-
INSPECT_POD_RESTART_CHECK=falseskips the pre-operation pod read insideread_file()/write_file(), for deployments where that per-opread_namespaced_podcall becomes a load problem on the Kubernetes API server at high concurrency. Defaults to enabled, so behaviour is unchanged unless set.exec()always performs the check regardless. -
network_mode: noneisolation is now enforced by omitting any ingress allow for the service rather than an unconditional ingress deny. Observable behaviour is unchanged for a chart used on its own, but a network policy layered on top of this chart (e.g. to allow a specific port) now takes effect instead of being silently shadowed. -
Sandbox pods no longer see their Kubernetes namespace. The kubelet was writing the pod's
<pod>.<subdomain>.<namespace>.svc.cluster.localFQDN into/etc/hosts, so an agent under evaluation could read whatever the namespace name gives away (e.g. the model or benchmark being run). Pods no longer have a subdomain, so the kubelet writes a plain<pod IP> <pod name>instead. Service-to-service DNS is unaffected. The per-pod DNS name<pod>.<service>.<namespace>.svc.cluster.localno longer resolves — nothing in this chart used it, but a deployment that created its own governing Service to reach individual pods by name must now use the pod IP. -
BREAKING CHANGE: The CoreDNS sidecar now runs as UID/GID 65532 on a read-only root filesystem with only
NET_BIND_SERVICE. A customcorednsImagemust run under that context; set the newcorednsSecurityContextif it cannot. The default image moves from CoreDNS 1.8.3 to a digest-pinned CoreDNS 1.14.6. -
BREAKING CHANGE: Service names, network names and
additionalDnsRecordsare now validated at install time and rejected with a schema error, rather than producing a release that fails later or resolves unexpectedly. -
The CoreDNS sidecar no longer serves its
readyendpoint on port 8181, and refuses queries beyond 1000 concurrent. -
Raise an error when a conflicting
max_pod_opssetting would otherwise be ignored. -
Fix a service's
args(composecommand:) reaching the container as a single space-joined string instead of a list. -
Honour compose
command:on thedefaultservice. Previously the chart default entrypoint (tail -f /dev/null) was deep-merged in, so the user's command never ran. -
exec(user=...)no longer wraps the shell inrunuserwhen the container is already running as that user.runusercallssetgroups(2), which needsCAP_SETGIDeven for a root -> root switch, so the unconditional wrapper made everyexec(user=...)fail in a container whose capabilities had been dropped. On that path the process environment is the container's rather than onerunuserhas reset (HOME,USER, supplementary groups). A container that cannot switch users at all -- non-root, noCAP_SETGID, or norunuserinstalled -- is now logged as a warning and returned as a failedExecResultrather than raised, so a caller that probes with a user and falls back (as inspect-ai does when injecting its sandbox tools) can do so. Naming a user that does not exist still raises. -
A sandbox waiting for cluster capacity no longer blocks other sandboxes from being created. Inspect's console count of in-progress installs now reflects submissions in flight rather than sandboxes still starting up.
-
A release which does not become ready now reports
Helm release did not become ready within Nstogether with the state of its containers, rather than Helm'scontext deadline exceeded. It names the sandboxes still missing, and reports Warning events against the rest of the release rather than only its pods, so a controller which cannot create its pod at all (a missingRuntimeClass, say) is explained rather than merely counted as absent. -
A timeout now always reports, rather than hanging, when the Kubernetes API is slow to answer the reads which gather the error's diagnostics.
-
Charts which render Pods directly, rather than via a StatefulSet or Deployment, are now waited for. The eval no longer starts before every Pod labelled
inspect/serviceis Ready, even when the chart also creates Pods which are not sandboxes — aDaemonSet, a hook, or anything added throughadditionalResources. -
A chart which declares no Pod labelled
inspect/servicenow fails the install, rather than starting an eval with no sandbox. -
Fix a sandbox being backed by a pod which had already terminated, when the cluster still listed it beside its replacement.
exec()failed intermittently. -
Add
INSPECT_HELM_UNINSTALL_TIMEOUT(default 600s). Uninstalls previously usedINSPECT_HELM_TIMEOUT, which is now safe to set to hours. -
A Helm release which fails to uninstall during sample cleanup no longer fails the sample. It is retried and reported at the end of the eval as before.
-
Remove the
No GPU node is currently availablewarning, which also fired for releases that requested no GPU. -
Fix sandbox pods being left in the cluster when a sample's sandbox fails to start (e.g.
helm installtiming out): every retry of the sample added another set of pods, none of which were removed until the eval ended. A chart with fixed-nameadditionalResourcesno longer fails the retry withexists and cannot be imported into the current release.
- Fix
write_file()silently writing a truncated or empty file while reporting success inspect sandbox cleanup k8s(with no release name) now exits non-zero if any release fails to uninstall, rather than reportingComplete.and exiting 0. Releases which fail to uninstall are named, at end-of-task cleanup too, along with their namespace and theinspect sandbox cleanup k8s <release>command to retry them.- BREAKING CHANGE: Sandbox pods created by the built-in Helm chart no longer mount
Kubernetes service-account API tokens by default. Set
automountServiceAccountToken: trueonly for sandboxes that require Kubernetes API access. Docker Compose users can setx-k8s.automount_service_account_token: true. - BREAKING CHANGE:
serviceAccountNamenow selects an existing ServiceAccount by default. SetserviceAccountCreate: trueto retain automatic creation by the Helm chart. - Add
service_account_name,service_account_create, andautomount_service_account_tokento the top-level Docker Composex-k8sextension. - On Helm install failure, the raised error now includes pod diagnostics.
- Compose to HELM: Support the
security_optseccomp option (mapped to a podseccompProfile) and ignore the unsupportedmemswap_limit. See Compose to Helm for details. - The package and bundled
agent-envchart versions are now unified, both jumping to0.13.0(intervening numbers are unused).
- no changes - version bump only
- Replace non-UTF-8 bytes in command output rather than throwing
UnicodeDecodeError. - BREAKING CHANGE:
allowDomainsegress is now restricted to ports 80/443, with the request identity enforced (TLS SNI on 443, HTTPHoston 80) rather than just the resolved IP. Wildcard entries require Cilium >= 1.18. NewallowDomainsPortsopens other ports to those domains (IP-pinned; seevalues.yaml). - Add a per-service
x-inspect_k8s_sandbox.resourcescompose extension (aliasx-k8s) for Kubernetes resourcerequests/limits(e.g.ephemeral-storage) that themem_limit/cpus/deploy.resourcesshortcuts cannot express. Merged with those shortcuts; conflicts are rejected. - Add optional
serviceAccountNameto the agent-env Helm chart for IRSA-based S3 access from sandbox pods. - Honour Inspect sandbox config overrides (e.g. exec output size limits) that were previously ignored on Kubernetes.
- Recover from pod replacement or container restart instead of looping against the old pod, and raise typed
PodReplacedError/ContainerRestartedError(wasRuntimeError). - Include the cause's type and message in
K8sError's string. - Don't misreport a user command's own stderr as a
runuserconfiguration error underexec(user=...). - Fix
exec(input=...)andwrite_filefailing with "Connection reset by peer" for large inputs (e.g. a ~28 MiB binary). - Fix
TimeoutErrors in high-concurrency evals (many concurrent clusters).
- Fixes for transient errors in sandbox operations
- Prefer kubeconfig over in-cluster config to preserve the configured namespace
- Configurable K8s client token refresh
- Add
INSPECT_K8S_DEFAULT_NAMESPACEenv var to override the default namespace - Use
--wait=legacywith Helm 4.x to avoid kstatus treating unscheduled pods as permanently failed - Log a warning when no GPU node is available during
helm install, so users know the wait is expected rather than a hang - Pass comma-separated
key=valuelabels from env varINSPECT_HELM_LABELStohelm install --labels
INSPECT_SANDBOX_COREDNS_IMAGEoverride- Detect in-cluster Kubernetes config automatically, falling back to kubeconfig
- Add
max_pod_opstoK8sSandboxEnvironmentConfig - Declare K8sSandboxEnvironment as Docker-compatible (supports
inspect-harborand Docker Compose/Dockerfile config files) - Pass sample metadata as Helm
--set-stringvalues - Extend compose-to-helm converter: support
allow_entities, ignorenetworks[].internal, defaultnetworks[].drivertobridge - Add
inspectSampleUUIDlabel to pods - Network policy: also allow node-local DNS cache
- Support initContainers
- Increase files open limit if necessary
- Migrate to uv
- Add (ignored) concurrency param to exec
- Support
network_mode: nonein Docker Compose files - Support
x-defaultservice key in Docker Compose files - Breaking: When converting multi-service Docker Compose files without an explicit
default, the first service (in YAML order) is now renamed to
default. This ensures consistent default service resolution regardless of Kubernetes pod ordering. - Breaking: Add validation for null values in Helm values files (Helm 4 silently filters out null values from maps during template processing, which can cause unexpected behavior)
- First release to Pypi
- Ignore
x-localkey in Docker Compose files (Inspect-specific extension). - Enhanced
additionalResourcesto support full Helm templating. - Support
userparameter onK8sSandboxEnvironment.exec()(only when container is running as root andrunuseris installed). - Support
userparameter onK8sSandboxEnvironment.connection()(returnsSandboxConnection). - Add
SandboxConnectionsupport for human agent baselining and connecting to a sandbox for debugging. - Add support for specifying a kubeconfig context name in K8sSandboxEnvironmentConfig.
- Add automatic translation of Docker Compose files to Helm values files.
- Handle cancellation of evals (either manually or due to an error) such that Helm releases are uninstalled.
- Increase default Helm install timeout from 5 to 10 minutes.
- For "helm install timeout" errors, add link to docs within and include instructions on increasing timeout within the error message.
- Ignore "release not found" errors when uninstalling Helm charts (expected when helm release was not successfully installed).
- Prevent DNS exfiltration attacks by limiting which domains can be looked up (when using the built-in Helm chart).
- If a namespace is not includes in the kubeconfig context, default to a namespace named "default".
- Add
CLUSTER_DEFAULTmagic string forruntimeClassNamewhich will remove the field from the pod spec. - Add ignored
timeout_retryparameter toexec()method. - Always capture the output of
helm uninstallso that errors can contain meaningful information. - Add support for
inspect sandbox cleanup k8scommand to uninstall all Inspect Helm charts. - Remove use of Inspect's deleted
SANDBOXlog level in favour oftrace_action()andtrace_message()functions. - Initial release.