Version. OpenShell 0.1.2, Helm chart 0.1.2, Kubernetes driver (Docker Desktop v1.36.1 dev cluster, Agent Sandbox v1.0.4). Observed 2026-09-29.
Observed. After openshell policy set --global <policy.yaml> on a Kubernetes-driver gateway, every subsequent sandbox create fails to start. The supervisor's own policy push is refused with policy is managed globally. Clearing the global policy restores sandbox start. The same policy set --global on a Docker-driver gateway works.
Why it matters. A gateway-wide policy lock is exactly what a platform team wants on Kubernetes (one policy, enforced for every sandbox, not trusting each caller's --policy). As shipped, choosing the lock on the k8s driver takes the gateway out of service with an error that reads as a permissions problem, not as a driver limitation.
Repro.
- Install chart 0.1.2 with the Kubernetes driver; confirm
sandbox create -- sh -c 'echo ok' works.
openshell policy set --global <any valid policy>
sandbox create -- sh -c 'echo ok' — refused; supervisor log: policy is managed globally.
Ask. Either make the global lock work on the k8s driver (the supervisor should read the global policy rather than push its own), or have policy set --global refuse on a k8s-driver gateway with a message that says so.
Workaround we use: a ConfigMap holding the policy, passed per sandbox as --policy by the launcher. Related: #4300 asks for a chart value that mounts a policy ConfigMap.
Version. OpenShell 0.1.2, Helm chart 0.1.2, Kubernetes driver (Docker Desktop v1.36.1 dev cluster, Agent Sandbox v1.0.4). Observed 2026-09-29.
Observed. After
openshell policy set --global <policy.yaml>on a Kubernetes-driver gateway, every subsequentsandbox createfails to start. The supervisor's own policy push is refused withpolicy is managed globally. Clearing the global policy restores sandbox start. The samepolicy set --globalon a Docker-driver gateway works.Why it matters. A gateway-wide policy lock is exactly what a platform team wants on Kubernetes (one policy, enforced for every sandbox, not trusting each caller's
--policy). As shipped, choosing the lock on the k8s driver takes the gateway out of service with an error that reads as a permissions problem, not as a driver limitation.Repro.
sandbox create -- sh -c 'echo ok'works.openshell policy set --global <any valid policy>sandbox create -- sh -c 'echo ok'— refused; supervisor log:policy is managed globally.Ask. Either make the global lock work on the k8s driver (the supervisor should read the global policy rather than push its own), or have
policy set --globalrefuse on a k8s-driver gateway with a message that says so.Workaround we use: a ConfigMap holding the policy, passed per sandbox as
--policyby the launcher. Related: #4300 asks for a chart value that mounts a policy ConfigMap.