Repository navigation
refactor(sdk): pass gateway settings through gatewayConfig, not legacy server values - #12949
Merged
Merged
Conversation
Contributor
|
v1 documentation preview: https://nvidia-preview-nemoclaw-v1-pr-12949.docs.buildwithfern.com/nemoclaw |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Failure
The OpenShell v0.1.3 chart (NVIDIA/OpenShell#3384) moves gateway settings into
gatewayConfig. NemoClaw still set four of them throughserver.*values, which work only through the chart's compatibility mapping:server.oidcissuer, audience, claims, and rolesserver.auth.allowUnauthenticatedUsersserver.workspaceDefaultStorageSizeserver.drivers.kubernetes.workspaceModeDecision
Set them in
gatewayConfig(schema version 2), using the dotted TOML table keys the chart's own CI values use:serverkeeps only values the templates read directly: TLS, the JWT signing secret, credential storage, telemetry, andserver.oidc.caConfigMapName. The chart mounts the issuer CA only from that last value. The settings themselves are unchanged.Validation
gatewayConfigtables, and thatserverholds only those directly read keys. Both failed before the change and pass after it. All 84 Kubernetes tests pass.cargo cipassed: 1,322 workspace tests and all 120 lifecycle tests.linux_arm64andlinux_amd64with the real v0.1.3 chart (run 38003924177). That includesthe_pinned_chart_renders_with_the_sdk_valuesandthe_gateway_installs_authenticates_and_is_removed_keeping_storage, which authenticates through the OIDC settings ingatewayConfig.