Repository navigation
feat: enforce one workload sandbox backend per run - #9771
Conversation
Resolve the primary workload backend and inherit omitted enclave runtimes. Reject explicit or assembled backend conflicts before staging. Preserve unsupported Cloud Hypervisor and NVX integration guards. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 2d29b77f-7ee8-4e53-8e41-6dfee822ffaf
Documentation PreviewDocumentation has been built for this PR. To view locally:
Built from commit 421ce35 |
There was a problem hiding this comment.
🟢 Approval recommended
Backend normalization, fail-closed validation, tests, schemas, and documentation are consistent with the stated scope.
0 open findings
What changed in this PR
Enforces a single normalized sandbox backend across primary and enclave workloads while preserving existing runtime gates.
Changes:
- Adds backend normalization, inheritance, and mismatch validation.
- Validates assembled configurations before workflow infrastructure starts.
- Updates focused tests, schemas, and enclave documentation.
| File | Description |
|---|---|
src/parsers/enclave-parser.ts |
Inherits and validates enclave backends. |
src/parsers/enclave-parser.test.ts |
Tests inheritance and mismatch rejection. |
src/enclave/run-backend.ts |
Adds backend resolution and validation. |
src/enclave/run-backend.test.ts |
Tests aliases and assembled configurations. |
src/commands/build-config.ts |
Passes primary runtime during assembly. |
src/commands/build-config.test.ts |
Tests assembly behavior. |
src/cli-workflow.ts |
Adds early backend consistency checks. |
src/cli-workflow.test.ts |
Verifies rejection before startup. |
src/awf-config-schema.json |
Synchronizes the runtime schema. |
docs/enclaves-architecture.md |
Documents the run-wide invariant. |
docs/awf-config.schema.json |
Updates the canonical schema. |
docs/awf-config-spec.md |
Specifies inheritance and runtime gates. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Define separate workload instances of one resolved backend per enclave run. Preserve host executor mechanisms and sequence static CH then NVX integration. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 2d29b77f-7ee8-4e53-8e41-6dfee822ffaf
|
✅ Copilot review passed with no inline comments. @lpcox Add the |
✅ Coverage Check PassedOverall Coverage
📁 Per-file Coverage Changes (3 files)
✨ New Files (1 files)
Coverage comparison generated by |
|
✅ Build Test Suite completed successfully!
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅
|
|
Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed.
|
|
💎 Smoke Gemini is crystallizing results on this pull request... |
|
🚀 Security Guard has started processing this pull request |
|
🔮 The ancient spirits stir... Smoke Codex awakens to divine this pull request... |
|
✅ Smoke Claude passed
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅
|
|
🪪 Smoke Copilot BYOK AOAI (Entra) is testing Azure OpenAI BYOK (Entra / GitHub OIDC) mode on this pull request... |
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
🔑 Smoke Copilot BYOK AOAI (api-key) is testing Azure OpenAI BYOK (api-key) mode on this pull request... |
Smoke Test: Cloud Hypervisor + Copilot
Result: ALL CHECKS PASSED
|
|
EGRESS_RESULT allow=pass deny=pass
Overall: PASS — @lpcox
|
Smoke Test: Claude Engine Validation
Overall result: PASS
|
|
Smoke services: ✅ Redis PONG · ✅ pg_isready accepting connections · ✅ SELECT 1 → 1. PASS
|
Smoke Test: Copilot BYOK (Direct) Mode ✅
Mode: Direct BYOK (COPILOT_PROVIDER_API_KEY) → api-proxy sidecar → api.githubcopilot.com Status: PASS
|
|
OTEL smoke test
|
|
Smoke Copilot: PASS
Author: @lpcox
|
Chroot version comparison
Node.js differs between host and chroot, so not all tests passed. The
|
🏗️ Build Test Suite Results
Overall: 6/8 ecosystems passed — FAIL Failures:
All 8 repos cloned successfully. The
|
Summary
This is the backend-resolution first step toward one workload sandbox backend per AWF run, not further lifecycle integration.
buildConfig.runMainWorkflowstages seeds or starts infrastructure. gVisor remains distinct from Docker despite Docker orchestration; no fallback or implicit primary switch occurs in enclave-enabled runs.Validation
Verified in a clean main-based worktree:
git diff --checkpasses; canonical and embedded config schemas match.The original scoped 12-file backend-resolution patch plus the requested new ADR and ADR 0002 cross-link are included. The parent's Dockerfile edit, untracked research documents, and previously committed unrelated test fixes are excluded.