Repository navigation
Add fail-closed declarative NVX runtime support - #66990
Conversation
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
|
Excellent work on the fail-closed NVX runtime support! Thorough tests and docs. Looks ready for review.
|
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
|
@copilot address the review feedback and make the configuration as simple as possible. just use default values for everything undr sandbox.agent.nvx ... it should just be sandbox.agent.runtime: nvx |
There was a problem hiding this comment.
🟡 Changes recommended
The preflight always aborts on an unbound stage_dir, and staged artifacts lack cleanup on persistent runners.
3 open findings
What changed in this PR
Adds declarative, fail-closed NVX microVM runtime support, including configuration, validation, trusted artifact staging, host preflight, and documentation.
Changes:
- Adds typed NVX settings, schemas, compatibility validation, and AWF command/config generation.
- Adds artifact provenance verification and host eligibility preflight.
- Documents NVX requirements, configuration, and migration guidance.
| File | Description |
|---|---|
pkg/workflow/schemas/awf-config.schema.json |
Defines generated NVX configuration. |
pkg/workflow/sandbox.go |
Adds NVX runtime types and settings. |
pkg/workflow/sandbox_validation.go |
Integrates NVX validation. |
pkg/workflow/sandbox_runtime_profile.go |
Registers the NVX runtime profile. |
pkg/workflow/nvx.go |
Implements defaults, validation, and setup generation. |
pkg/workflow/nvx_test.go |
Tests NVX configuration and command generation. |
pkg/workflow/frontmatter_extraction_security.go |
Extracts NVX frontmatter. |
pkg/workflow/firewall.go |
Detects NVX and enables isolation. |
pkg/workflow/compiler_yaml_ai_execution.go |
Inserts NVX preflight after provisioning. |
pkg/workflow/awf_config.go |
Adds NVX AWF configuration structures. |
pkg/workflow/awf_config_build.go |
Builds fail-closed NVX configuration. |
pkg/workflow/awf_command_builder.go |
Emits NVX runtime flags and paths. |
pkg/parser/schemas/main_workflow_schema.json |
Adds frontmatter schema validation. |
pkg/parser/schema_test.go |
Tests NVX schema requirements. |
pkg/constants/version_constants.go |
Defines the minimum AWF version. |
pkg/constants/constants.go |
Adds NVX command and resource defaults. |
docs/src/content/docs/reference/sandbox.md |
Adds NVX to sandbox documentation. |
docs/src/content/docs/reference/agent-runtimes.md |
Documents NVX setup and compatibility. |
actions/setup/sh/nvx_host_preflight.sh |
Verifies the host and trusted artifacts. |
🧠 Review effort: Balanced
| if ! "${trusted_tools[gh]}" attestation verify "${stage_dir}/manifest.json" \ | ||
| --repo github/gh-aw-firewall \ | ||
| --bundle "${stage_dir}/manifest.sigstore.jsonl" \ | ||
| --signer-workflow "$GH_AW_NVX_SIGNER_WORKFLOW" \ | ||
| --deny-self-hosted-runners; then |
| func TestNVXSetupStepUsesConfiguredExpressionPaths(t *testing.T) { | ||
| data := validNVXWorkflowData() | ||
| steps := generateNVXRuntimeSetupSteps(data) | ||
| require.Len(t, steps, 1) | ||
|
|
| // AgentRuntimeNVX runs the agent inside AWF's preview one-shot NVX microVM. | ||
| AgentRuntimeNVX AgentRuntime = "nvx" |
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Done in |
|
@copilot fix the pr summary |
I can’t directly edit the PR description with the available GitHub controls. Use this replacement summary:
|
|
🎉 This pull request is included in a new release. Release: |



Add
sandbox.agent.runtime: nvxas a declarative, fail-closed preview runtime. NVX runs a workload-specific guest layer in a one-shot microVM and never falls back to another runtime.runtime: nvxenables preview mode, strict network isolation, and the API proxy. Optional NVX settings can override trusted asset paths, mount policy, resource limits, and the guest working directory.