Skip to content

Latest commit

 

History

History
169 lines (152 loc) · 12 KB

File metadata and controls

169 lines (152 loc) · 12 KB

Changelog

Unreleased

  • INSPECT_POD_RESTART_CHECK=false skips the pre-operation pod read inside read_file() / write_file(), for deployments where that per-op read_namespaced_pod call becomes a load problem on the Kubernetes API server at high concurrency. Defaults to enabled, so behaviour is unchanged unless set. exec() always performs the check regardless.

  • network_mode: none isolation is now enforced by omitting any ingress allow for the service rather than an unconditional ingress deny. Observable behaviour is unchanged for a chart used on its own, but a network policy layered on top of this chart (e.g. to allow a specific port) now takes effect instead of being silently shadowed.

  • Sandbox pods no longer see their Kubernetes namespace. The kubelet was writing the pod's <pod>.<subdomain>.<namespace>.svc.cluster.local FQDN into /etc/hosts, so an agent under evaluation could read whatever the namespace name gives away (e.g. the model or benchmark being run). Pods no longer have a subdomain, so the kubelet writes a plain <pod IP> <pod name> instead. Service-to-service DNS is unaffected. The per-pod DNS name <pod>.<service>.<namespace>.svc.cluster.local no longer resolves — nothing in this chart used it, but a deployment that created its own governing Service to reach individual pods by name must now use the pod IP.

  • BREAKING CHANGE: The CoreDNS sidecar now runs as UID/GID 65532 on a read-only root filesystem with only NET_BIND_SERVICE. A custom corednsImage must run under that context; set the new corednsSecurityContext if it cannot. The default image moves from CoreDNS 1.8.3 to a digest-pinned CoreDNS 1.14.6.

  • BREAKING CHANGE: Service names, network names and additionalDnsRecords are now validated at install time and rejected with a schema error, rather than producing a release that fails later or resolves unexpectedly.

  • The CoreDNS sidecar no longer serves its ready endpoint on port 8181, and refuses queries beyond 1000 concurrent.

  • Raise an error when a conflicting max_pod_ops setting would otherwise be ignored.

  • Fix a service's args (compose command:) reaching the container as a single space-joined string instead of a list.

  • Honour compose command: on the default service. Previously the chart default entrypoint (tail -f /dev/null) was deep-merged in, so the user's command never ran.

  • exec(user=...) no longer wraps the shell in runuser when the container is already running as that user. runuser calls setgroups(2), which needs CAP_SETGID even for a root -> root switch, so the unconditional wrapper made every exec(user=...) fail in a container whose capabilities had been dropped. On that path the process environment is the container's rather than one runuser has reset (HOME, USER, supplementary groups). A container that cannot switch users at all -- non-root, no CAP_SETGID, or no runuser installed -- is now logged as a warning and returned as a failed ExecResult rather than raised, so a caller that probes with a user and falls back (as inspect-ai does when injecting its sandbox tools) can do so. Naming a user that does not exist still raises.

  • A sandbox waiting for cluster capacity no longer blocks other sandboxes from being created. Inspect's console count of in-progress installs now reflects submissions in flight rather than sandboxes still starting up.

  • A release which does not become ready now reports Helm release did not become ready within Ns together with the state of its containers, rather than Helm's context deadline exceeded. It names the sandboxes still missing, and reports Warning events against the rest of the release rather than only its pods, so a controller which cannot create its pod at all (a missing RuntimeClass, say) is explained rather than merely counted as absent.

  • A timeout now always reports, rather than hanging, when the Kubernetes API is slow to answer the reads which gather the error's diagnostics.

  • Charts which render Pods directly, rather than via a StatefulSet or Deployment, are now waited for. The eval no longer starts before every Pod labelled inspect/service is Ready, even when the chart also creates Pods which are not sandboxes — a DaemonSet, a hook, or anything added through additionalResources.

  • A chart which declares no Pod labelled inspect/service now fails the install, rather than starting an eval with no sandbox.

  • Fix a sandbox being backed by a pod which had already terminated, when the cluster still listed it beside its replacement. exec() failed intermittently.

  • Add INSPECT_HELM_UNINSTALL_TIMEOUT (default 600s). Uninstalls previously used INSPECT_HELM_TIMEOUT, which is now safe to set to hours.

  • A Helm release which fails to uninstall during sample cleanup no longer fails the sample. It is retried and reported at the end of the eval as before.

  • Remove the No GPU node is currently available warning, which also fired for releases that requested no GPU.

  • Fix sandbox pods being left in the cluster when a sample's sandbox fails to start (e.g. helm install timing out): every retry of the sample added another set of pods, none of which were removed until the eval ended. A chart with fixed-name additionalResources no longer fails the retry with exists and cannot be imported into the current release.

2026-08-12 0.13.0

  • Fix write_file() silently writing a truncated or empty file while reporting success
  • inspect sandbox cleanup k8s (with no release name) now exits non-zero if any release fails to uninstall, rather than reporting Complete. and exiting 0. Releases which fail to uninstall are named, at end-of-task cleanup too, along with their namespace and the inspect sandbox cleanup k8s <release> command to retry them.
  • BREAKING CHANGE: Sandbox pods created by the built-in Helm chart no longer mount Kubernetes service-account API tokens by default. Set automountServiceAccountToken: true only for sandboxes that require Kubernetes API access. Docker Compose users can set x-k8s.automount_service_account_token: true.
  • BREAKING CHANGE: serviceAccountName now selects an existing ServiceAccount by default. Set serviceAccountCreate: true to retain automatic creation by the Helm chart.
  • Add service_account_name, service_account_create, and automount_service_account_token to the top-level Docker Compose x-k8s extension.
  • On Helm install failure, the raised error now includes pod diagnostics.
  • Compose to HELM: Support the security_opt seccomp option (mapped to a pod seccompProfile) and ignore the unsupported memswap_limit. See Compose to Helm for details.
  • The package and bundled agent-env chart versions are now unified, both jumping to 0.13.0 (intervening numbers are unused).

2026-06-25 0.6.1

  • no changes - version bump only

2026-06-25 0.6.0

  • Replace non-UTF-8 bytes in command output rather than throwing UnicodeDecodeError.
  • BREAKING CHANGE: allowDomains egress is now restricted to ports 80/443, with the request identity enforced (TLS SNI on 443, HTTP Host on 80) rather than just the resolved IP. Wildcard entries require Cilium >= 1.18. New allowDomainsPorts opens other ports to those domains (IP-pinned; see values.yaml).
  • Add a per-service x-inspect_k8s_sandbox.resources compose extension (alias x-k8s) for Kubernetes resource requests/limits (e.g. ephemeral-storage) that the mem_limit/cpus/deploy.resources shortcuts cannot express. Merged with those shortcuts; conflicts are rejected.
  • Add optional serviceAccountName to the agent-env Helm chart for IRSA-based S3 access from sandbox pods.
  • Honour Inspect sandbox config overrides (e.g. exec output size limits) that were previously ignored on Kubernetes.
  • Recover from pod replacement or container restart instead of looping against the old pod, and raise typed PodReplacedError / ContainerRestartedError (was RuntimeError).
  • Include the cause's type and message in K8sError's string.
  • Don't misreport a user command's own stderr as a runuser configuration error under exec(user=...).
  • Fix exec(input=...) and write_file failing with "Connection reset by peer" for large inputs (e.g. a ~28 MiB binary).
  • Fix TimeoutErrors in high-concurrency evals (many concurrent clusters).

2026-05-07 0.5.0

  • Fixes for transient errors in sandbox operations
  • Prefer kubeconfig over in-cluster config to preserve the configured namespace
  • Configurable K8s client token refresh
  • Add INSPECT_K8S_DEFAULT_NAMESPACE env var to override the default namespace
  • Use --wait=legacy with Helm 4.x to avoid kstatus treating unscheduled pods as permanently failed
  • Log a warning when no GPU node is available during helm install, so users know the wait is expected rather than a hang
  • Pass comma-separated key=value labels from env var INSPECT_HELM_LABELS to helm install --labels

2026-03-04 0.4.0

  • INSPECT_SANDBOX_COREDNS_IMAGE override
  • Detect in-cluster Kubernetes config automatically, falling back to kubeconfig
  • Add max_pod_ops to K8sSandboxEnvironmentConfig
  • Declare K8sSandboxEnvironment as Docker-compatible (supports inspect-harbor and Docker Compose/Dockerfile config files)
  • Pass sample metadata as Helm --set-string values
  • Extend compose-to-helm converter: support allow_entities, ignore networks[].internal, default networks[].driver to bridge
  • Add inspectSampleUUID label to pods
  • Network policy: also allow node-local DNS cache
  • Support initContainers

2025-12-09 0.3.0

  • Increase files open limit if necessary
  • Migrate to uv
  • Add (ignored) concurrency param to exec
  • Support network_mode: none in Docker Compose files
  • Support x-default service key in Docker Compose files
  • Breaking: When converting multi-service Docker Compose files without an explicit default, the first service (in YAML order) is now renamed to default. This ensures consistent default service resolution regardless of Kubernetes pod ordering.
  • Breaking: Add validation for null values in Helm values files (Helm 4 silently filters out null values from maps during template processing, which can cause unexpected behavior)

2025-09-25 0.2.0

  • First release to Pypi
  • Ignore x-local key in Docker Compose files (Inspect-specific extension).
  • Enhanced additionalResources to support full Helm templating.
  • Support user parameter on K8sSandboxEnvironment.exec() (only when container is running as root and runuser is installed).
  • Support user parameter on K8sSandboxEnvironment.connection() (returns SandboxConnection).
  • Add SandboxConnection support for human agent baselining and connecting to a sandbox for debugging.
  • Add support for specifying a kubeconfig context name in K8sSandboxEnvironmentConfig.
  • Add automatic translation of Docker Compose files to Helm values files.
  • Handle cancellation of evals (either manually or due to an error) such that Helm releases are uninstalled.
  • Increase default Helm install timeout from 5 to 10 minutes.
  • For "helm install timeout" errors, add link to docs within and include instructions on increasing timeout within the error message.
  • Ignore "release not found" errors when uninstalling Helm charts (expected when helm release was not successfully installed).
  • Prevent DNS exfiltration attacks by limiting which domains can be looked up (when using the built-in Helm chart).
  • If a namespace is not includes in the kubeconfig context, default to a namespace named "default".
  • Add CLUSTER_DEFAULT magic string for runtimeClassName which will remove the field from the pod spec.
  • Add ignored timeout_retry parameter to exec() method.
  • Always capture the output of helm uninstall so that errors can contain meaningful information.
  • Add support for inspect sandbox cleanup k8s command to uninstall all Inspect Helm charts.
  • Remove use of Inspect's deleted SANDBOX log level in favour of trace_action() and trace_message() functions.
  • Initial release.