feat: make supervisor base image configurable via build ARG
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 84/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- docker
- Ambito
- build-system, devops
Direzione di ricerca
Inizia confrontando deploy/docker/Dockerfile.supervisor con deploy/docker/Dockerfile.gateway e leggi la documentazione dell’immagine di base in architecture/build.md. Aggiungi l’override del supervisor usando come valore predefinito l’immagine attualmente bloccata, quindi esegui la build con e senza override per verificare il comportamento predefinito e la configurabilità. Il lavoro è completato quando la documentazione copre entrambi gli override e il valore predefinito rimane invariato.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
User Story
As an operator or downstream packager deploying OpenShell's supervisor container in an environment with specific registry-trust, compliance, or support constraints (e.g. a registry allowlist, a FIPS-validated base image requirement, or an internal support SLA tied to a specific image vendor), I want to override the supervisor's base image at build time, so that I can satisfy my environment's constraints without forking the Dockerfile.
Problem Statement
deploy/docker/Dockerfile.gateway already exposes its base image as a build ARG:
ARG GATEWAY_BASE_IMAGE=gcr.io/distroless/cc-debian13:nonroot@sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97
FROM ${GATEWAY_BASE_IMAGE} AS gateway
deploy/docker/Dockerfile.supervisor does not. It hardcodes:
FROM gcr.io/distroless/base-nossl-debian13@sha256:af5cb8dd589b8520b8c06bebb9efb73d7e16406cab58e85c51761fff49d370a0 AS supervisor
There is no equivalent override point, so substituting an alternate base image for the supervisor today requires forking/patching the Dockerfile.
Impact / Why This Matters
Downstream consumers building in a registry-restricted environment, needing a FIPS-validated base, or needing a base image they can patch/support on their own schedule currently have to maintain a forked Dockerfile to get a different supervisor base image. A fork drifts from upstream over time (missed binary/build-step changes) and duplicates this maintenance burden across every downstream consumer who needs it. The gateway already solves this cleanly; the supervisor's inconsistency with that pattern is the actual gap, not a missing capability invented from scratch.
Proposed Design
Add a build ARG to deploy/docker/Dockerfile.supervisor (e.g. SUPERVISOR_BASE_IMAGE) defaulting to the current pinned image/digest, mirroring GATEWAY_BASE_IMAGE's existing pattern. This is purely additive: no default behavior change, and no change to published images unless a builder explicitly overrides the ARG. Exact ARG naming/defaulting mechanics are left to the implementing PR.
Acceptance Criteria
-
deploy/docker/Dockerfile.supervisoraccepts a build ARG for its base image, with the current image pinned as the default. - Building without overriding the ARG produces the same image as today (no default-behavior change).
- Wherever the gateway's
GATEWAY_BASE_IMAGEoverride is documented (e.g.architecture/build.md) is updated to document the supervisor's new equivalent consistently.
Alternatives Considered
- Status quo (hardcoded base, consumers fork the Dockerfile if they need something else) — rejected: duplicates maintenance effort per downstream consumer and drifts from upstream over time.
- Change the default base image itself (e.g. to Red Hat's Project Hummingbird
registry.access.redhat.com/hi/core-runtime) — rejected for now: a direct comparison (skopeo inspectagainst both) shows Hummingbird'score-runtimeimage is larger and has more layers than the current default (12.82 MB / 23 layers vs. the current base's 5.94 MB / 14 layers), and its image config setsCMD ["/bin/bash"], suggesting a shell may be present where the current distroless base has none. It is not a demonstrated improvement, and changing the project's default base is a larger decision needing broader maintainer alignment, not a mechanical change. - Make the sandbox image configurable the same way (
deploy/docker/Dockerfile.sandbox,FROM scratch) — rejected: the sandbox image has no runtime base to swap, it's a bare static binary with no base at all, so this axis doesn't apply there.
Agent Investigation
Confirmed by reading the current Dockerfiles directly and inspecting published images/registries with skopeo inspect:
deploy/docker/Dockerfile.gatewayalready has theGATEWAY_BASE_IMAGEARG described above.deploy/docker/Dockerfile.supervisorhas no equivalent ARG.deploy/docker/Dockerfile.sandboxisFROM scratchwith no base image to parameterize.- Published
ghcr.io/nvidia/openshell/supervisor:devis 15 layers / ~19.6 MB total; its base (distroless/base-nossl-debian13) is 14 layers / ~5.94 MB. registry.access.redhat.com/hi/core-runtime:latest(Project Hummingbird's comparable minimal base) is 23 layers / ~12.82 MB, with image configCMD ["/bin/bash"].
No RFC needed — this is a small, additive, non-breaking build-configuration change, not a change to OpenShell's architecture or default behavior.
- Lingua principale
- Rust
- Stelle
- 13.2k
- Fork
- 1.6k
- Merge medio
- 1g 19h
- PR unite (30g)
- 343
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di NVIDIA/OpenShell
-
bug(vm-driver): VM sandbox cold start stalls ~5 s repeatedly on "Waiting for VM supervisor"Forse già presa Una pull request collegata a questa issue è aperta o già unita. Apertastate:triage-needed
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
I maintainer di solito rispondono entro 1 giorno
-
docs: document workspace and provider label capabilitiesForse già presa Una pull request collegata a questa issue è aperta o già unita. Apertaarea:docs
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
I maintainer di solito rispondono entro 1 giorno
-
Sandbox-side proposal audit (CONFIG:PROPOSED and /wait decisions) names only the first endpointApertastate:triage-needed
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
bug(driver-mxc): test helper fails to compile after gateway-name argumentForse già presa @feloy l’ha presa 2 giorni fa. Apertastate:triage-needed
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
I maintainer di solito rispondono entro 1 giorno
-
bug: install.sh ignores XDG_CONFIG_HOME for the local gateway configForse già presa @fede-kamel l’ha presa 6 giorni fa. Apertaarea:cli os:linux os:macos state:validated
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
NVIDIA/OpenShell#4042 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di NVIDIA/OpenShell
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
I maintainer di solito rispondono entro 4 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
I maintainer di solito rispondono entro 1 giorno
-
Update dusk-bls12_381 to 0.16Forse già presa @HDauven l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
`TcpListenerService` shares one `Extensions` store across all accepted connectionsForse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
googlefonts/fontquant#43 ·