not ready for review:

```bash
gh pr create --draft --title "WIP: New feature" --assignee "@me"
gh pr create --draft --title "WIP: New feature"
```

### With Labels
Expand Down Expand Up @@ -185,7 +168,6 @@ Populate the testing checklist based on what was actually run. Check boxes for s
```bash
gh pr create \
--title "feat(cli): add pagination to sandbox list" \
--assignee "@me" \
--body "$(cat <<'EOF'
## Summary

Expand Down Expand Up @@ -222,7 +204,6 @@ EOF
| ------------------- | ------------------------------------------ |
| `--title, -t` | PR title (use conventional commit format) |
| `--body, -b` | PR description |
| `--assignee, -a` | Assign to user (use `@me` for yourself) |
| `--reviewer, -r` | Request review from user |
| `--draft` | Create as draft (WIP) |
| `--label, -l` | Add label (can use multiple times) |
Expand Down
23 changes: 12 additions & 11 deletions .agents/skills/debug-inference/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -174,7 +174,7 @@ openshell sandbox create -- curl https://inference.local/v1/chat/completions --j

Interpretation:

- **`cluster inference is not configured`**: set the managed route with `openshell inference set`
- **`cluster inference is not configured`**: set the managed gateway route with `openshell inference set`
- **`connection not allowed by policy`** on `inference.local`: unsupported method or path
- **`no compatible route`**: provider type and client API shape do not match
- **Connection refused / upstream unavailable / verification failures**: base URL, bind address, topology, or credentials are wrong
Expand Down Expand Up @@ -232,7 +232,7 @@ In this case, OpenShell routing is usually working correctly. The failing hop is

This is not the same issue as the Colima CoreDNS fix.

OpenShell injects `host.docker.internal` and `host.openshell.internal` into sandbox pods with `hostAliases`. That path bypasses cluster DNS lookup. If the request still times out, the usual cause is host firewall or network policy, not CoreDNS.
OpenShell injects `host.docker.internal` and `host.openshell.internal` into sandbox workloads when the selected compute platform supports it. That path bypasses runtime DNS lookup. If the request still times out, the usual cause is host firewall or network policy, not DNS.

### Verify the Problem

Expand All @@ -248,40 +248,41 @@ OpenShell injects `host.docker.internal` and `host.openshell.internal` into sand
curl -sS http://172.17.0.1:11434/v1/models
```

3. Test the same endpoint from the OpenShell cluster container:
3. Test the same endpoint from a gateway or sandbox container on the Docker network:

```bash
docker exec openshell-cluster-<gateway> wget -qO- -T 5 http://host.docker.internal:11434/v1/models
docker ps --filter name=openshell --format '{{.Names}}'
docker exec <container-name> wget -qO- -T 5 http://host.docker.internal:11434/v1/models
```

If steps 1 and 2 succeed but step 3 times out, the host firewall or network configuration is blocking the container-to-host path.

### Fix

Allow the Docker bridge network used by the OpenShell cluster to reach the host-local inference port. The exact command depends on your firewall tooling (iptables, nftables, firewalld, UFW, etc.), but the rule should allow:
Allow the Docker bridge network used by the OpenShell gateway and sandbox containers to reach the host-local inference port. The exact command depends on your firewall tooling (iptables, nftables, firewalld, UFW, etc.), but the rule should allow:

- **Source**: the Docker bridge subnet used by the OpenShell cluster container (commonly `172.18.0.0/16`)
- **Destination**: the host gateway IP injected into sandbox pods for `host.docker.internal` (commonly `172.17.0.1`)
- **Source**: the Docker bridge subnet used by OpenShell containers (commonly `172.18.0.0/16`)
- **Destination**: the host gateway IP injected into sandbox workloads for `host.docker.internal` (commonly `172.17.0.1`)
- **Port**: the inference server port (e.g. `11434/tcp` for Ollama)

To find the actual values on your system:

```bash
# Docker bridge subnet for the OpenShell cluster network
# Docker bridge subnet for the OpenShell network
docker network inspect $(docker network ls --filter name=openshell -q) --format '{{range .IPAM.Config}}{{.Subnet}}{{end}}'

# Host gateway IP visible from inside the container
docker exec openshell-cluster-<gateway> cat /etc/hosts | grep host.docker.internal
docker exec <container-name> cat /etc/hosts | grep host.docker.internal
```

Adjust the source subnet, destination IP, or port to match your local Docker network layout.

### Verify the Fix

1. Re-run the cluster container check:
1. Re-run the container network check:

```bash
docker exec openshell-cluster-<gateway> wget -qO- -T 5 http://host.docker.internal:11434/v1/models
docker exec <container-name> wget -qO- -T 5 http://host.docker.internal:11434/v1/models
```

2. Re-test from a sandbox:
Expand Down
Loading
Loading