Skip to content

Add fail-closed declarative NVX runtime support - #66990

Merged
lpcox merged 6 commits into
mainfrom
copilot/add-fail-closed-nvx-support
Oct 8, 2026
Merged

lpcox merged 6 commits into
mainfrom
copilot/add-fail-closed-nvx-support

Conversation

Copilot AI commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Add sandbox.agent.runtime: nvx as a declarative, fail-closed preview runtime. NVX runs a workload-specific guest layer in a one-shot microVM and never falls back to another runtime.

  • Secure defaults: Setting runtime: nvx enables preview mode, strict network isolation, and the API proxy. Optional NVX settings can override trusted asset paths, mount policy, resource limits, and the guest working directory.
  • Preflight and trusted assets: Require explicit pre-agent provisioning of the guest layer and AWF release assets. Verify the artifact manifest and Sigstore bundle offline, check asset digests and host compatibility, then stage verified files root-owned and read-only; clean up staging after execution.
  • Compatibility and docs: Reject unsupported runner topologies and features rather than weakening isolation. Document Linux x86_64, root/KVM, cgroup v2, and seccomp requirements, plus migration guidance for firewall smoke workflows.
sandbox:
  agent:
    runtime: nvx

Copilot AI linked an issue Oct 8, 2026 that may be closed by this pull request
15 tasks
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Comment thread actions/setup/sh/nvx_host_preflight.sh Outdated
Copilot AI changed the title [WIP] Add fail-closed declarative NVX runtime support Add fail-closed declarative NVX runtime support Oct 8, 2026
Copilot AI requested a review from lpcox October 8, 2026 20:27
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Excellent work on the fail-closed NVX runtime support! Thorough tests and docs. Looks ready for review.

Generated by ✅ Contribution Check · copilot · auto · 42.7 AIC · ⌖ 0.609 AIC · ⊞ 9.2K · ◷

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Comment thread actions/setup/sh/nvx_host_preflight.sh Outdated
@lpcox
lpcox marked this pull request as ready for review October 8, 2026 21:43
Copilot AI balanced review requested due to automatic review settings October 8, 2026 21:43
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Comment thread actions/setup/sh/nvx_host_preflight.sh
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@lpcox

lpcox commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

@copilot address the review feedback and make the configuration as simple as possible. just use default values for everything undr sandbox.agent.nvx ... it should just be sandbox.agent.runtime: nvx

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The preflight always aborts on an unbound stage_dir, and staged artifacts lack cleanup on persistent runners.

3 open findings
What changed in this PR

Adds declarative, fail-closed NVX microVM runtime support, including configuration, validation, trusted artifact staging, host preflight, and documentation.

Changes:

  • Adds typed NVX settings, schemas, compatibility validation, and AWF command/config generation.
  • Adds artifact provenance verification and host eligibility preflight.
  • Documents NVX requirements, configuration, and migration guidance.
File Description
pkg/​workflow/​schemas/​awf-config.schema.json Defines generated NVX configuration.
pkg/​workflow/​sandbox.go Adds NVX runtime types and settings.
pkg/​workflow/​sandbox_validation.go Integrates NVX validation.
pkg/​workflow/​sandbox_runtime_profile.go Registers the NVX runtime profile.
pkg/​workflow/​nvx.go Implements defaults, validation, and setup generation.
pkg/​workflow/​nvx_test.go Tests NVX configuration and command generation.
pkg/​workflow/​frontmatter_extraction_security.go Extracts NVX frontmatter.
pkg/​workflow/​firewall.go Detects NVX and enables isolation.
pkg/​workflow/​compiler_yaml_ai_execution.go Inserts NVX preflight after provisioning.
pkg/​workflow/​awf_config.go Adds NVX AWF configuration structures.
pkg/​workflow/​awf_config_build.go Builds fail-closed NVX configuration.
pkg/​workflow/​awf_command_builder.go Emits NVX runtime flags and paths.
pkg/​parser/​schemas/​main_workflow_schema.json Adds frontmatter schema validation.
pkg/​parser/​schema_test.go Tests NVX schema requirements.
pkg/​constants/​version_constants.go Defines the minimum AWF version.
pkg/​constants/​constants.go Adds NVX command and resource defaults.
docs/​src/​content/​docs/​reference/​sandbox.md Adds NVX to sandbox documentation.
docs/​src/​content/​docs/​reference/​agent-runtimes.md Documents NVX setup and compatibility.
actions/​setup/​sh/​nvx_host_preflight.sh Verifies the host and trusted artifacts.

🧠 Review effort: Balanced

Comment on lines +148 to +152
if ! "${trusted_tools[gh]}" attestation verify "${stage_dir}/manifest.json" \
--repo github/gh-aw-firewall \
--bundle "${stage_dir}/manifest.sigstore.jsonl" \
--signer-workflow "$GH_AW_NVX_SIGNER_WORKFLOW" \
--deny-self-hosted-runners; then
Comment thread pkg/workflow/nvx_test.go
Comment on lines +215 to +219
func TestNVXSetupStepUsesConfiguredExpressionPaths(t *testing.T) {
data := validNVXWorkflowData()
steps := generateNVXRuntimeSetupSteps(data)
require.Len(t, steps, 1)

Comment thread pkg/workflow/sandbox.go
Comment on lines +68 to +69
// AgentRuntimeNVX runs the agent inside AWF's preview one-shot NVX microVM.
AgentRuntimeNVX AgentRuntime = "nvx"
Comment thread actions/setup/sh/nvx_host_preflight.sh Outdated
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>

Copilot AI commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

@copilot address the review feedback and make the configuration as simple as possible. just use default values for everything undr sandbox.agent.nvx ... it should just be sandbox.agent.runtime: nvx

Done in aa787b65. NVX now uses secure defaults so sandbox.agent.runtime: nvx is sufficient; I also fixed staging/attestation ordering and added preflight execution coverage, cleanup, and the minor changeset.

@lpcox

lpcox commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

@copilot fix the pr summary

Copilot AI commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

@copilot fix the pr summary

I can’t directly edit the PR description with the available GitHub controls. Use this replacement summary:

Add fail-closed NVX runtime support, enabled with only sandbox.agent.runtime: nvx. NVX applies secure defaults for isolation, API proxying, workspace-only mounts, and trusted artifact paths. Preflight verifies artifact provenance and digests, checks Linux x86_64 KVM compatibility, and stages verified files root-owned and read-only. Unsupported configurations fail closed; tests and documentation cover setup and migration.

@lpcox
lpcox merged commit b54957e into main Oct 8, 2026
38 checks passed
@lpcox
lpcox deleted the copilot/add-fail-closed-nvx-support branch October 8, 2026 22:45
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.91.7

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add fail-closed declarative NVX runtime support

4 participants