[Kubernetes] Qualify the external-gateway runner on one cluster tuple
- Dominant language
- TypeScript
- Stars
- 22.5k
- Forks
- 3.1k
- Avg merge
- 1d 1h
- Merged PRs (30d)
- 715
Description
Parent: #9816
## Outcome
Qualify the external-gateway NemoClaw runner on one exact Kubernetes or OpenShift configuration and retain reproducible, sanitized evidence.
## Scope
- Add one explicit-only `kubernetes-external-gateway` live target through the existing typed E2E registry and workflow planner.
- Launch the runner as non-root with no Docker or Podman socket, privileged builder, or host runtime mount.
- Verify TLS and machine authentication, one OpenShell workspace, exact release compatibility, exact runner and sandbox image digests, one completed OpenClaw turn, inspection, and automatic cleanup.
- Compare stable gateway identity and lifecycle state before and after the run.
## Acceptance
- [ ] Evidence records the NemoClaw commit/version, runner and sandbox image digests, OpenShell client/gateway/chart/controller versions, cluster version, workspace, TLS mode, CA fingerprint, sanitized manifests, phase results, agent-turn receipt, and cleanup receipt.
- [ ] Missing or invalid trust, authentication, workspace, release, or image digest fails with actionable, redacted diagnostics.
- [ ] No kubeconfig, Secret contents, tokens, private keys, environment dumps, or unbounded logs are retained.
- [ ] Cleanup failures fail qualification and report the exact remaining run-owned identity.
- [ ] The gateway, controller, chart release, shared image, and consumer-owned Secret remain unchanged.
## Dependencies
The external target/readiness and buildless lifecycle capabilities under #9816 must be complete for the selected exact version tuple.
## Out of scope
Release-gate promotion, support-matrix claims, broad distribution coverage, HA, multi-tenancy, and production support.
Contributor guide
Research direction
Start with parent issue #9816 and the existing typed E2E registry and workflow planner, including its external-target/readiness and buildless lifecycle capabilities. Define one explicit-only kubernetes-external-gateway target for an exact version tuple, then qualify the stated TLS, authentication, workspace, image, agent-turn, inspection, lifecycle, evidence, and cleanup requirements without changing shared resources.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- kubernetes, typescript
- Domain
- devops, infrastructure, testing
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100