NVIDIA / NVIDIA/NemoClaw

[Kubernetes] Qualify the external-gateway runner on one cluster tuple

Open
#9,874 0 comments 0 reactions 0 assignees View on GitHub
area: e2e integration: openclaw platform: k8s
Dominant language
TypeScript
Stars
22.5k
Forks
3.1k
Avg merge
1d 1h
Merged PRs (30d)
715

Description

Parent: #9816

## Outcome

Qualify the external-gateway NemoClaw runner on one exact Kubernetes or OpenShift configuration and retain reproducible, sanitized evidence.

## Scope

- Add one explicit-only `kubernetes-external-gateway` live target through the existing typed E2E registry and workflow planner.
- Launch the runner as non-root with no Docker or Podman socket, privileged builder, or host runtime mount.
- Verify TLS and machine authentication, one OpenShell workspace, exact release compatibility, exact runner and sandbox image digests, one completed OpenClaw turn, inspection, and automatic cleanup.
- Compare stable gateway identity and lifecycle state before and after the run.

## Acceptance

- [ ] Evidence records the NemoClaw commit/version, runner and sandbox image digests, OpenShell client/gateway/chart/controller versions, cluster version, workspace, TLS mode, CA fingerprint, sanitized manifests, phase results, agent-turn receipt, and cleanup receipt.
- [ ] Missing or invalid trust, authentication, workspace, release, or image digest fails with actionable, redacted diagnostics.
- [ ] No kubeconfig, Secret contents, tokens, private keys, environment dumps, or unbounded logs are retained.
- [ ] Cleanup failures fail qualification and report the exact remaining run-owned identity.
- [ ] The gateway, controller, chart release, shared image, and consumer-owned Secret remain unchanged.

## Dependencies

The external target/readiness and buildless lifecycle capabilities under #9816 must be complete for the selected exact version tuple.

## Out of scope

Release-gate promotion, support-matrix claims, broad distribution coverage, HA, multi-tenancy, and production support.

Contributor guide

Open the contributing guide

Research direction

Start with parent issue #9816 and the existing typed E2E registry and workflow planner, including its external-target/readiness and buildless lifecycle capabilities. Define one explicit-only kubernetes-external-gateway target for an exact version tuple, then qualify the stated TLS, authentication, workspace, image, agent-turn, inspection, lifecycle, evidence, and cleanup requirements without changing shared resources.

Written by the indexing model from the issue text.

Assessment

Tech stack
kubernetes, typescript
Domain
devops, infrastructure, testing
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.