Conversation
`template.files` says every Sandbox from the pool gets the same files. It did not say the consequence: anything done inside one Sandbox that invalidates the credential invalidates it for the whole pool, and `readOnly` does not prevent that — a revocation or a token rotation happens at the provider, not at the file. The `sandbox` pool has hit this twice, neither time looking like a credential problem. A `claude logout` in one Sandbox revoked the token for every lease. A replacement was taken from whoever's keychain had one, and because the workload's account metadata is writable while the credential is not, boxes reported one identity while authenticating as another for days. Both follow from the credential's shape rather than from the mechanism: a person's OAuth login is scoped to a human, expires, and usually rotates its refresh token on use. A machine credential — an API key, a service account — does none of those, which is what makes `readOnly` right rather than an obstacle. So the field now names the distinction and says which to prefer, and says that "somebody logged out" is a first-class explanation for every lease failing at once. This is the documentation half of #375. Which credential the `sandbox` pool should actually serve is a billing decision, not an engineering one, and the warning that issue asks for at lease hand-out needs the pool threaded into the lease response — `sandbox_lease_accepted` takes only the pool's name today. Both stay open.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CRD doc-comment and the regenerated schema only.
What was missing
template.filessaid every Sandbox from the pool gets the same files. It didnot say the consequence: anything done inside one Sandbox that invalidates
the credential invalidates it for every lease from that pool.
readOnlydoesnot prevent it — a revocation or a token rotation takes effect at the issuing
service, not at the file.
Why the credential's shape is the whole question
readOnlyis exactly right for the first: nothing a workload does reaches thecredential, and the only way to break the pool is to revoke it deliberately.
For the second it is an obstacle rather than a protection. Such a credential
refreshes and cannot persist the result, so every Sandbox refreshes again; and
the failure modes do not look like credential problems —
credential can report one identity while authenticating as another
The field now says to mount a machine credential, and that "someone signed
out" is a first-class explanation when every lease loses access at once.
Scope
Documentation only. It describes what the mechanism does, not what any
particular deployment mounts.
Verification
just build-crdgenregeneratedcharts/kobe/crds/sandboxpools.yaml;clippy --all-features -D warningsclean.